{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T20:03:22Z","timestamp":1778789002954,"version":"3.51.4"},"reference-count":60,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2020,5,29]],"date-time":"2020-05-29T00:00:00Z","timestamp":1590710400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2020,6,30]]},"abstract":"<jats:p>Data security and privacy of Android users is one of the challenging security problems addressed by the security research community. A major source of the security vulnerabilities in Android apps is attributed to bugs within source code, insecure APIs, and unvalidated code before performing sensitive operations. Specifically, the major class of app vulnerabilities is related to the categories such as inter-component communication (ICC), networking, web, cryptographic APIs, storage, and runtime-permission validation. A major portion of current contributions focus on identifying a smaller subset of vulnerabilities. In addition, these methods do not discuss how to remove detected vulnerabilities from the affected code.<\/jats:p>\n          <jats:p>\n            In this work, we propose a novel vulnerability detection and patching framework,\n            <jats:italic>Vulvet<\/jats:italic>\n            , which employs static analysis approaches from different domains of program analysis for detection of a wide range of vulnerabilities in Android apps. We propose an additional light-weight technique,\n            <jats:italic>FP-Validation,<\/jats:italic>\n            to mitigate false positives in comparison to existing solutions owing to over-approximation. In addition to improved detection,\n            <jats:italic>Vulvet<\/jats:italic>\n            provides an automated patching of apps with safe code for each of the identified vulnerability using bytecode instrumentation. We implement\n            <jats:italic>Vulvet<\/jats:italic>\n            as an extension of Soot. To demonstrate the efficiency of our proposed framework, we analyzed 3,700 apps collected from various stores and benchmarks consisting of various weak implementations. Our results indicate that\n            <jats:italic>Vulvet<\/jats:italic>\n            is able to achieve vulnerability detection with 95.23% precision and 0.975 F-measure on benchmark apps; a significant improvement in comparison to recent works along with successful patching of identified vulnerabilities.\n          <\/jats:p>","DOI":"10.1145\/3376121","type":"journal-article","created":{"date-parts":[[2020,5,30]],"date-time":"2020-05-30T04:22:42Z","timestamp":1590812562000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["<i>Vulvet<\/i>"],"prefix":"10.1145","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8223-5975","authenticated-orcid":false,"given":"Jyoti","family":"Gajrani","sequence":"first","affiliation":[{"name":"MNIT Jaipur, Rajasthan, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meenakshi","family":"Tripathi","sequence":"additional","affiliation":[{"name":"MNIT Jaipur, Rajasthan, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vijay","family":"Laxmi","sequence":"additional","affiliation":[{"name":"MNIT Jaipur, Rajasthan, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gaurav","family":"Somani","sequence":"additional","affiliation":[{"name":"Central University of Rajasthan, Ajmer, Rajasthan, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Akka","family":"Zemmari","sequence":"additional","affiliation":[{"name":"LaBRI, Bordeaux INP, University of Bordeaux, CNRS, Bordeaux, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Manoj Singh","family":"Gaur","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Jammu, J8K, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,5,29]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/3155562.3155681"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.36"},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 13th International Conference on Predictive Models and Data Analytics in Software Engineering. ACM, 43--52","author":"Mitra Joydeep","year":"2017","unstructured":"Joydeep Mitra and Venkatesh-Prasad Ranganath . 