{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T15:49:30Z","timestamp":1767973770667,"version":"3.49.0"},"reference-count":20,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2016,9,12]],"date-time":"2016-09-12T00:00:00Z","timestamp":1473638400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Sci. China Inf. Sci."],"published-print":{"date-parts":[[2017,5]]},"DOI":"10.1007\/s11432-015-5422-7","type":"journal-article","created":{"date-parts":[[2016,9,20]],"date-time":"2016-09-20T11:59:12Z","timestamp":1474372752000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["A static technique for detecting input validation vulnerabilities in Android apps","\u57fa\u4e8e\u9759\u6001\u5206\u6790\u7684Android\u5e94\u7528\u8f6f\u4ef6\u8f93\u5165\u9a8c\u8bc1\u6f0f\u6d1e\u6316\u6398\u6280\u672f"],"prefix":"10.1007","volume":"60","author":[{"given":"Zhejun","family":"Fang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qixu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuqing","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kai","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiqiang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qianru","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,12]]},"reference":[{"key":"5422_CR1","unstructured":"Category: input validation on owasp. https:\/\/www.owasp.org\/index.php\/Category:Input Validation"},{"key":"5422_CR2","volume-title":"Proceedings of the 19th Annual Symposium on Network and Distributed System Security (NDSS\u201912)","author":"M Grace","year":"2012","unstructured":"Grace M, Zhou Y J, Wang Z, et al. Systematic detection of capability leaks in stock Android smartphones. In: Proceedings of the 19th Annual Symposium on Network and Distributed System Security (NDSS\u201912), San Diego, 2012"},{"key":"5422_CR3","first-page":"22","volume-title":"Proceedings of the 20th USENIX Conference on Security (Sec\u201911), San Francisco","author":"A P Felt","year":"2011","unstructured":"Felt A P, Wang H J, Moshchuk A, et al. Permission re-delegation: attacks and defenses. In: Proceedings of the 20th USENIX Conference on Security (Sec\u201911), San Francisco, 2011. 22\u201338"},{"key":"5422_CR4","volume-title":"Proceedings of the 20th Network and Distributed System Security Symposium (NDSS\u201913)","author":"Y J Zhou","year":"2013","unstructured":"Zhou Y J, Jiang X X. Detecting passive content leaks and pollution in Android applications. In: Proceedings of the 20th Network and Distributed System Security Symposium (NDSS\u201913), San Diego, 2013"},{"key":"5422_CR5","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1145\/2382196.2382223","volume-title":"Proceedings of the 2012 ACM Conference on Computer and Communications Security (CCS\u201912), Raleigh","author":"L Lu","year":"2012","unstructured":"Lu L, Li Z C, Wu Z Y, et al. Chex: statically vetting android apps for component hijacking vulnerabilities. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security (CCS\u201912), Raleigh, 2012. 229\u2013240"},{"key":"5422_CR6","volume-title":"Proceedings of the 21th Annual Network and Distributed System Security Symposium (NDSS\u201914)","author":"M Zhang","year":"2014","unstructured":"Zhang M, Yin H. AppSealer: automatic generation of vulnerability-specific patches for preventing component hijacking attacks in Android applications. In: Proceedings of the 21th Annual Network and Distributed System Security Symposium (NDSS\u201914), San Diego, 2014"},{"key":"5422_CR7","first-page":"531","volume-title":"Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security (ASIA CCS 2014), Kyoto","author":"K Yang","year":"2014","unstructured":"Yang K, Zhuge JW, Wang Y K, et al. IntentFuzzer: detecting capability leaks of Android applications. In: Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security (ASIA CCS 2014), Kyoto, 2014. 531\u2013536"},{"key":"5422_CR8","volume-title":"SCanDroid: automated security certification of Android applications","author":"A P Fuchs","year":"2009","unstructured":"Fuchs A P, Chaudhuri A, Foster J S. SCanDroid: automated security certification of Android applications. Technical Report CS-TR-4991. 2009"},{"key":"5422_CR9","doi-asserted-by":"crossref","first-page":"347","DOI":"10.1007\/s10207-014-0260-y","volume":"14","author":"T Mustafa","year":"2012","unstructured":"Mustafa T, Sohr K. Understanding the implemented access control policy of Android system services with slicing and extended static checking. Int J Inf Secur, 2012, 14: 347\u2013366","journal-title":"Int J Inf Secur"},{"key":"5422_CR10","first-page":"235","volume-title":"Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS\u201909), Chicago","author":"W Enck","year":"2009","unstructured":"Enck W, Ongtang M, McDaniel P. On lightweight mobile phone application certification. In: Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS\u201909), Chicago, 2009. 