{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T16:24:53Z","timestamp":1783095893060,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,12]],"date-time":"2021-11-12T00:00:00Z","timestamp":1636675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Strategic Priority Research Program of Chinese Academy of Sciences","award":["No. XDC02040100"],"award-info":[{"award-number":["No. XDC02040100"]}]},{"name":"Shandong Key Research and Development Program","award":["No. 2020ZLYS09"],"award-info":[{"award-number":["No. 2020ZLYS09"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,12]]},"DOI":"10.1145\/3460120.3484801","type":"proceedings-article","created":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T12:05:27Z","timestamp":1636805127000},"page":"1581-1597","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Ghost in the Binder: Binder Transaction Redirection Attacks in Android System Services"],"prefix":"10.1145","author":[{"given":"Xiaobo","family":"Xiang","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences; University of Chinese Academy of Sciences; Alpha Lab; and 360 Government &amp; Enterprise Security Group, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ren","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nervos &amp; Shandong Institute of Blockchain, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hanxiang","family":"Wen","sequence":"additional","affiliation":[{"name":"Ant Group, Hanzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaorui","family":"Gong","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Baoxu","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,11,13]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Yousra Aafer Jianjun Huang Yi Sun Xiangyu Zhang Ninghui Li and Chen Tian. 2018a. AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency Detection. In NDSS.","DOI":"10.14722\/ndss.2018.23121"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243842"},{"key":"e_1_3_2_1_3_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Aafer Yousra","year":"2021","unstructured":"Yousra Aafer, Wei You, Yi Sun, Yu Shi, Xiangyu Zhang, and Heng Yin. 2021. Android SmartTVs Vulnerability Discovery via Log-Guided Fuzzing. In 30th USENIX Security Symposium (USENIX Security 21)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2338965.2336760"},{"key":"e_1_3_2_1_5_1","unstructured":"Android Code Search. 2021 a. libbinder: Add SafeInterface. https:\/\/cs.android.com\/android\/_\/android\/platform\/frameworks\/native\/+\/d630e520de9ff4bc50723a7e8f91b6d9be27db1c. Accessed on Jan 31 2021."},{"key":"e_1_3_2_1_6_1","unstructured":"Android Code Search. 2021 b. Source code of CameraService.h in AOSP. https:\/\/cs.android.com\/android\/platform\/superproject\/+\/master:frameworks\/av\/services\/camera\/libcameraservice\/CameraService.h?q=cameraservice. Accessed on May 7 2021."},{"key":"e_1_3_2_1_7_1","unstructured":"Android developers. 2021 a. Android AppOpsManager. https:\/\/developer.android.com\/reference\/android\/app\/AppOpsManager. Accessed on Aug 3 2021."},{"key":"e_1_3_2_1_8_1","unstructured":"Android developers. 2021 b. Android PermissionChecker Developer API. https:\/\/developer.android.com\/reference\/androidx\/core\/content\/PermissionChecker. Accessed on July 29 2021."},{"key":"e_1_3_2_1_9_1","unstructured":"Android Developers. 2021. Parcel. https:\/\/developer.android.com\/reference\/android\/os\/Parcel#active-objects. Accessed on Feb 2 2021."},{"key":"e_1_3_2_1_10_1","unstructured":"Android Developers Blog. 2017. Here comes Treble: A modular base for Android. https:\/\/android-developers.googleblog.com\/2017\/05\/here-comes-treble-modular-base-for.html. Accessed on Feb 2 2021."},{"key":"e_1_3_2_1_11_1","unstructured":"Android Open Source Project. 2021. Android Interface Definition Language (AIDL). https:\/\/developer.android.com\/guide\/components\/aidl. Accessed on Jan 31 2021."},{"key":"e_1_3_2_1_12_1","volume-title":"the ACM Conference on Computer and Communications Security. 