Nataniel P. Borges

dblp:202/8462 · also Nataniel P. Borges Jr., Nataniel Pereira Borges Jr. · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
0since 2021 · last 2020
0000-0002-9733-3113ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 4 first-authorSecurity and privacy · 2

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
5 papers
Software testing · 72% Program analysis · 28%
Network and information security
1 paper
Web and mobile security · 100%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software testing › test generation
GUI test generation
1.132020
Speeding up GUI Testing by On-Device Test Generation · ASE 2020
Learning user interface element interactions · ISSTA 2019
DroidMate-2: a platform for Android test generation · ASE 2018
Software testing
test generation
1.132020
Speeding up GUI Testing by On-Device Test Generation · ASE 2020
Learning user interface element interactions · ISSTA 2019
DroidMate-2: a platform for Android test generation · ASE 2018
Software testing › test generation
android test generation
0.822020
Speeding up GUI Testing by On-Device Test Generation · ASE 2020
DroidMate-2: a platform for Android test generation · ASE 2018
Program analysis › static analysis
pointer analysis
0.412020
Heaps'n leaks: how heap snapshots improve Android taint analysis · ICSE 2020
Program analysis
static analysis
0.412020
Heaps'n leaks: how heap snapshots improve Android taint analysis · ICSE 2020
Program analysis › static analysis
taint analysis
0.412020
Heaps'n leaks: how heap snapshots improve Android taint analysis · ICSE 2020
Software testing › mobile application testing
android app testing
0.312017
Data flow oriented UI testing: exploiting data flows and UI elements to test Android applications · ISSTA 2017
Software testing
UI testing
0.312017
Data flow oriented UI testing: exploiting data flows and UI elements to test Android applications · ISSTA 2017
Web and mobile security › mobile security
android security
0.112020
Heaps'n leaks: how heap snapshots improve Android taint analysis · ICSE 2020
Web and mobile security
mobile security
0.112020
Heaps'n leaks: how heap snapshots improve Android taint analysis · ICSE 2020
Program analysis
data flow analysis
0.112017
Data flow oriented UI testing: exploiting data flows and UI elements to test Android applications · ISSTA 2017