2017 . Ghera: A repository of Android app vulnerability benchmarks . In Proceedings of the 13th International Conference on Predictive Models and Data Analytics in Software Engineering. ACM, 43--52 . Joydeep Mitra and Venkatesh-Prasad Ranganath. 2017. Ghera: A repository of Android app vulnerability benchmarks. In Proceedings of the 13th International Conference on Predictive Models and Data Analytics in Software Engineering. ACM, 43--52."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2015.2457411"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC\u201907)","author":"Kosuga Yuji","year":"2007","unstructured":"Yuji Kosuga , Kenji Kono , Miyuki Hanaoka , Miho Hishiyama , and Yu Takahama . 2007 . Sania: Syntactic and semantic analysis for automated testing against SQL injection . In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC\u201907) . IEEE, 107--117. Yuji Kosuga, Kenji Kono, Miyuki Hanaoka, Miho Hishiyama, and Yu Takahama. 2007. Sania: Syntactic and semantic analysis for automated testing against SQL injection. In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC\u201907). IEEE, 107--117."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the USENIX Security Symposium","volume":"14","author":"Benjamin Livshits V.","unstructured":"V. Benjamin Livshits and Monica S. Lam . 2005. Finding security vulnerabilities in Java applications with static analysis . In Proceedings of the USENIX Security Symposium , Vol. 14 . V. Benjamin Livshits and Monica S. Lam. 2005. Finding security vulnerabilities in Java applications with static analysis. In Proceedings of the USENIX Security Symposium, Vol. 14."},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 6--pp.","author":"Jovanovic Nenad","year":"2006","unstructured":"Nenad Jovanovic , Christopher Kruegel , and Engin Kirda . 2006 . Pixy: A static analysis tool for detecting web application vulnerabilities . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 6--pp. Nenad Jovanovic, Christopher Kruegel, and Engin Kirda. 2006. Pixy: A static analysis tool for detecting web application vulnerabilities. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 6--pp."},{"key":"e_1_2_1_8_1","first-page":"904","article-title":"Identifying stored security vulnerabilities in computer software applications","volume":"9","author":"Tripp Omer","year":"2018","unstructured":"Omer Tripp and Omri Weisman . 2018 . Identifying stored security vulnerabilities in computer software applications . US Patent 9 , 904 ,786. Omer Tripp and Omri Weisman. 2018. Identifying stored security vulnerabilities in computer software applications. US Patent 9,904,786.","journal-title":"US Patent"},{"key":"e_1_2_1_9_1","unstructured":"MITRE. 2018. Common Vulnerabilities and Exposures (CVE). Retrieved from https:\/\/cve.mitre.org\/cgi-bin\/cvekey.cgi?keyword&equals;Android.  MITRE. 2018. Common Vulnerabilities and Exposures (CVE). Retrieved from https:\/\/cve.mitre.org\/cgi-bin\/cvekey.cgi?keyword&equals;Android."},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the Cetus Users and Compiler Infastructure Workshop (CETUS\u201911)","volume":"15","author":"Lam Patrick","year":"2011","unstructured":"Patrick Lam , Eric Bodden , Ondrej Lhot\u00e1k , and Laurie Hendren . 2011 . The Soot framework for Java program analysis: A retrospective . In Proceedings of the Cetus Users and Compiler Infastructure Workshop (CETUS\u201911) , Vol. 15 . 35. Patrick Lam, Eric Bodden, Ondrej Lhot\u00e1k, and Laurie Hendren. 2011. The Soot framework for Java program analysis: A retrospective. In Proceedings of the Cetus Users and Compiler Infastructure Workshop (CETUS\u201911), Vol. 15. 35."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1999995.2000018"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917)","author":"Lei Lingguang","year":"2017","unstructured":"Lingguang Lei , Yi He , Kun Sun , Jiwu Jing , Yuewu Wang , Qi Li , and Jian Weng . 2017 . Vulnerable implicit service: A revisit . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917) . ACM, New York, NY, 1051--1063. DOI:http:\/\/dx.doi.org\/10.1145\/3133956.3133975 10.1145\/3133956.3133975 Lingguang Lei, Yi He, Kun Sun, Jiwu Jing, Yuewu Wang, Qi Li, and Jian Weng. 2017. Vulnerable implicit service: A revisit. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917). ACM, New York, NY, 1051--1063. DOI:http:\/\/dx.doi.org\/10.1145\/3133956.3133975"},{"key":"e_1_2_1_13_1","volume-title":"CEUR Workshop Proceedings","volume":"1977","author":"Oyetoyan Tosin Daniel","year":"2017","unstructured":"Tosin Daniel Oyetoyan and Marcos Lordello Chaim . 2017 . Comparing capability of static analysis tools to detect security weaknesses in mobile applications . In CEUR Workshop Proceedings Vol. 1977 . 8--18. Tosin Daniel Oyetoyan and Marcos Lordello Chaim. 2017. Comparing capability of static analysis tools to detect security weaknesses in mobile applications. In CEUR Workshop Proceedings Vol. 1977. 8--18."},{"key":"e_1_2_1_14_1","unstructured":"Lori Flynn. 2015. DRD09. Restrict access to sensitive activities. Retrieved from https:\/\/wiki.sei.cmu.edu\/confluence\/display\/android\/DRD09.+Restrict+access+to+sensitive+activities.  Lori Flynn. 2015. DRD09. Restrict access to sensitive activities. Retrieved from https:\/\/wiki.sei.cmu.edu\/confluence\/display\/android\/DRD09.+Restrict+access+to+sensitive+activities."},{"key":"e_1_2_1_15_1","unstructured":"Gaku Mochizuki. 2015. JVN#37825153 AirDroid for Android vulnerable in handling of implicit intents. Retrieved from http:\/\/jvn.jp\/en\/jp\/JVN37825153\/.  Gaku Mochizuki. 2015. JVN#37825153 AirDroid for Android vulnerable in handling of implicit intents. Retrieved from http:\/\/jvn.jp\/en\/jp\/JVN37825153\/."},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the USENIX Security Symposium. 121--136","author":"Xu Wei","year":"2006","unstructured":"Wei Xu , Sandeep Bhatkar , and Ramachandran Sekar . 2006 . Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks . In Proceedings of the USENIX Security Symposium. 121--136 . Wei Xu, Sandeep Bhatkar, and Ramachandran Sekar. 2006. Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. In Proceedings of the USENIX Security Symposium. 121--136."},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 20th Network and Distributed System Security Symposium (NDSS\u201913)","author":"Xuxian Jiang Yajin Zhou","year":"2013","unstructured":"Yajin Zhou Xuxian Jiang and Zhou Xuxian . 2013 . Detecting passive content leaks and pollution in Android applications . In Proceedings of the 20th Network and Distributed System Security Symposium (NDSS\u201913) . Yajin Zhou Xuxian Jiang and Zhou Xuxian. 2013. Detecting passive content leaks and pollution in Android applications. In Proceedings of the 20th Network and Distributed System Security Symposium (NDSS\u201913)."},{"key":"e_1_2_1_18_1","unstructured":"Hiroshi Kumagai. 2014. JVN#55438786 Content Provider in CamiApp for Android fails to restrict access permissions. Retrieved from http:\/\/jvn.jp\/en\/jp\/JVN55438786\/index.html.  Hiroshi Kumagai. 2014. JVN#55438786 Content Provider in CamiApp for Android fails to restrict access permissions. Retrieved from http:\/\/jvn.jp\/en\/jp\/JVN55438786\/index.html."},{"key":"e_1_2_1_19_1","volume-title":"Man in the middle attacks demos","author":"Ornaghi Alberto","year":"2003","unstructured":"Alberto Ornaghi and Marco Valleri . 2003. Man in the middle attacks demos , 2003 . https:\/\/bbs.pku.edu.cn\/attach\/53\/35\/533561f8d8187eb6\/ManInMiddle.pdf (visited: 2020-05-04). Alberto Ornaghi and Marco Valleri. 2003. Man in the middle attacks demos, 2003. https:\/\/bbs.pku.edu.cn\/attach\/53\/35\/533561f8d8187eb6\/ManInMiddle.pdf (visited: 2020-05-04)."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076781"},{"key":"e_1_2_1_21_1","unstructured":"NIST. 2018. CVE-2018-5298 Detail. Retrieved from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-5298.  NIST. 2018. CVE-2018-5298 Detail. Retrieved from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-5298."},{"key":"e_1_2_1_22_1","unstructured":"MITRE.\n     2014. CVE-2014-5930.\n   (\n  2014\n  ). Retrieved from https:\/\/www.cvedetails.com\/cve\/CVE-2014-5930\/.  MITRE. 2014. CVE-2014-5930. (2014). Retrieved from https:\/\/www.cvedetails.com\/cve\/CVE-2014-5930\/."},{"key":"e_1_2_1_23_1","unstructured":"MITRE.\n     2014. CVE-2014-7609.