{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:31:31Z","timestamp":1783791091967,"version":"3.55.0"},"reference-count":60,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2015,9,1]],"date-time":"2015-09-01T00:00:00Z","timestamp":1441065600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/100000185","name":"US Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["D11AP00282"],"award-info":[{"award-number":["D11AP00282"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"name":"US National Security Agency","award":["H98230-14-C-0140"],"award-info":[{"award-number":["H98230-14-C-0140"]}]},{"DOI":"10.13039\/100000180","name":"US Department of Homeland Security","doi-asserted-by":"publisher","award":["HSHQDC-14-C-B0040"],"award-info":[{"award-number":["HSHQDC-14-C-B0040"]}],"id":[{"id":"10.13039\/100000180","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"US National Science Foundation","doi-asserted-by":"publisher","award":["CCF-1252644"],"award-info":[{"award-number":["CCF-1252644"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IIEEE Trans. Software Eng."],"published-print":{"date-parts":[[2015,9,1]]},"DOI":"10.1109\/tse.2015.2419611","type":"journal-article","created":{"date-parts":[[2015,4,3]],"date-time":"2015-04-03T20:45:02Z","timestamp":1428093902000},"page":"866-886","source":"Crossref","is-referenced-by-count":100,"title":["COVERT: Compositional Analysis of Android Inter-App Permission Leakage"],"prefix":"10.1109","volume":"41","author":[{"given":"Hamid","family":"Bagheri","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alireza","family":"Sadeghi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joshua","family":"Garcia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sam","family":"Malek","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Permission re-delegation: Attacks and defenses","author":"felt","year":"2011","journal-title":"20th USENIX Security Symp"},{"key":"ref38","article-title":"Scandroid: Automated security certification of android applications","year":"0"},{"key":"ref33","year":"0","journal-title":"Proc 22nd USENIX Security Symp"},{"key":"ref32","article-title":"Systematic detection of capability leaks in stock android smartphones","author":"grace","year":"0","journal-title":"Proc 19th Annu Netw Distrib Syst Security Symp"},{"key":"ref31","first-page":"291","article-title":"Androidleaks: Automatically detecting potential privacy leaks in android applications on a large scale","author":"gibler","year":"0","journal-title":"Trust and Trustworthy Computing"},{"key":"ref30","article-title":"A study of android application security","author":"enck","year":"2011","journal-title":"Proc 20th USENIX Conf Security"},{"key":"ref37","article-title":"Android taint flow analysis for app sets","year":"0","journal-title":"Proc 3rd ACM SIGPLAN Int Workshop State Art Java Program Anal"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382223"},{"key":"ref35","article-title":"Detecting passive content leaks and pollution in android applications","author":"zhou","year":"2013","journal-title":"Proc Symp Netw Distrib Syst Security"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/2245276.2232009"},{"key":"ref60","article-title":"Spacemaker: practical formal synthesis of tradeoff spaces for object-relational mapping","year":"0","journal-title":"24th Int Conf on Software Engineering and Knowledge Engineering"},{"key":"ref28","first-page":"259","article-title":"FlowDroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps","author":"arzt","year":"2014","journal-title":"Proc 35th Annu ACM SIGPLAN Conf Programm Lang Design Implementation"},{"key":"ref27","year":"0"},{"key":"ref29","year":"0"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/1999995.2000018"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.2"},{"key":"ref20","year":"0"},{"key":"ref22","first-page":"346","article-title":"Privilege escalation attacks on android","author":"davi","year":"0","journal-title":"Proc 13th Int Conf Inf Security"},{"key":"ref21","article-title":"Flow permissions for android","year":"0","journal-title":"Proc 28th Int IEEE\/ACM Conf Autom Softw Eng"},{"key":"ref24","year":"0"},{"key":"ref23","year":"0"},{"key":"ref26","year":"0"},{"key":"ref25","year":"0"},{"key":"ref50","article-title":"A lightweight code analysis and its role in evaluation of a dependability case","year":"0","journal-title":"Proc 3rd Int Conf Software Engineering"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2010.01.049"},{"key":"ref59","article-title":"TradeMaker: automated dynamic analysis of synthesized tradespaces","year":"0","journal-title":"Proc 36th Int Conf Soft Eng (ICSE '14)"},{"key":"ref58","article-title":"Architectural style as an independent variable","year":"0","journal-title":"Proc 25th IEEE\/ACM Int Conf Automated Soft Eng (ASE '10)"},{"key":"ref57","year":"0","journal-title":"Proc 9th Joint Meeting Found Softw Eng"},{"key":"ref56","article-title":"Design and validation of a general security model with the alloy analyzer","year":"0","journal-title":"Proc ACM SIGSOFT 1st Alloy Workshop"},{"key":"ref55","year":"0"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/s00165-007-0058-z"},{"key":"ref53","first-page":"238","article-title":"Query-aware test generation using a relational constraint solver","author":"khalek","year":"2008","journal-title":"Proc 23rd IEEE\/ACM Int Conf Automated Softw Eng"},{"key":"ref52","article-title":"Monarch: Model-based development of software architectures","year":"0","journal-title":"Proc 13th ACM\/IEEE Int'l Conf Model-Driven Engineering Languages and Systems"},{"key":"ref10","year":"0","journal-title":"TOSEM"},{"key":"ref11","first-page":"13","article-title":"Soot&#x2014;a Java bytecode optimization framework","author":"\u00e9-rai","year":"0","journal-title":"Proc Conf Centre Adv Stud Collaborative Res"},{"key":"ref40","article-title":"Semantically rich application-centric security in android","year":"0","journal-title":"Proc 25th Annu Comput Security Appl Conf"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2259051.2259056"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/1592434.1592436"},{"key":"ref14","article-title":"A practical comparison of alloy and spin","year":"0"},{"key":"ref15","year":"0"},{"key":"ref16","author":"aho","year":"2006","journal-title":"Compilers Principles Techniques and Tools"},{"key":"ref17","year":"0"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382222"},{"key":"ref19","doi-asserted-by":"crossref","first-page":"210","DOI":"10.1007\/978-3-642-37057-1_15","article-title":"ANDROMEDA: Accurate and scalable security analysis of web applications","author":"tripp","year":"2013","journal-title":"Proc 16th Int Conf Fundam Approaches Softw Eng"},{"key":"ref4","first-page":"639","article-title":"These aren&#x2019;t the droids you&#x2019;re looking for: Retrofitting android to protect data from imperious applications","author":"hornyack","year":"0","journal-title":"Proc ACM Conf Comput Commun Security"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/2619091"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653691"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046779"},{"key":"ref8","article-title":"Towards taming privilege-escalation attacks on android","author":"bugiel","year":"0"},{"key":"ref7","year":"0","journal-title":"Proc ESORICS"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/347324.383378"},{"key":"ref9","article-title":"Quire: Lightweight provenance for smart phone operating systems","author":"dietz","year":"0","journal-title":"Proc 20th USENIX Seurity Symp"},{"key":"ref46","article-title":"Language-based security on android","year":"0","journal-title":"Proc Programm Lang Anal Security"},{"key":"ref45","article-title":"Whyper: Towards automating risk assessment of mobile applications","year":"0","journal-title":"Proc 22nd USENIX Conf Security"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/582419.582441"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/1103845.1094840"},{"key":"ref42","article-title":"Hey, you, get off of my market: Detecting malicious apps in official and alternative android markets","author":"zhou","year":"2012","journal-title":"Proc Symp Netw Distrib Syst Security"},{"key":"ref41","article-title":"A methodology for empirical analysis of permission-based security models and its application to android","year":"0","journal-title":"Proc 17th ACM Conf Comput Commun Security"},{"key":"ref44","article-title":"Curbing android permission creep","author":"vidas","year":"2011","journal-title":"IEEE Web 2 0 Security and Privacy Workshop"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/2307636.2307663"}],"container-title":["IEEE Transactions on Software Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/32\/7268815\/07079508.pdf?arnumber=7079508","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:01:56Z","timestamp":1642003316000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7079508\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,9,1]]},"references-count":60,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tse.2015.2419611","relation":{},"ISSN":["0098-5589","1939-3520"],"issn-type":[{"value":"0098-5589","type":"print"},{"value":"1939-3520","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,9,1]]}}}