Abstract
In this poster, we present TaintGrep, a novel static analysis approach to detect vulnerabilities of Android applications. This approach combines the advantages of semantic pattern matching and taint analysis to get better accuracy and be able to detect cross-function vulnerabilities. Compared with many traditional tools, TaintGrep does not require the full source code or building environment to analyze. Moreover, it supports users in defining their customized matching rules using their vulnerability mining experience, which makes this approach more flexible and scalable. In the preliminary experiment, we give a detailed analysis of the rules of two typical vulnerabilities: generic DoS and arbitrary file read/write, and have detected 77 0day vulnerabilities with these rules in 16 well-known Android applications.
Author supplied keywords
Cite
CITATION STYLE
Yang, R., Cai, J., & Han, X. (2022). Poster: TaintGrep: A Static Analysis Tool for Detecting Vulnerabilities of Android Apps Supporting User-defined Rules. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 3507–3509). Association for Computing Machinery. https://doi.org/10.1145/3548606.3563527
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.