\n   (\n  2014\n  ). Retrieved from https:\/\/www.cvedetails.com\/cve\/CVE-2014-7609\/.  MITRE. 2014. CVE-2014-7609. (2014). Retrieved from https:\/\/www.cvedetails.com\/cve\/CVE-2014-7609\/."},{"key":"e_1_2_1_24_1","unstructured":"Checkmarx. 2018. Common Vulnerabilities and Exposures (CVE). Retrieved from https:\/\/www.checkmarx.com\/2018\/01\/23\/tinder-someone-may-watching-swipe-2\/.  Checkmarx. 2018. Common Vulnerabilities and Exposures (CVE). Retrieved from https:\/\/www.checkmarx.com\/2018\/01\/23\/tinder-someone-may-watching-swipe-2\/."},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the 21st Network and Distributed System Security Symposium (NDSS\u201914)","author":"Zhang Mu","year":"2014","unstructured":"Mu Zhang and Heng Yin . 2014 . AppSealer: Automatic generation of vulnerability-specific patches for preventing component hijacking attacks in Android applications . In Proceedings of the 21st Network and Distributed System Security Symposium (NDSS\u201914) . Citeseer. Mu Zhang and Heng Yin. 2014. AppSealer: Automatic generation of vulnerability-specific patches for preventing component hijacking attacks in Android applications. In Proceedings of the 21st Network and Distributed System Security Symposium (NDSS\u201914). Citeseer."},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201916)","volume":"16","author":"Michelle","unstructured":"Michelle Y. Wong and David Lie. 2016. IntelliDroid: A targeted input generator for the dynamic analysis of Android malware . In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201916) , Vol. 16 . 21--24. Michelle Y. Wong and David Lie. 2016. IntelliDroid: A targeted input generator for the dynamic analysis of Android malware. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201916), Vol. 16. 21--24."},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201914)","volume":"14","author":"Rasthofer Siegfried","year":"2014","unstructured":"Siegfried Rasthofer , Steven Arzt , and Eric Bodden . 2014 . A machine-learning approach for classifying and categorizing Android sources and sinks . In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201914) , Vol. 14 . Citeseer, 1125. Siegfried Rasthofer, Steven Arzt, and Eric Bodden. 2014. A machine-learning approach for classifying and categorizing Android sources and sinks. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201914), Vol. 14. Citeseer, 1125."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594299"},{"key":"e_1_2_1_29_1","unstructured":"Yu-Cheng Lin. 2015. Androbugs Framework Project. Retrieved from https:\/\/github.com\/AndroBugs\/AndroBugs_Framework.  Yu-Cheng Lin. 2015. Androbugs Framework Project. Retrieved from https:\/\/github.com\/AndroBugs\/AndroBugs_Framework."},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the 47th IEEE\/IFIP International Conference on Dependable Systems and Networks Workshop (DSN-W\u201917)","author":"Tien Chia-Wei","year":"2017","unstructured":"Chia-Wei Tien , Tse-Yung Huang , Ting-Chun Huang , Wei-Ho Chung , and Sy-Yen Kuo . 2017 . MAS: Mobile-apps assessment and analysis system . In Proceedings of the 47th IEEE\/IFIP International Conference on Dependable Systems and Networks Workshop (DSN-W\u201917) . IEEE, 145--148. Chia-Wei Tien, Tse-Yung Huang, Ting-Chun Huang, Wei-Ho Chung, and Sy-Yen Kuo. 2017. MAS: Mobile-apps assessment and analysis system. In Proceedings of the 47th IEEE\/IFIP International Conference on Dependable Systems and Networks Workshop (DSN-W\u201917). IEEE, 145--148."},{"key":"e_1_2_1_31_1","volume-title":"ACM Sigplan Not.","volume":"5","author":"Allen Frances E.","year":"1970","unstructured":"Frances E. Allen . 1970 . Control flow analysis . ACM Sigplan Not. , Vol. 5 . ACM, 1--19. Frances E. Allen. 1970. Control flow analysis. ACM Sigplan Not., Vol. 5. ACM, 1--19."},{"key":"e_1_2_1_32_1","unstructured":"2018. Findsecbugs. Retrieved from https:\/\/find-sec-bugs.github.io\/.  2018. Findsecbugs. Retrieved from https:\/\/find-sec-bugs.github.io\/."},{"key":"e_1_2_1_33_1","unstructured":"Edward Flanker and Anant Shrivastava. 2014. Joint Advanced Defect assEsment for Android applications. Retrieved from https:\/\/github.com\/flankerhqd\/JAADAS.  