Sydur Rahaman

dblp:205/9467 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2023
0009-0002-9131-6387ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2023 Detecting Potential User-data Save & Export Losses due to Android App Termination
abstract
A common feature in Android apps is saving, or exporting, user’s work (e.g., a drawing) as well as data (e.g., a spreadsheet) onto local storage, as a file. Due to the volatile nature of the OS and the mobile environment in general, the system can terminate apps without notice, which prevents the execution of file write operations; consequently, user data that was supposed to be saved/exported is instead lost. Testing apps for such potential losses raises several challenges: how to identify data originating from user input or resulting from user action (then check whether it is saved), and how to reproduce a potential error by terminating the app at the exact moment when unsaved changes are pending. We address these challenges via an approach that finds potential “lost writes”, i.e., user data supposed to be written to a file, but the file write does not take place due to system-initiated termination. Our approach consists of two phases: a static analysis that finds potential losses and a dynamic loss verification phase where we compare lossy and lossless system-level file write traces to confirm errors. We ran our analysis on 2,182 apps from Google Play and 38 apps from F-Droid. Our approach found 163 apps where termination caused losses, including losing user’s app-specific data, notes, photos, user’s work and settings. In contrast, two state-of-the-art tools aimed at finding volatility errors in Android apps failed to discover the issues we found.
Sydur Rahaman, Umar Farooq 0002, Iulian Neamtiu, Zhijia Zhao 0001
AST1
2022 InnerEye: A Tale on Images Filtered Using Instagram Filters - How Do We Interact with them and How Can We Automatically Identify the Extent of Filtering?
Gazi Abdur Rakib, Rudaiba Adnin, Shekh Ahammed Adnan Bashir, Chashi Mahiul Islam, Abir Mohammad Turza, Saad Manzur, Monowar Anjum Rashik, Abdus Salam Azad, Tusher Chakraborty, Sydur Rahaman, Muhammad Rayhan Shikder, Syed Ishtiaque Ahmed, A. B. M. Alim Al Islam
MobiQuitous10
2021 Algebraic-datatype taint tracking, with applications to understanding Android identifier leaks
abstract
Current taint analyses track flow from sources to sinks, and report the results simply as source → sink pairs, or flows. This is imprecise and ineffective in many real-world scenarios; examples include taint sources that are mutually exclusive, or flows that combine sources (e.g., IMEI and MAC Address are concatenated, hashed, leaked vs. IMEI and MAC Address hashed separately and leaked separately). These shortcomings are particularly acute in the context of Android, where sensitive identifiers can be combined, processed, and then leaked, in complicated ways. To address these issues, we introduce a novel, algebraic-datatype taint analysis that generates rich yet concise taint signatures involving AND, XOR, hashing – akin to algebraic, product and sum, types. We implemented our approach as a static analysis for Android that derives app leak signatures – an algebraic representation of how, and where, hardware/software identifiers are manipulated before being exfiltrated to the network. We perform six empirical studies of algebraic-datatype taint tracking on 1,000 top apps from Google Play and their embedded libraries, including: discerning between “raw” and hashed flows which eliminates a source of imprecision in current analyses; finding apps and libraries that go against Google Play’s guidelines by (ab)using hardware identifiers; showing that third-party code, rather than app code, is the predominant source of leaks; exposing potential de-anonymization practices; and quantifying how apps have become more privacy-friendly over the past two years.
Sydur Rahaman, Iulian Neamtiu
ESEC/SIGSOFT FSE1