Finder: Automatic ICC Data Reconstruction for Long-Term Runtime Semantics

Chia Wei Hsu, Sheng Ru Wei, Shiuhpyng Shieh

研究成果: Conference contribution同行評審


In Android, both system services and apps are composed of components, and the inter-component communication (ICC) is therefore vital for representing the system states of the past runtime. Conventional approaches focus on inspecting the program behaviors of apps in the laboratory environment, but not suitable for a long-Time period, system-wide activities. Analysts consider that ICC preserves much runtime semantics, so we propose Finder, an automatic ICC data reconstruction system to provide a long-Term and comprehensive view of the past runtime. We decouple the program analysis on ICC from runtime monitoring thereby decreasing the runtime overhead. Finder applies transpiling techniques to generate the data resolvers compatible with all off-The-shelf Android version. The generated data resolvers can reconstruct a high-level, system-wide runtime information, and therefore the result is useful for digital forensic, program analysis, and auditing.

主出版物標題DSC 2018 - 2018 IEEE Conference on Dependable and Secure Computing
發行者Institute of Electrical and Electronics Engineers Inc.
出版狀態Published - 23 1月 2019
事件2018 IEEE Conference on Dependable and Secure Computing, DSC 2018 - Kaohsiung, 台灣
持續時間: 10 12月 201813 12月 2018


名字DSC 2018 - 2018 IEEE Conference on Dependable and Secure Computing


Conference2018 IEEE Conference on Dependable and Secure Computing, DSC 2018


深入研究「Finder: Automatic ICC Data Reconstruction for Long-Term Runtime Semantics」主題。共同形成了獨特的指紋。