Edward Flanker and Anant Shrivastava. 2014. Joint Advanced Defect assEsment for Android applications. Retrieved from https:\/\/github.com\/flankerhqd\/JAADAS."},{"key":"e_1_2_1_34_1","unstructured":"Google Play market. Retrieved from http:\/\/play.google.com\/store\/apps\/.  Google Play market. Retrieved from http:\/\/play.google.com\/store\/apps\/."},{"key":"e_1_2_1_35_1","unstructured":"2014 PlayDrone Android Apps. Retrieved from https:\/\/archive.org\/details\/android.  2014 PlayDrone Android Apps. Retrieved from https:\/\/archive.org\/details\/android."},{"key":"e_1_2_1_36_1","unstructured":"Nduo Market. Retrieved from https:\/\/www.nduo.cn\/.  Nduo Market. Retrieved from https:\/\/www.nduo.cn\/."},{"key":"e_1_2_1_37_1","unstructured":"Mobomarket. Retrieved from https:\/\/mobomarket.jaleco.com\/.  Mobomarket. Retrieved from https:\/\/mobomarket.jaleco.com\/."},{"key":"e_1_2_1_38_1","unstructured":"APK4Fun. Retrieved from https:\/\/www.apk4fun.com\/.  APK4Fun. Retrieved from https:\/\/www.apk4fun.com\/."},{"key":"e_1_2_1_39_1","unstructured":"GFAN. Retrieved from http:\/\/apk.gfan.com\/.  GFAN. Retrieved from http:\/\/apk.gfan.com\/."},{"key":"e_1_2_1_40_1","unstructured":"Androidpur. Retrieved from http:\/\/androidpur.org\/.  Androidpur. Retrieved from http:\/\/androidpur.org\/."},{"key":"e_1_2_1_41_1","unstructured":"APPSAPK. Retrieved from https:\/\/www.appsapk.com\/.  APPSAPK. Retrieved from https:\/\/www.appsapk.com\/."},{"key":"e_1_2_1_42_1","unstructured":"CWE-329. Retrieved from https:\/\/cwe.mitre.org\/data\/definitions\/329.html.  CWE-329. Retrieved from https:\/\/cwe.mitre.org\/data\/definitions\/329.html."},{"key":"e_1_2_1_43_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1533--1546","author":"Chhotaray Animesh","year":"2017","unstructured":"Animesh Chhotaray , Adib Nahiyan , Thomas Shrimpton , Domenic Forte , and Mark Tehranipoor . 2017 . Standardizing bad cryptographic practice: A teardown of the IEEE standard for protecting electronic-design intellectual property . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1533--1546 . Animesh Chhotaray, Adib Nahiyan, Thomas Shrimpton, Domenic Forte, and Mark Tehranipoor. 2017. Standardizing bad cryptographic practice: A teardown of the IEEE standard for protecting electronic-design intellectual property. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1533--1546."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"e_1_2_1_45_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1105--1116","author":"Zhang Mu","year":"2014","unstructured":"Mu Zhang , Yue Duan , Heng Yin , and Zhiruo Zhao . 2014 . Semantics-aware Android malware classification using weighted contextual API dependency graphs . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1105--1116 . Mu Zhang, Yue Duan, Heng Yin, and Zhiruo Zhao. 2014. Semantics-aware Android malware classification using weighted contextual API dependency graphs. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1105--1116."},{"key":"e_1_2_1_46_1","volume-title":"Proceedings of the International Symposium on Software Testing and Analysis. ACM, 71--82","author":"Wang Haoyu","year":"2015","unstructured":"Haoyu Wang , Yao Guo , Ziang Ma , and Xiangqun Chen . 2015 . Wukong: A scalable and accurate two-phase approach to Android app clone detection . In Proceedings of the International Symposium on Software Testing and Analysis. ACM, 71--82 . Haoyu Wang, Yao Guo, Ziang Ma, and Xiangqun Chen. 2015. Wukong: A scalable and accurate two-phase approach to Android app clone detection. In Proceedings of the International Symposium on Software Testing and Analysis. ACM, 71--82."},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the 2nd ACM Conference on Data and Application Security and Privacy. ACM, 317--326","author":"Zhou Wu","year":"2012","unstructured":"Wu Zhou , Yajin Zhou , Xuxian Jiang , and Peng Ning . 2012 . Detecting repackaged smartphone applications in third-party Android marketplaces . In Proceedings of the 2nd ACM Conference on Data and Application Security and Privacy. ACM, 317--326 . Wu Zhou, Yajin Zhou, Xuxian Jiang, and Peng Ning. 2012. Detecting repackaged smartphone applications in third-party Android marketplaces. In Proceedings of the 2nd ACM Conference on Data and Application Security and Privacy. ACM, 317--326."