Tanzirul Azim

dblp:129/8213 · also Md Tanzirul Azim · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 3 first-authorComputer networks · 1 · 1 first-authorSecurity and privacy · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
7 papers
Debugging and program repair · 33% Software testing · 30% Program analysis · 28%
Network and information security
2 papers
Web and mobile security · 62% Systems and software security · 38%

Topics — the 17 heaviest of 20, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Debugging and program repair
fault localization
0.832019
Dynamic slicing for Android · ICSE 2019
Finding resume and restart errors in Android applications · OOPSLA 2016
Towards self-healing smartphone software via automated patching · ASE 2014
Software testing
mobile application testing
0.432015
Versatile yet lightweight record-and-replay for Android · OOPSLA 2015
Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013
RERAN: timing- and touch-sensitive record and replay for Android · ICSE 2013
Debugging and program repair
record and replay
0.422015
Versatile yet lightweight record-and-replay for Android · OOPSLA 2015
RERAN: timing- and touch-sensitive record and replay for Android · ICSE 2013
Program analysis
dynamic analysis
0.412019
Dynamic slicing for Android · ICSE 2019
Program analysis › dynamic analysis
dynamic slicing
0.412019
Dynamic slicing for Android · ICSE 2019
Program analysis
static analysis
0.322016
Finding resume and restart errors in Android applications · OOPSLA 2016
Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013
Software testing
test generation
0.212016
Finding resume and restart errors in Android applications · OOPSLA 2016
Debugging and program repair › automated program repair
automated patch generation
0.212014
Towards self-healing smartphone software via automated patching · ASE 2014
Software testing › fault detection
crash detection
0.212014
Towards self-healing smartphone software via automated patching · ASE 2014
Software testing
GUI testing
0.212013
RERAN: timing- and touch-sensitive record and replay for Android · ICSE 2013
Software testing
regression testing
0.112019
Dynamic slicing for Android · ICSE 2019
Software testing › regression testing
test suite reduction
0.112019
Dynamic slicing for Android · ICSE 2019
Operating systems › mobile systems
mobile platform
0.112015
Versatile yet lightweight record-and-replay for Android · OOPSLA 2015
Web and mobile security › mobile security
android security
0.112014
Brahmastra: Driving Apps to Test the Security of Third-Party Components · USENIX Security Symposium 2014
Operating systems › mobile systems
mobile operating systems
0.112014
Towards self-healing smartphone software via automated patching · ASE 2014
Program analysis
data flow analysis
0.012013
Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013
Program analysis › static analysis
taint analysis
0.012013
Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013

Methods — techniques the papers use, named apart from their topics

static analysis · 0.8dynamic analysis · 0.7instrumentation · 0.4asynchronous slicing · 0.4input generation · 0.2stream-oriented record-and-replay · 0.2bytecode rewriting · 0.2static taint-style dataflow analysis · 0.2event stream capture · 0.2control flow graph construction · 0.2
YearPublicationVenuePosition
2019 Dynamic slicing for Android
abstract
Dynamic program slicing is useful for a variety of tasks, from testing to debugging to security. Prior slicing approaches have targeted traditional desktop/server platforms, rather than mobile platforms such as Android. Slicing mobile, event-based systems is challenging due to their asynchronous callback construction and the IPC (interprocess communication)- heavy, sensor-driven, timing-sensitive nature of the platform. To address these problems, we introduce AndroidSlicer1, the first slicing approach for Android. AndroidSlicer combines a novel asynchronous slicing approach for modeling data and control dependences in the presence of callbacks with lightweight and precise instrumentation; this allows slicing for apps running on actual phones, and without requiring the app's source code. Our slicer is capable of handling a wide array of inputs that Android supports without adding any noticeable overhead. Experiments on 60 apps from Google Play show that AndroidSlicer is effective (reducing the number of instructions to be examined to 0.3% of executed instructions) and efficient (app instrumentation and post-processing combined takes 31 seconds); all while imposing a runtime overhead of just 4%. We present three applications of AndroidSlicer that are particularly relevant in the mobile domain: (1) finding and tracking input parts responsible for an error/crash, (2) fault localization, i.e., finding the instructions responsible for an error/crash, and (3) reducing the regression test suite. Experiments with these applications on an additional set of 18 popular apps indicate that AndroidSlicer is effective for Android testing and debugging.