217--228","author":"Yee Au Kathy Wain","year":"2012","unstructured":"Kathy Wain Yee Au, Yi Fan Zhou, Zhen Huang, and David Lie. 2012. PScout: analyzing the Android permission specification. In the ACM Conference on Computer and Communications Security. 217--228."},{"key":"e_1_3_2_1_13_1","volume-title":"25th USENIX security symposium (USENIX security 16). 1101--1118.","author":"Backes Michael","unstructured":"Michael Backes, Sven Bugiel, Erik Derr, Patrick McDaniel, Damien Octeau, and Sebastian Weisgerber. 2016. On demystifying the Android application framework: Re-visiting Android permission specification analysis. In 25th USENIX security symposium (USENIX security 16). 1101--1118."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2322867"},{"key":"e_1_3_2_1_15_1","unstructured":"Michal Bednarski. 2017. Reparcel Bug. https:\/\/github.com\/michalbednarski\/ReparcelBug. Accessed on Feb 3 2021."},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 31st Annual Computer Security Applications Conference. Association for Computing Machinery, 361--370","author":"Chen Cao","year":"2015","unstructured":"Cao Chen, Gao Neng, Liu Peng, and Xiang Ji. 2015. Towards Analyzing the Input Validation Vulnerabilities Associated with Android System Services. In Proceedings of the 31st Annual Computer Security Applications Conference. Association for Computing Machinery, 361--370."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134638"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3381991.3395396"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046779"},{"key":"e_1_3_2_1_20_1","volume-title":"BinderCracker: Assessing the Robustness of Android System Services. arXiv preprint arXiv:1604.06964","author":"Feng Huan","year":"2016","unstructured":"Huan Feng and Kang G Shin. 2016. BinderCracker: Assessing the Robustness of Android System Services. arXiv preprint arXiv:1604.06964 (2016)."},{"key":"e_1_3_2_1_21_1","volume-title":"Fuzzing android system services by binder call to escalate privilege. BlackHat USA","author":"Gong Guang","year":"2015","unstructured":"Guang Gong. 2015. Fuzzing android system services by binder call to escalate privilege. BlackHat USA (2015)."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292006.3300023"},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks. 151--161","author":"William Enck Sigmund Albert","year":"2019","unstructured":"Sigmund Albert Gorski III and William Enck. 2019. ARF: identifying re-delegation vulnerabilities in Android system services. In Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks. 151--161."},{"key":"e_1_3_2_1_24_1","volume-title":"BlackHat Asia","author":"He Qidan","year":"2016","unstructured":"Qidan He. 2016. Hey your Parcel Looks Bad, Fuzzing and Exploiting Parcelization vulnerabilities in Android. In BlackHat Asia, 2016."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813606"},{"key":"e_1_3_2_1_26_1","unstructured":"Jim Huang. 2012. Android IPC Mechanism. https:\/\/www.slideshare.net\/jserv\/android-ipc-mechanism."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2017.16"},{"key":"e_1_3_2_1_28_1","volume-title":"IEEE Conference on Communications and Network Security (CNS). 709--710","author":"Kai Wang","year":"2015","unstructured":"Wang Kai, Zhang Yuqing, Liu Qixu, and Fan Dan. 2015. A fuzzing test for dynamic vulnerability detection on Android Binder mechanism. In IEEE Conference on Communications and Network Security (CNS). 709--710."},{"key":"e_1_3_2_1_29_1","unstructured":"Nick Kralevich. 2017. Honey I Shrunk the Attack Surface -- Adventures in Android Security Hardening."},{"key":"e_1_3_2_1_30_1","volume-title":"The BSD conference","volume":"5","author":"Lattner Chris","year":"2008","unstructured":"Chris Lattner. 2008. LLVM and Clang: Next generation compiler technology. In The BSD conference, Vol. 5."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.60"},{"key":"e_1_3_2_1_32_1","volume-title":"29th USENIX Security Symposium (USENIX Security).","author":"Liu Baozheng","year":"2020","unstructured":"Baozheng Liu, Chao Zhang, Guang Gong, Yishun Zeng, Haifeng Ruan, and Jianwei Zhuge. 