},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the IEEE 23rd International Conference on Program Comprehension. IEEE Press, 163--173","author":"Soh Charlie","year":"2015","unstructured":"Charlie Soh , Hee Beng Kuan Tan , Yauhen Leanidavich Arnatovich , and Lipo Wang . 2015 . Detecting clones in Android applications through analyzing user interfaces . In Proceedings of the IEEE 23rd International Conference on Program Comprehension. IEEE Press, 163--173 . Charlie Soh, Hee Beng Kuan Tan, Yauhen Leanidavich Arnatovich, and Lipo Wang. 2015. Detecting clones in Android applications through analyzing user interfaces. In Proceedings of the IEEE 23rd International Conference on Program Comprehension. IEEE Press, 163--173."},{"key":"e_1_2_1_49_1","volume-title":"Proceedings of the ACM on Asia Conference on Computer and Communications Security. ACM, 71--85","author":"Bosu Amiangshu","year":"2017","unstructured":"Amiangshu Bosu , Fang Liu , Danfeng Daphne Yao , and Gang Wang . 2017 . Collusive data leak and more: Large-scale threat analysis of inter-app communications . In Proceedings of the ACM on Asia Conference on Computer and Communications Security. ACM, 71--85 . Amiangshu Bosu, Fang Liu, Danfeng Daphne Yao, and Gang Wang. 2017. Collusive data leak and more: Large-scale threat analysis of inter-app communications. In Proceedings of the ACM on Asia Conference on Computer and Communications Security. ACM, 71--85."},{"key":"e_1_2_1_50_1","unstructured":"Japan Smart Phone Security Association. 2016. Android Application Secure Design\/Secure Coding Guidebook. Retrieved from https:\/\/www.jssec.org\/dl\/android_securecoding.pdf.  Japan Smart Phone Security Association. 2016. Android Application Secure Design\/Secure Coding Guidebook. Retrieved from https:\/\/www.jssec.org\/dl\/android_securecoding.pdf."},{"key":"e_1_2_1_51_1","doi-asserted-by":"crossref","unstructured":"Steve Quirolgico Jeffrey Voas Tom Karygiannis Christoph Michael and Karen Scarfone. 2015. Vetting the Security of Mobile Applications. Retrieved from http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-163.pdf.  Steve Quirolgico Jeffrey Voas Tom Karygiannis Christoph Michael and Karen Scarfone. 2015. Vetting the Security of Mobile Applications. Retrieved from http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-163.pdf.","DOI":"10.6028\/NIST.SP.800-163"},{"key":"e_1_2_1_52_1","unstructured":"Taiwan Industrial Development Bureau Ministry of Economic Affairs. 2016. Mobile Application Security Guideline. Retrieved from http:\/\/www.mas.org.tw\/spaw2\/uploads\/files\/1050219-1.pdf.  Taiwan Industrial Development Bureau Ministry of Economic Affairs. 2016. Mobile Application Security Guideline. Retrieved from http:\/\/www.mas.org.tw\/spaw2\/uploads\/files\/1050219-1.pdf."},{"key":"e_1_2_1_53_1","volume-title":"Proceedings of the ACM International Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software (Onward!). ACM, 1--13","author":"Arzt Steven","year":"2015","unstructured":"Steven Arzt , Sarah Nadi , Karim Ali , Eric Bodden , Sebastian Erdweg , and Mira Mezini . 2015 . Towards secure integration of cryptographic software . In Proceedings of the ACM International Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software (Onward!). ACM, 1--13 . Steven Arzt, Sarah Nadi, Karim Ali, Eric Bodden, Sebastian Erdweg, and Mira Mezini. 2015. Towards secure integration of cryptographic software. In Proceedings of the ACM International Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software (Onward!). ACM, 1--13."},{"key":"e_1_2_1_54_1","volume-title":"Proceedings of the IEEE\/ACM 37th IEEE International Conference on Software Engineering (ICSE\u201915)","volume":"2","author":"Sadeghi Alireza","year":"2015","unstructured":"Alireza Sadeghi , Hamid Bagheri , and Sam Malek . 2015 . Analysis of Android inter-app security vulnerabilities using COVERT . In Proceedings of the IEEE\/ACM 37th IEEE International Conference on Software Engineering (ICSE\u201915) , Vol. 2 . IEEE, 725--728. Alireza Sadeghi, Hamid Bagheri, and Sam Malek. 