Title: Finder: Automatic ICC Data Reconstruction for Long-Term Runtime Semantics
Authors: Hsu, Chia-Wei
Wei, Sheng-Ru
Shieh, Shiuhpyng
資訊工程學系
Department of Computer Science
Keywords: Mobile;Android;Inter-Component Communication;Binder;Transpiler
Issue Date: 1-Jan-2018
Abstract: In Android, both system services and apps are composed of components, and the inter-component communication (ICC) is therefore vital for representing the system states of the past runtime. Conventional approaches focus on inspecting the program behaviors of apps in the laboratory environment, but not suitable for a long-time period, system-wide activities. Analysts consider that ICC preserves much runtime semantics, so we propose Finder, an automatic ICC data reconstruction system to provide a long-term and comprehensive view of the past runtime. We decouple the program analysis on ICC from runtime monitoring thereby decreasing the runtime overhead. Finder applies transpiling techniques to generate the data resolvers compatible with all off-the-shelf Android version. The generated data resolvers can reconstruct a high-level, system-wide runtime information, and therefore the result is useful for digital forensic, program analysis, and auditing.
URI: http://hdl.handle.net/11536/151747
ISBN: 978-1-5386-5790-4
Journal: 2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC)
Begin Page: 139
End Page: 147
Appears in Collections:Conferences Paper