14 papers · ranked by Valyu relevance
Rajendra Kumar Solanki, Vijay Laxmi, Manoj Singh Gaur
—Android Permission Model and Application (app) analysis has consistently remained the focus of the investigation of research groups and stakeholders of the Android ecosystem since it was launched in 2008. Even though the Android smartphone operating system (OS) permission model has evolved significantly from…
Lakshmi Priya Bodepudi, Yutong Zhao, Michael C. Fu, Yuanyuan Wu + 2 more
Building Android applications reliably remains a persistent challenge due to complex dependencies, diverse configurations, and the rapid evolution of the Android ecosystem. This study conducts an empirical analysis of 200 open-source Android projects written in Java and Kotlin to diagnose and resolve build failures.…
Samuele Doria, Eleonora Losiouk
Dynamically resolving method reachability in Android applications remains a critical and largely unsolved problem. Despite notable advancements in GUI testing and static call graph construction, current tools are insufficient for reliably driving execution toward specific target methods, especially those not embedded…
Aurora Gori Savellini, Tiziano Squartini, Massimo Riccaboni
Mobile applications (apps) increasingly rely on third-party Software Development Kits (SDKs) to provide services such as advertising, analytics, authentication, crash reporting, and location services. These components form an important, but often hidden, layer of the mobile ecosystem. Here, we present a large-scale…
Thomas Sutter, Timo Kehrer, Bernhard Tellenbach, Marc Rennhard
Dynamic analysis of Android's application layer typically relies on physical devices, limiting scalability and reproducibility. To compensate, we introduce a systematic re-hosting method that relocates the Android framework and pre-installed software from real device firmware into a fully emulated environment. Our…
Rahul Patel
The assumption that mobile enterprise software requires native Android SDK development has persisted for over a decade, but for institutional deployments, this assumption is not merely outdated: it is economically wasteful and technically unnecessary. This paper presents a campus management system built during an…
Zhiyuan Chen, Soham Sanjay Deo, Poorna Chander Reddy Puttaparthi, Vanessa Nava-Camal + 4 more
With the rapid growth of mobile apps, users' concerns about their privacy have become increasingly prominent. Android app logs serve as crucial computer resources, aiding developers in debugging and monitoring the status of Android apps, while also containing a wealth of software system information. Previous studies…
Luca Ferrari, Marco Alecci, Jordan Samhi, Tegawende' F. Bissyande' + 3 more
Android applications (apps) developers increasingly rely on code obfuscation techniques to hinder reverse engineering and protect intellectual property. However, obfuscation also reduces the effectiveness of static analysis and vulnerability detection tools, creating challenges for Android security analysis. Existing…
Jordan Doyle, Thomas Laurent, Anthony Ventresque
Mobile application development is a fast paced industry with frequent releases. While the development pace increases, so too does the need for automated test generation. Model-based test generation is one of the most common and successful approaches to support this need. Understanding and modelling the application…
Sinan Wang, Qi Zhang, Jiacheng Li, Lili Wei + 2 more
Android apps are built on APIs that abstract core Android system functionalities. These APIs are officially documented in multiple files distributed with the Android source code or SDK, which we collectively refer to as Android API Lists (AALs). Prior Android research has relied on specific AALs, often treating them as…
Marco Alecci, Pilar Martínez-Jiménez, Tegawendé F. Bissyandé
While mobile app evolution over time has been extensively studied, geographical variation in app behavior remains largely unexplored. This paper presents a large-scale study of location-based Android app differentiation, uncovering two important and previously underexplored phenomena with significant security and…
Jordan Doyle, Thomas Laurent, Anthony Ventresque
Android automated test input generation has been a highly researched topic for over a decade and has shown promising results with a variety of approaches. Random input generation is commonly used and the easiest to maintain, but ultimately inefficient. Systematic and search-based approaches produce effective tests but…
Jordan Doyle, Takfarinas Saber, Paolo Arcaini, Anthony Ventresque
Testing mobile applications often relies on tools, such as Exerciser Monkey for Android systems, that simulate user input. Exerciser Monkey, for example, generates random events (e.g., touches, gestures, navigational keys) that give developers a sense of what their application will do when deployed on real mobile…
Simon Althaus, Nikolaos Alexopoulos, Max Mühlhäuser, Christian Reuter + 1 more
System auditing on Android faces two problems. First, existing syscall tracers lose events under load, silently overwriting entries faster than a user space reader can drain them. Second, security-relevant application behavior is mediated through Binder, Android's kernel IPC mechanism, and is therefore hidden from the…