2020. FANS: Fuzzing Android Native System Services via Automated Interface Analysis. In 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081361"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.60"},{"key":"e_1_3_2_1_35_1","unstructured":"Microsoft Security Update Guide. 2020. CVE-2020--1393 Windows Diagnostics Hub Elevation of Privilege Vulnerability. https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2020--1393. Accessed on Jan 31 2021."},{"key":"e_1_3_2_1_36_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Narayan Shravan","year":"2020","unstructured":"Shravan Narayan, Craig Disselkoen, Tal Garfinkel, Nathan Froyd, Eric Rahm, Sorin Lerner, Hovav Shacham, and Deian Stefan. 2020. Retrofitting fine grain isolation in the Firefox renderer. In 29th USENIX Security Symposium (USENIX Security 20). 699--716."},{"key":"e_1_3_2_1_37_1","unstructured":"Stephen Hines Nick Desaulniers Greg Hackmann. 2021. Compiling Android userspace and Linux Kernel with LLVM. https:\/\/llvm.org\/devmtg\/2017--10\/slides\/Hines-CompilingAndroidKeynote.pdf. Accessed on Jan 31 2021."},{"key":"e_1_3_2_1_38_1","unstructured":"Tom\u00e1? Rosa. 2011. Android Binder Security Note: On Passing Binder Through Another Binder. https:\/\/crypto.hyperlink.cz\/files\/xbinder.pdf. Accessed on Feb 2 2021."},{"key":"e_1_3_2_1_39_1","volume-title":"Zhuoqing Morley Mao, Jason Ott, and Zhiyun Qian.","author":"Shao Yuru","year":"2016","unstructured":"Yuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott, and Zhiyun Qian. 2016. Kratos: Discovering Inconsistent Security Policy Enforcement in the Android Framework.. In NDSS."},{"key":"e_1_3_2_1_40_1","unstructured":"SUDONULL. 2019. EvilParcel Vulnerability Analysis. https:\/\/sudonull.com\/post\/26295-EvilParcel-Vulnerability-Analysis-Doctor-Web-Blog. Accessed on Feb 3 2021."},{"key":"e_1_3_2_1_41_1","unstructured":"relax Tuna. 2021. Monthly tarball of AOSP. https:\/\/mirrors.tuna.tsinghua.edu.cn\/aosp-monthly\/. Accessed on May 6 2021."},{"key":"e_1_3_2_1_42_1","volume-title":"ACM SIGSAC Conference on Computer and Communications Security. 92--103","author":"Wang Kai","year":"2016","unstructured":"Kai Wang, Yuqing Zhang, and Peng Liu. 2016. Call Me Back! Attacks on System Server and System Apps in Android Through Synchronous Callback. In ACM SIGSAC Conference on Computer and Communications Security. 92--103."},{"key":"e_1_3_2_1_43_1","volume-title":"IEEE\/ACM 39th International Conference on Software Engineering: Software Engineering in Practice Track (ICSE-SEIP). 283--292","author":"Wu J.","unstructured":"J. Wu, S. Liu, S. Ji, M. Yang, T. Luo, Y. Wu, and Y. Wang. 2017. Exception beyond Exception: Crashing Android System by Trapping in \"Uncaught Exception\". In IEEE\/ACM 39th International Conference on Software Engineering: Software Engineering in Practice Track (ICSE-SEIP). 283--292."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243843"},{"key":"e_1_3_2_1_45_1","volume-title":"Relationships between design patterns. Pattern languages of program design","author":"Zimmer Walter","year":"1995","unstructured":"Walter Zimmer. 1995. Relationships between design patterns. Pattern languages of program design, Vol. 57 (1995), 345--364."}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event Republic of Korea","acronym":"CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484801","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460120.3484801","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T20:46:50Z","timestamp":1763498810000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484801"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,12]]},"references-count":45,"alternative-id":["10.1145\/3460120.3484801","10.1145\/3460120"],"URL":"https:\/\/doi.org\/10.1145\/3460120.3484801","relation":{},"subject":[],"published":{"date-parts":[[2021,11,12]]},"assertion":[{"value":"2021-11-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}