Published January 31, 2023
| Version v1
Report
Open
Assessing the security of inter-app communications in android through reinforcement learning
Description
A central aspect of the Android platform is Inter-Component Communication (ICC), which allows the reuse of functionality across apps and components through message passing. While ICC is a powerful feature, it also presents a serious attack surface. This paper addresses the issue of generating exploits for a subset of Android ICC vulnerabilities (i.e., IDOS, XAS, and FI) using static analysis, Deep Reinforcement Learning-based dynamic analysis, and software instrumentation. Our approach, called RONIN, outperforms state-of-the-art and baseline tools in terms of the number of exploited vulnerabilities.
Files
TR-Precrime-2023-02.pdf
Files
(946.2 kB)
Name | Size | Download all |
---|---|---|
md5:37cd73f88e31818fe21b636ab4289142
|
946.2 kB | Preview Download |
Additional details
Related works
- Is published in
- 10.1016/j.cose.2023.103311 (DOI)