VLDB 2026 Research / reviewers in the wild / expert
Bara' Nazzal
dblp:245/7640
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | KASTroid: A Static Taint Analysis Framework for Kotlin-Based Android ApplicationsabstractWe introduce KASTroid1, a static taint analysis framework designed to detect information leakage vulnerabilities in Kotlin-based Android applications, with a focus on insecure usage of broadcasts. As Kotlin increasingly replaces Java as the preferred language for Android development, ensuring the security of inter-component communication, particularly through broadcasts, is critical. KASTroid employs a novel static analysis approach to identify tainted flows arising from unsafe broadcast practices, such as the use of implicit broadcasts via sendBroadcast, which can expose sensitive user data to unauthorized applications. We evaluated KASTroid on a dataset of 1,716 Kotlin Android applications and found that over 70% of broadcasts are implicit, posing significant privacy risks. To demonstrate the framework’s effectiveness, we present a case study on a previous version of AndroidAPS, a medical application, where KASTroid identified unsafe broadcast usage that could leak sensitive information to other local applications. Our findings highlight the importance of secure broadcast practices and demonstrate KASTroid’s ability to assist developers in detecting and remedying such vulnerabilities. Bara' Nazzal, Manar H. Alalfi, James R. Cordy |
COMPSAC | 1 |
| 2025 | A Modeling and Static Analysis Approach for the Verification of Privacy and Safety Properties in Kotlin Android AppsabstractThe safety and privacy of medical devices is critical, as they directly affect the health of users and handle sensitive personal data. Ensuring that these devices meet safety and security standards is essential, especially with the rise of do-it-yourself solutions such as open-source artificial pancreas systems (APSs) for insulin delivery. In this work, we study AndroidAPS, an APS controller written in Kotlin, and propose an approach to detect safety and security issues. We develop a modeling and analysis framework for Kotlin applications that extracts a structural model and supports detecting logging vulnerabilities and ensuring the application of safety constraints. We conduct two experiments. The first examines logging behavior to check for privacy risks. Out of $\mathbf{3, 0 5 9 ~ l o g g i n g}$ instances, our tool identified 48 sinks that received 144 sensitive flows, with $68 \%$ precision due to coarse-grained flagging. The second experiment verifies that calculation-related values are validated against safety constraints before being set to the profile. We show that AndroidAPS generally adheres to its safety design properties, but it has one calculation-related value that is not explicitly validated at the plugin level and only partially validated earlier in the flow. Bara' Nazzal, Manar H. Alalfi, James R. Cordy |
PST | 1 |
| 2022 | A mutation framework for evaluating security analysis tools in IoT applicationsabstractSummary With the growing and widespread use of Internet of Things (IoT) in our daily life, its security is becoming more crucial. To ensure information security, we require better security analysis tools for IoT applications. Hence, this paper presents an automated framework to evaluate taint‐flow analysis tools in the domain of IoT applications. First, we propose a set of mutational operators tailored to evaluate three types of sensitivity analysis, flow, path and context sensitivity. Then we developed mutators to automatically generate mutants for those types. We demonstrated the framework on a subset of mutational operators to evaluate three taint‐flow analysers, SaINT, Taint‐Things and FlowsMiner. Our framework and experiments ranked the taint analysis tools according to precision and recall as follows: Taint‐Things (99% recall, 100% precision), FlowsMiner (100% recall, 87.6% precision) and SaINT (100% recall, 56.8% precision). To the best of our knowledge, our framework is the first framework to address the need for evaluating taint‐flow analysis tools and specifically those developed for IoT SmartThings applications. Manar H. Alalfi, Sajeda Parveen, Bara' Nazzal |
Softw. Test. Verification Reliab. | 3 |