2015. Analysis of Android inter-app security vulnerabilities using COVERT. In Proceedings of the IEEE\/ACM 37th IEEE International Conference on Software Engineering (ICSE\u201915), Vol. 2. IEEE, 725--728."},{"key":"e_1_2_1_55_1","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security. ACM, 229--240","author":"Lu Long","year":"2012","unstructured":"Long Lu , Zhichun Li , Zhenyu Wu , Wenke Lee , and Guofei Jiang . 2012 . CHEX: Statically vetting Android apps for component hijacking vulnerabilities . In Proceedings of the ACM Conference on Computer and Communications Security. ACM, 229--240 . Long Lu, Zhichun Li, Zhenyu Wu, Wenke Lee, and Guofei Jiang. 2012. CHEX: Statically vetting Android apps for component hijacking vulnerabilities. In Proceedings of the ACM Conference on Computer and Communications Security. ACM, 229--240."},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the 21stNetwork and Distributed System Security Symposium (NDSS\u201914)","author":"Sounthiraraj David","year":"2014","unstructured":"David Sounthiraraj , Justin Sahs , Garret Greenwood , Zhiqiang Lin , and Latifur Khan . 2014 . SMV-HUNTER: Large scale, automated detection of SSL\/TLS man-in-the-middle vulnerabilities in Android apps . In Proceedings of the 21stNetwork and Distributed System Security Symposium (NDSS\u201914) . Citeseer. David Sounthiraraj, Justin Sahs, Garret Greenwood, Zhiqiang Lin, and Latifur Khan. 2014. SMV-HUNTER: Large scale, automated detection of SSL\/TLS man-in-the-middle vulnerabilities in Android apps. In Proceedings of the 21stNetwork and Distributed System Security Symposium (NDSS\u201914). Citeseer."},{"key":"e_1_2_1_57_1","unstructured":"Google Developers. 2018. Android Lint. Retrieved from https:\/\/developer.android.com\/studio\/write\/lint.  Google Developers. 2018. Android Lint. Retrieved from https:\/\/developer.android.com\/studio\/write\/lint."},{"key":"e_1_2_1_58_1","volume-title":"Static detection and automatic exploitation of intent message vulnerabilities in android applications","author":"Gallingani Daniele","year":"2014","unstructured":"Daniele Gallingani , Rigel Gjomemo , VN Venkatakrishnan , and Stefano Zanero . 2014. Static detection and automatic exploitation of intent message vulnerabilities in android applications , 2014 . http:\/\/www.ieee-security.org\/TC\/SPW2015\/MoST\/papers\/s3p1.pdf (visited: 2020-05-04). Daniele Gallingani, Rigel Gjomemo, VN Venkatakrishnan, and Stefano Zanero. 2014. Static detection and automatic exploitation of intent message vulnerabilities in android applications, 2014. http:\/\/www.ieee-security.org\/TC\/SPW2015\/MoST\/papers\/s3p1.pdf (visited: 2020-05-04)."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23328"},{"key":"e_1_2_1_60_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1329--1341","author":"Wei Fengguo","year":"2014","unstructured":"Fengguo Wei , Sankardas Roy , Xinming Ou , 2014 . Amandroid: A precise and general inter-component data flow analysis framework for security vetting of Android apps . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1329--1341 . Fengguo Wei, Sankardas Roy, Xinming Ou, et al. 2014. Amandroid: A precise and general inter-component data flow analysis framework for security vetting of Android apps. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 1329--1341."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3376121","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3376121","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:34Z","timestamp":1750203874000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3376121"}},"subtitle":["Vetting of Vulnerabilities in Android Apps to Thwart Exploitation"],"short-title":[],"issued":{"date-parts":[[2020,5,29]]},"references-count":60,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2020,6,30]]}},"alternative-id":["10.1145\/3376121"],"URL":"https:\/\/doi.org\/10.1145\/3376121","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,5,29]]},"assertion":[{"value":"2019-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-05-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}