{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T02:52:10Z","timestamp":1781059930403,"version":"3.54.1"},"reference-count":17,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2017,5,9]],"date-time":"2017-05-09T00:00:00Z","timestamp":1494288000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["World Wide Web"],"published-print":{"date-parts":[[2018,1]]},"DOI":"10.1007\/s11280-017-0458-9","type":"journal-article","created":{"date-parts":[[2017,5,8]],"date-time":"2017-05-08T23:15:37Z","timestamp":1494285337000},"page":"127-150","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["An automatically vetting mechanism for SSL error-handling vulnerability in android hybrid Web apps"],"prefix":"10.1007","volume":"21","author":[{"given":"Yang","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaoshun","family":"Zuo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zonghua","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinshun","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,5,9]]},"reference":[{"key":"458_CR1","doi-asserted-by":"crossref","unstructured":"Arzt, S., Rasthofer, S., Fritz, C., Bodden, E., Bartel, A., Klein, J., Le Traon, Y., Octeau, D., McDaniel, P.: Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In: ACM SIGPLAN Notices, vol. 49, pp. 259\u2013269. ACM (2014)","DOI":"10.1145\/2666356.2594299"},{"key":"458_CR2","unstructured":"Bhoraskar, R., Han, S., Jeon, J., Azim, T., Chen, S., Jung, J., Nath, S., Wang, R., Wetherall, D., Langenegger, D., et al.: Brahmastra: driving apps to test the security of third-party components"},{"key":"458_CR3","unstructured":"Brubaker, C., Jana, S., Ray, B., Khurshid, S., Shmatikov, V.: Using frankencerts for automated adversarial testing of certificate validation in ssl\/tls implementations"},{"key":"458_CR4","doi-asserted-by":"crossref","unstructured":"Clark, J., van Oorschot, P.C.: Sok: Ssl and https: revisiting past challenges and evaluating certificate trust model enhancements. In: 2013 IEEE Symposium on Security and Privacy (SP), pp. 511\u2013525. IEEE (2013)","DOI":"10.1109\/SP.2013.41"},{"key":"458_CR5","unstructured":"Desnos, A.: Androguard: Reverse engineering, malware and goodware analysis of android applications... and more (ninja!)"},{"issue":"3","key":"458_CR6","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1145\/2494522","volume":"57","author":"W Enck","year":"2014","unstructured":"Enck, W., Gilbert, P., Chun, B.-G., Cox, L.P., Jung, J., McDaniel, P., Sheth, A.N.: Taintdroid: an information flow tracking system for real-time privacy monitoring on smartphones. Commun. ACM 57(3), 99\u2013106 (2014)","journal-title":"Commun. ACM"},{"key":"458_CR7","doi-asserted-by":"crossref","unstructured":"Fahl, S., Harbach, M., Muders, T., Baumg\u00e4rtner, L., Freisleben, B., Smith, M.: Why eve and mallory love android: an analysis of android ssl (in) security. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 50\u201361. ACM (2012)","DOI":"10.1145\/2382196.2382205"},{"key":"458_CR8","unstructured":"Felt, A.P., Wagner, D: Phishing on mobile devices, na (2011)"},{"key":"458_CR9","doi-asserted-by":"crossref","unstructured":"Georgiev, M., Iyengar, S., Jana, S., Anubhai, R., Boneh, D., Shmatikov, V.: The most dangerous code in the world: validating ssl certificates in non-browser software. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 38\u201349. ACM. http:\/\/dl.acm.org\/citation.cfm?id=2382204 (2012)","DOI":"10.1145\/2382196.2382204"},{"key":"458_CR10","unstructured":"Green, I.: Dns spoofing by the man in the middle"},{"key":"458_CR11","unstructured":"Housley, R., Ford, W., Polk, W., Solo, D.: Rfc 5280: Internet x. 509 public key infrastructure certificate and crl profile (2008)"},{"key":"458_CR12","doi-asserted-by":"crossref","unstructured":"MacHiry, A., Tahiliani, R., Naik, M.: Dynodroid: an input generation system for android apps. In: Proceedings of the 2013 9th Joint Meeting on Foundations of Software Engineering, pp. 224\u2013234. ACM (2013)","DOI":"10.1145\/2491411.2491450"},{"key":"458_CR13","doi-asserted-by":"crossref","unstructured":"Rastogi, V., Chen, Y., Enck, W.: Appsplayground: automatic security analysis of smartphone applications. In: Proceedings of the Third ACM Conference on Data and Application Security and Privacy, pp. 209\u2013220. ACM (2013)","DOI":"10.1145\/2435349.2435379"},{"key":"458_CR14","doi-asserted-by":"crossref","unstructured":"Sounthiraraj, D., Sahs, J., Greenwood, G., Lin, Z., Khan, L.: Smv-Hunter: large scale, automated detection of ssl\/tls man-in-the-middle vulnerabilities in android apps. In: Proceedings of the 19th Network and Distributed System Security Symposium. San Diego","DOI":"10.14722\/ndss.2014.23205"},{"key":"458_CR15","unstructured":"Yan, L.-K., Yin, H.: Droidscope: seamlessly reconstructing the os and dalvik semantic views for dynamic android malware analysis. In: USENIX Security Symposium, pp. 569\u2013584 (2012)"},{"key":"458_CR16","doi-asserted-by":"crossref","unstructured":"Zheng, C., Zhu, S., Dai, S., Gu, G., Gong, X., Han, X., Zou, W.: Smartdroid: an automatic system for revealing ui-based trigger conditions in android applications. In: Proceedings of the Second ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, pp. 93\u2013104. ACM (2012)","DOI":"10.1145\/2381934.2381950"},{"key":"458_CR17","doi-asserted-by":"crossref","unstructured":"Zuo, C., Wu, J., Guo, S.: Automatically detecting ssl error-handling vulnerabilities in hybrid mobile web apps. In: Proceedings of ASIA CCS \u201915 the 10th ACM Symposium on Information, Computer and Communications Security, pp. 591\u2013596. ACM (2015)","DOI":"10.1145\/2714576.2714583"}],"container-title":["World Wide Web"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11280-017-0458-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-017-0458-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-017-0458-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,23]],"date-time":"2019-09-23T19:10:47Z","timestamp":1569265847000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11280-017-0458-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,5,9]]},"references-count":17,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,1]]}},"alternative-id":["458"],"URL":"https:\/\/doi.org\/10.1007\/s11280-017-0458-9","relation":{},"ISSN":["1386-145X","1573-1413"],"issn-type":[{"value":"1386-145X","type":"print"},{"value":"1573-1413","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,5,9]]}}}