Tanzirul Azim, Arash Alavi 0001, Iulian Neamtiu, Rajiv Gupta 0001
ICSE1
2016 uLink: Enabling User-Defined Deep Linking to App Content
abstract
Web deep links are instrumental to many fundamental user experiences such as navigating to one web page from another, bookmarking a page, or sharing it with others. Such experiences are not possible with individual pages inside mobile apps, since historically mobile apps did not have links equivalent to web deep links. Mobile deep links, introduced in recent years, still lack many important properties of web deep links. Unlike web links, mobile deep links need significant developer effort, cover a small number of predefined pages, and are defined statically to navigate to a page for a given link, but not to dynamically generate a link for a given page. We propose uLink, a novel deep linking mechanism that addresses these problems. uLink is implemented as an application library, which transparently tracks data- and UI-event-dependencies of app pages, and encodes the information in links to the pages; when a link is invoked, the information is utilized to recreate the target page quickly and accurately. uLink also employs techniques, based on static and dynamic analysis of the app, that can provide feedback to users about whether a link may break in the future due to, e.g., modifications of external resources such as a file the link depends on. We have implemented uLink on Android. Our evaluation with 34 (of 1000 most downloaded) Android apps shows that compared to existing mobile deep links, uLink requires minimal developer effort, achieves significantly higher coverage, and can provide accurate user feedback on a broken link.
Tanzirul Azim, Oriana Riva, Suman Nath
MobiSys1
2016 Finding resume and restart errors in Android applications
abstract
Smartphone apps create and handle a large variety of ``instance'' data that has to persist across runs, such as the current navigation route, workout results, antivirus settings, or game state. Due to the nature of the smartphone platform, an app can be paused, sent into background, or killed at any time. If the instance data is not saved and restored between runs, in addition to data loss, partially-saved or corrupted data can crash the app upon resume or restart. While smartphone platforms offer API support for data-saving and data-retrieving operations, the use of this API is ad-hoc: left to the programmer, rather than enforced by the compiler. We have observed that several categories of bugs---including data loss, failure to resume/restart or resuming/restarting in the wrong state---are due to incorrect handling of instance data and are easily triggered by just pressing the `Home' or `Back' buttons. To help address this problem, we have constructed a tool chain for Android (the KREfinder static analysis and the KREreproducer input generator) that helps find and reproduce such incorrect handling. We have evaluated our approach by running the static analysis on 324 apps, of which 49 were further analyzed manually. Results indicate that our approach is (i) effective, as it has discovered 49 bugs, including in popular Android apps, and (ii) efficient, completing on average in 61 seconds per app. More generally, our approach helps determine whether an app saves too much or too little state.
Zhiyong Shan, Tanzirul Azim, Iulian Neamtiu
OOPSLA2
2015 Versatile yet lightweight record-and-replay for Android
abstract
Recording and replaying the execution of smartphone apps is useful in a variety of contexts, from reproducing bugs to profiling and testing. Achieving effective record-and-replay is a balancing act between accuracy and overhead. On smartphones, the act is particularly complicated, because smartphone apps receive a high-bandwidth stream of input (e.g., network, GPS, camera, microphone, touchscreen) and concurrency events, but the stream has to be recorded and replayed with minimal overhead, to avoid interfering with app execution. Prior record-and-replay approaches have focused on replaying machine instructions or system calls, which is not a good fit on smartphones. We propose a novel, stream-oriented record-and-replay approach which achieves high-accuracy and low-overhead by aiming at a sweet spot: recording and replaying sensor and network input, event schedules, and inter-app communication via intents. To demonstrate the versatility of our approach, we have constructed a tool named VALERA that supports record-and-replay on the Android platform. VALERA works with apps running directly on the phone, and does not require access to the app source code. Through an evaluation on 50 popular Android apps, we show that: VALERA's replay fidelity far exceeds current record-and-replay approaches for Android; VALERA's precise timing control and low overhead (about 1% for either record or replay) allows it to replay high-throughput, timing-sensitive apps such as video/audio capture and recognition; and VALERA's support for event schedule replay enables the construction of useful analyses, such as reproducing event-driven race bugs.
