Yuwan Ma

dblp:221/9468 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program analysis · 100%
Network and information security
1 paper
Web and mobile security · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Web and mobile security
mobile security
0.712023
μDep: Mutation-Based Dependency Generation for Precise Taint Analysis on Android Native Code · IEEE Trans. Dependable Secur. Comput. 2023
Program analysis › static analysis
information flow analysis
0.712023
μDep: Mutation-Based Dependency Generation for Precise Taint Analysis on Android Native Code · IEEE Trans. Dependable Secur. Comput. 2023
Program analysis › static analysis
taint analysis
0.712023
μDep: Mutation-Based Dependency Generation for Precise Taint Analysis on Android Native Code · IEEE Trans. Dependable Secur. Comput. 2023
Program analysis › binary analysis
static binary analysis
0.212023
μDep: Mutation-Based Dependency Generation for Precise Taint Analysis on Android Native Code · IEEE Trans. Dependable Secur. Comput. 2023

Methods — techniques the papers use, named apart from their topics

stub generation · 1.3mutation-based dynamic analysis · 1.3control flow analysis · 1.3
YearPublicationVenuePosition
2023 μDep: Mutation-Based Dependency Generation for Precise Taint Analysis on Android Native Code
abstract
The existence of native code in Android apps plays an important role in triggering inconspicuous propagation of secrets and circumventing malware detection. However, the state-of-the-art information-flow analysis tools for Android apps all have limited capabilities of analyzing native code. Due to the complexity of binary-level static analysis, most static analyzers choose to build conservative models for a selected portion of native code. Though the recent inter-language analysis improves the capability of tracking information flow in native code, it is still far from attaining similar effectiveness of the state-of-the-art information-flow analyzers that focus on non-native Java methods. To overcome the above constraints, we propose a new analysis framework,$\mu$Dep, to detect sensitive information flows of the Android apps containing native code. In this framework, we combine a control-flow based static binary analysis with a mutation-based dynamic analysis to model the tainting behaviors of native code in the apps. Based on the result of the analyses,$\mu$Dep conducts a stub generation for the related native functions to facilitate the state-of-the-art analyzer DroidSafe with fine-grained tainting behavior summaries of native code. The experimental results show that our framework is competitive on the accuracy, and effective in analyzing the information flows in real-world apps and malware compared with the state-of-the-art inter-language static analysis.
Cong Sun 0001, Yuwan Ma, Dongrui Zeng, Gang Tan, Siqi Ma 0001
IEEE Trans. Dependable Secur. Comput.2