Sajjad Pourali

dblp:330/2141 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0001-9405-8710ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Panoptes: Detecting Out-of-Sight Privacy Exposure in Android
abstract
Android apps frequently collect and transmit sensitive user information, even when not actively engaged by users. While existing research has extensively explored privacy concerns related to foreground app usage, the risks associated with apps operating out-of-sight, when they are minimized or closed, remain largely unexplored. We design and implement Panoptes, a dynamic analysis tool that detects and attributes data exposure in Android out-of-sight app operations at scale. By systematically triggering and monitoring background works, we conduct the first large-scale measurement of what data apps collect and how they expose sensitive information without user interaction, and attribute the execution of background works to the criteria that trigger them. We evaluated 15,456 popular apps from AndroidRank and found that 13,068/15,456 (84.5%) apps establish network connections while not visible on the device. Of these, 7534/13,068 (57.7%) continue their activity regardless of whether the app is visibly open, closed, or even if it has never been opened. Our findings also uncovered undocumented features that enable apps to collect data even when they are apparently closed. This study sheds light on the hidden privacy risks in Android, and highlights the need for developing more robust techniques to mitigate surreptitious data exfiltration through invisible activities.
Sajjad Pourali, Mohammad Mannan
Proc. Priv. Enhancing Technol.1
2024 Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS Galaxy
Sajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan, Amr M. Youssef
USENIX Security Symposium1
2022 Hidden in Plain Sight: Exploring Encrypted Channels in Android Apps
abstract
As privacy features in Android operating system improve, privacy-invasive apps may gradually shift their focus to non-standard and covert channels for leaking private user/device information. Such leaks also remain largely undetected by state-of-the-art privacy analysis tools, which are very effective in uncovering privacy exposures via regular HTTP and HTTPS channels. In this study, we design and implement, ThirdEye, to significantly extend the visibility of current privacy analysis tools, in terms of the exposures that happen across various non-standard and covert channels, i.e., via any protocol over TCP/UDP (beyond HTTP/S), and using multi-layer custom encryption over HTTP/S and non-HTTP protocols. Besides network exposures, we also consider covert channels via storage media that also leverage custom encryption layers. Using ThirdEye, we analyzed 12,598 top-apps in various categories from Androidrank, and found that 2887/12,598 (22.92%) apps used custom encryption/decryption for network transmission and storing content in shared device storage, and 2465/2887 (85.38%) of those apps sent device information (e.g., advertising ID, list of installed apps) over the network that can fingerprint users. Besides, 299 apps transmitted insecure encrypted content over HTTP/non-HTTP protocols; 22 apps that used authentication tokens over HTTPS, happen to expose them over insecure (albeit custom encrypted) HTTP/non-HTTP channels. We found non-standard and covert channels with multiple levels of obfuscation (e.g., encrypted data over HTTPS, encryption at nested levels), and the use of vulnerable keys and cryptographic algorithms. Our findings can provide valuable insights into the evolving field of non-standard and covert channels, and help spur new countermeasures against such privacy leakage and security issues.
Sajjad Pourali, Nayanamana Samarasinghe, Mohammad Mannan
CCS1