Yongjian Hu, Tanzirul Azim, Iulian Neamtiu
OOPSLA2
2014 Towards self-healing smartphone software via automated patching
abstract
Frequent app bugs and low tolerance for loss of functionality create an impetus for self-healing smartphone software. We take a step towards this via on-the-fly error detection and automated patching. Specifically, we add failure detection and recovery to Android by detecting crashes and ``sealing off'' the crashing part of the app to avoid future crashes. In the detection stage, our system dynamically analyzes app execution to detect certain exceptional situations. In the recovery stage, we use bytecode rewriting to alter app behavior as to avoid such situations in the future. When using our implementation, apps can resume operation (albeit with limited functionality) instead of repeatedly crashing. Our approach does not require access to app source code or any system (e.g., kernel-level) modification. Experiments on several real-world, popular Android apps and bugs show that our approach manages to recover the apps from crashes effectively, timely, and without introducing overhead.
Tanzirul Azim, Iulian Neamtiu, Lisa M. Marvel
ASE1
2014 Brahmastra: Driving Apps to Test the Security of Third-Party Components
Ravi Bhoraskar, Seungyeop Han, Jinseong Jeon, Tanzirul Azim, Shuo Chen 0001, Jaeyeon Jung, Suman Nath, Rui Wang 0010, David Wetherall
USENIX Security Symposium4
2013 RERAN: timing- and touch-sensitive record and replay for Android
abstract
Touchscreen-based devices such as smartphones and tablets are gaining popularity, but their rich input capabilities pose new development and testing complications. To alleviate this problem, we present an approach and tool named Reran that permits record-and-replay for the Android smartphone platform. Existing GUI-level record-and-replay approaches are inadequate due to the expressiveness of the smartphone domain, in which applications support sophisticated GUI gestures, depend on inputs from a variety of sensors on the device, and have precise timing requirements among the various input events. We address these challenges by directly capturing the low-level event stream on the phone, which includes both GUI events and sensor events, and replaying it with microsecond accuracy. Moreover, Reran does not require access to app source code, perform any app rewriting, or perform any modifications to the virtual machine or Android platform. We demonstrate RERAN's applicability in a variety of scenarios, including (a) replaying 86 out of the Top-100 Android apps on Google Play; (b) reproducing bugs in popular apps, e.g., Firefox, Facebook, Quickoffice; and (c) fast-forwarding executions. We believe that our versatile approach can help both Android developers and researchers.
Lorenzo Gomez, Iulian Neamtiu, Tanzirul Azim, Todd D. Millstein
ICSE3
2013 Targeted and depth-first exploration for systematic testing of android apps
abstract
Systematic exploration of Android apps is an enabler for a variety of app analysis and testing tasks. Performing the exploration while apps run on actual phones is essential for exploring the full range of app capabilities. However, exploring real-world apps on real phones is challenging due to non-determinism, non-standard control flow, scalability and overhead constraints. Relying on end-users to conduct the exploration might not be very effective: we performed a 7-use study on popular Android apps, and found that the combined 7-use coverage was 30.08% of the app screens and 6.46% of the app methods. Prior approaches for automated exploration of Android apps have run apps in an emulator or focused on small apps whose source code was available. To address these problems, we present A3E, an approach and tool that allows substantial Android apps to be explored systematically while running on actual phones, yet without requiring access to the app's source code. The key insight of our approach is to use a static, taint-style, dataflow analysis on the app bytecode in a novel way, to construct a high-level control flow graph that captures legal transitions among activities (app screens). We then use this graph to develop an exploration strategy named Targeted Exploration that permits fast, direct exploration of activities, including activities that would be difficult to reach during normal use. We also developed a strategy named Depth-first Exploration that mimics user actions for exploring activities and their constituents in a slower, but more systematic way. To measure the effectiveness of our techniques, we use two metrics: activity coverage (number of screens explored) and method coverage. Experiments with using our approach on 25 popular Android apps including BBC News, Gas Buddy, Amazon Mobile, YouTube, Shazam Encore, and CNN, show that our exploration techniques achieve 59.39--64.11% activity coverage and 29.53--36.46% method coverage.
Tanzirul Azim, Iulian Neamtiu
OOPSLA1