Methods — techniques the papers use, named apart from their topics

dynamic analysis · 1.2heap snapshot · 0.9on-device test generation · 0.4accessibility services · 0.4reinforcement learning · 0.4multi-armed bandit · 0.4test input generation · 0.3statement coverage measurement · 0.3test coverage · 0.3static analysis · 0.3
YearPublicationVenuePosition
2020 Heaps'n leaks: how heap snapshots improve Android taint analysis
abstract
The assessment of information flows is an essential part of analyzing Android apps, and is frequently supported by static taint analysis. Its precision, however, can suffer from the analysis not being able to precisely determine what elements a pointer can (and cannot) point to. Recent advances in static analysis suggest that incorporating dynamic heap snapshots, taken at one point at runtime, can significantly improve general static analysis. In this paper, we investigate to what extent this also holds for taint analysis, and how various design decisions, such as when and how many snapshots are collected during execution, and how exactly they are used, impact soundness and precision. We have extended FlowDroid to incorporate heap snapshots, yielding our prototype Heapster, and evaluated it on DroidMacroBench, a novel benchmark comprising real-world Android apps that we also make available as an artifact. The results show (1) the use of heap snapshots lowers analysis time and memory consumption while increasing precision; (2) a very good trade-off between precision and recall is achieved by a mixed mode in which the analysis falls back to static points-to relations for objects for which no dynamic data was recorded; and (3) while a single heap snapshot (ideally taken at the end of the execution) suffices to improve performance and precision, a better trade-off can be obtained by using multiple snapshots.
Manuel Benz, Erik Krogh Kristensen, Linghui Luo, Nataniel P. Borges, Eric Bodden, Andreas Zeller
ICSE4
2020 Speeding up GUI Testing by On-Device Test Generation
abstract
When generating GUI tests for Android apps, it typically is a separate test computer that generates interactions, which are then executed on an actual Android device. While this approach is efficient in the sense that apps and interactions execute quickly, the communication overhead between test computer and device slows down testing considerably. In this work, we present DD-2, a test generator for Android that tests other apps on the device using Android accessibility services. In our experiments, DD-2 has shown to be 3.2 times faster than its computer-device counterpart, while sharing the same source code.
Nataniel P. Borges, Jenny Rau, Andreas Zeller
ASE1
2019 Up-To-Crash: Evaluating Third-Party Library Updatability on Android
abstract
Buggy and flawed third-party libraries increase their host app's attack surface and put the users' privacy at risk. To avert this risk, libraries have to be kept updated to their newest versions by the app developers that integrate them into their projects. Recent researches revealed that the prevalence of outdated third-party libraries in Android apps is indeed a rampant problem, but also suggested that there is a great opportunity for drop-in replacements of outdated libraries, which would not even require cooperation by the app developers to update the libraries. However, all those conclusions are based on static app analysis, which can only provide an abstract view. In this work, we extend the updatability analysis to the runtime of apps. We implement a solution to update third-party libraries with drop-in replacements by their newer versions. To verify the feasibility of this developer-independent update mechanism, we dynamically test 3,000 real world apps for 3 popular libraries (78 library versions) for runtime failures stemming from incompatible library updates. To investigate the updatability of libraries in-depth, exploration enhanced dynamic testing is adopted to monitor the runtime behaviors of 15 apps before and after library updating. From our test, we find that the prior reported updatability rate is under real conditions overestimated by a factor of 1.57-2.06. Through root cause analysis, we find that the underlying problems prohibiting easy updates are intricate, such as deprecated functions, changed data structures, or entangled dependencies between different libraries and even the host app. We think our results not only put a more realistic light on the library updatability problem in Android, but also provide valuable insights for future solutions that provide automatic library updates or that try to support the app developers in better maintaining their external dependencies.
Jie Huang 0010, Nataniel P. Borges, Sven Bugiel, Michael Backes 0001
EuroS&P2
2019 Why Does this App Need this Data? Automatic Tightening of Resource Access
abstract
On mobile operating systems, apps may access resources that are not be needed for their primary functionality. Which are the resources an app actually needs for its core functionality? And what happens if we deny access to other resources? Using a test generator for user interaction, we systematically explore app behavior under varied resource constraints and determine the impact of access restrictions, yielding a minimal set of required privileges for each app and functionality. In our proof of concept on Android apps, our TIARA prototype could block up to 69% of resource accesses while retaining all previously explored functionality.
Nataniel P. Borges, Andreas Zeller
ICST1
2019 Learning user interface element interactions
abstract
When generating tests for graphical user interfaces, one central problem is to identify how individual UI elements can be interacted with—clicking, long- or right-clicking, swiping, dragging, typing, or more. We present an approach based on reinforcement learning that automatically learns which interactions can be used for which elements, and uses this information to guide test generation. We model the problem as an instance of the multi-armed bandit problem (MAB problem) from probability theory, and show how its traditional solutions work on test generation, with and without relying on previous knowledge. The resulting guidance yields higher coverage. In our evaluation, our approach shows improvements in statement coverage between 18% (when not using any previous knowledge) and 20% (when reusing previously generated models).
Christian Degott, Nataniel P. Borges, Andreas Zeller
ISSTA2
2019 AccessiLeaks: Investigating Privacy Leaks Exposed by the Android Accessibility Service
abstract
Abstract To support users with disabilities, Android provides the accessibility services, which implement means of navigating through an app. According to the Android developer’s guide: “Accessibility services should only be used to assist users with disabilities in using Android devices and apps”. However, developers are free to use this service without any restrictions, giving them critical privileges such as monitoring user input or screen content to capture sensitive information. In this paper, we show that simply enabling the accessibility service leaves 72 % of the top finance a nd 80 % of the top social media apps vulnerable to eavesdropping attacks, leaking sensitive information such as logins and passwords. A combination of several tools and recommendations could mitigate the privacy risks: We introduce an analysis technique that detects most of these issues automatically, e.g. in an app store. We also found that these issues can be automatically fixed in almost all cases; our fixes have b een accepted by 70 % of the surveyed developers. Finally, we designed a notification mechanism which would warn users against possible misuses of the accessibility services; 50 % of users would follow these notifications.
Mohammad Naseri, Nataniel P. Borges, Andreas Zeller, Romain Rouvoy
Proc. Priv. Enhancing Technol.2
2018 DroidMate-2: a platform for Android test generation
abstract
Android applications (apps) represent an ever increasing portion of the software market. Automated test input generators are the state of the art for testing and security analysis. We introduce DroidMate-2 (DM-2), a platform to easily assist both developers and researchers to customize, develop and test new test generators. DM-2 can be used without app instrumentation or operating system modifications, as a test generator on real devices and emulators for app testing or regression testing. Additionally, it provides sensitive resource monitoring or blocking capabilities through a lightweight app instrumentation, out-of-thebox statement coverage measurement through a fully-fledged app instrumentation and native experiment reproducibility. In our experiments we compared DM-2 against DroidBot, a state-of-the-art test generator by measuring statement coverage. Our results show that DM-2 reached 96% of its peak coverage in less than 2/3 of the time needed by DroidBot, allowing for better and more efficient tests. On short runs (5 minutes) DM-2 outperformed DroidBot by 7% while in longer runs (1 hour) this difference increases to 8%. ACM DL Artifact: https://www.doi.org/10.1145/3264864
Nataniel P. Borges, Jenny Rau, Andreas Zeller
ASE1
2017 Data flow oriented UI testing: exploiting data flows and UI elements to test Android applications
abstract
Testing user interfaces (UIs) is a challenging task. Ideally, every sequence of UI elements should be tested to guarantee that the application works correctly. This is, however, unfeasible due to the number of UI elements in an application. A better approach is to limit the evaluation to UI elements that affect a specific functionality. In this paper I present a novel technique to identify the relation between UI elements using the statically extracted data flows. I also present a method to refine these relations using dynamic analysis, in order to ensure that relations extracted from unreachable data flows are removed. Using these relations it is possible to more efficiently test a functionality. Finally, I present an approach to evaluate how these UI-aware data flows can be used as an heuristic to measure test coverage.
Nataniel P. Borges
ISSTA1