235\u2013245"},{"key":"5422_CR11","volume-title":"Smishing vulnerability in multiple Android platforms","author":"X X Jiang","year":"2012","unstructured":"Jiang X X. Smishing vulnerability in multiple Android platforms (including Gingerbread, Ice Cream Sandwich, and Jelly Bean). http:\/\/www.csc.ncsu.edu\/faculty\/jiang\/smishing.html, 2012"},{"key":"5422_CR12","unstructured":"Thomascannon. Android sms spoofer. https:\/\/github.com\/thomascannon\/android-sms-spoof, 2012"},{"key":"5422_CR13","doi-asserted-by":"crossref","first-page":"519","DOI":"10.1002\/sec.747","volume":"7","author":"Z J Fang","year":"2014","unstructured":"Fang Z J, Zhang Y Q, Kong Y, et al. Static detection of logic vulnerabilities in Java web applications. Secur Commun Netw, 2014, 7: 519\u2013531","journal-title":"Secur Commun Netw"},{"key":"5422_CR14","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1109\/MSP.2009.26","volume":"7","author":"W Enck","year":"2009","unstructured":"Enck W, Ongtang M, Mc Daniel P. Understanding Android security. IEEE Secur Priv, 2009, 7: 50\u201357","journal-title":"IEEE Secur Priv"},{"key":"5422_CR15","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1145\/2382196.2382222","volume-title":"Proceedings of the 2012 ACM Conference on Computer and Communications Security (CCS\u201912), Raleigh","author":"K W Y Au","year":"2012","unstructured":"Au K W Y, Zhou Y F, Huang Z, et al. Pscout: analyzing the Android permission specification. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security (CCS\u201912), Raleigh, 2012. 217\u2013228"},{"key":"5422_CR16","first-page":"21","volume-title":"Proceedings of the 20th USENIX Conference on Security (SEC\u201911), San Francisco","author":"W Enck","year":"2011","unstructured":"Enck W, Octeau D, McDaniel P, et al. A study of Android application security. In: Proceedings of the 20th USENIX Conference on Security (SEC\u201911), San Francisco, 2011. 21\u201337"},{"key":"5422_CR17","first-page":"627","volume-title":"Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS\u201911), Chicago","author":"A P Felt","year":"2011","unstructured":"Felt A P, Chin E, Hanna S, et al. Android permissions demystified. In: Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS\u201911), Chicago, 2011. 627\u2013638"},{"key":"5422_CR18","first-page":"235","volume-title":"Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS\u201909), Chicago","author":"W Enck","year":"2009","unstructured":"Enck W, Ongtang M, Mc Daniel P. On lightweight mobile phone application certification. In: Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS\u201909), Chicago, 2009. 235\u2013245"},{"key":"5422_CR19","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1109\/CSMR.2013.37","volume-title":"Proceedings of 17th European Conference on Software Maintenance and Reengineering (CSMR\u201913), Genova","author":"B J Berger","year":"2013","unstructured":"Berger B J, Sohr K, Koschke R. Extracting and analyzing the implemented security architecture of business applications. In: Proceedings of 17th European Conference on Software Maintenance and Reengineering (CSMR\u201913), Genova, 2013. 285\u2013294"},{"key":"5422_CR20","first-page":"012101","volume":"58","author":"Y Q Zhang","year":"2014","unstructured":"Zhang Y Q, Liu Q X, Luo Q H, et al. XAS: Cross-API scripting attacks in social ecosystems. Sci China Inf Sci, 2014, 58: 012101","journal-title":"Sci China Inf Sci"}],"container-title":["Science China Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-015-5422-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11432-015-5422-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-015-5422-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,24]],"date-time":"2017-06-24T23:14:28Z","timestamp":1498346068000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11432-015-5422-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,9,12]]},"references-count":20,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2017,5]]}},"alternative-id":["5422"],"URL":"https:\/\/doi.org\/10.1007\/s11432-015-5422-7","relation":{},"ISSN":["1674-733X","1869-1919"],"issn-type":[{"value":"1674-733X","type":"print"},{"value":"1869-1919","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,9,12]]},"article-number":"052111"}}