EDBT 2026 Demo / reviewers in the wild / expert
Oliver Schranz
dblp:167/0506
· DBLP profile ↗
5ranked-venue papers
0as first author
0since 2021 · last 2017
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Systems and software security · 60% Web and mobile security · 37% Authentication and access control · 3% | |
| Software engineering, system software, and programming languages
3 papers |
Compilers and program optimization · 41% Program analysis · 29% Operating systems · 29% |
Topics — the 11 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security › mobile security
android security |
0.6 | 3 | 2017 | The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017 POSTER: The ART of App Compartmentalization · CCS 2016 POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 |
Systems and software security
operating system security |
0.4 | 2 | 2017 | The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017 POSTER: The ART of App Compartmentalization · CCS 2016 |
Compilers and program optimization › program instrumentation
compiler instrumentation |
0.3 | 2 | 2017 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017 |
Systems and software security › operating system security
sandboxing |
0.3 | 2 | 2016 | Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015 POSTER: The ART of App Compartmentalization · CCS 2016 |
Systems and software security › operating system security
privilege separation |
0.3 | 1 | 2017 | The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017 |
Web and mobile security
mobile security |
0.2 | 1 | 2016 | POSTER: The ART of App Compartmentalization · CCS 2016 |
Systems and software security › operating system security › mobile OS security
android sandboxing |
0.2 | 1 | 2015 | Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015 |
Systems and software security › information flow tracking
dynamic taint analysis |
0.2 | 1 | 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 |
Operating systems › system security › operating system security › protection mechanism › isolation
application isolation |
0.2 | 1 | 2015 | Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015 |
Program analysis
dynamic analysis |
0.2 | 1 | 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 |
Authentication and access control
access control |
0.1 | 1 | 2016 | POSTER: The ART of App Compartmentalization · CCS 2016 |
Methods — techniques the papers use, named apart from their topics
inter-process communication protocol design · 0.6compiler instrumentation · 0.6bytecode instrumentation · 0.4app sandboxing · 0.4ahead-of-time compilation · 0.4runtime compartmentalization · 0.2compiler-based instrumentation · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2017 | The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock AndroidabstractThird-party libraries are commonly used by app developers for alleviating the development efforts and for monetizing their apps. On Android, the host app and its third-party libraries reside in the same sandbox and share all privileges awarded to the host app by the user, putting the users' privacy at risk of intrusions by third-party libraries. In this paper, we introduce a new privilege separation approach for third-party libraries on stock Android. Our solution partitions Android applications at compile-time into isolated, privilege-separated compartments for the host app and the included third-party libraries. A particular benefit of our approach is that it leverages compiler-based instrumentation available on stock Android versions and thus abstains from modification of the SDK, the app bytecode, or the device firmware. A particular challenge for separating libraries from their host apps is the reconstruction of the communication channels and the preservation of visual fidelity between the now separated app and its libraries. We solve this challenge through new IPC-based protocols to synchronize layout and lifecycle management between different sandboxes. Finally, we demonstrate the efficiency and effectiveness of our solution by applying it to real world apps from the Google Play Store that contain advertisements. Jie Huang 0010, Oliver Schranz, Sven Bugiel, Michael Backes 0001 |
CCS | 2 |
| 2017 | ARTist: The Android Runtime Instrumentation and Security ToolkitabstractWith the introduction of Android 5 Lollipop, the Android Runtime (ART) superseded the Dalvik Virtual Machine (DVM) by introducing ahead-of-time compilation and native execution of applications, effectively deprecating seminal works such as TaintDroid that hitherto depend on the DVM. In this paper, we discuss alternatives to overcome those restrictions and highlight advantages for the security community that can be derived from ART's novel on-device compiler dex2oat and its accompanying runtime components. To this end, we introduce ARTist, a compiler-based application instrumentation solution for Android that does not depend on operating system modifications and solely operates on the application layer. Since dex2oat is yet uncharted, our approach required first and foremost a thorough study of the compiler suite's internals and in particular of the new default compiler backend called Optimizing. We document the results of this study in this paper to facilitate independent research on this topic and exemplify the viability of ARTist by realizing two use cases. In particular, we conduct a case study on whether taint tracking can be re-instantiated using a compiler-based app instrumentation framework. Overall, our results provide compelling arguments for the community to choose compiler-based approaches over alternative bytecode or binary rewriting approaches for security solutions on Android. Michael Backes 0001, Sven Bugiel, Oliver Schranz, Philipp von Styp-Rekowsky, Sebastian Weisgerber |
EuroS&P | 3 |
| 2016 | POSTER: The ART of App CompartmentalizationabstractOn Android, advertising libraries are commonly integrated with their host apps. Since the host and advertising components share the application's sandbox, advertisement code inherits all permissions and can access host resources with no further approval needed. Motivated by the privacy risks of advertisement libraries as already shown in the literature, this poster introduces an Android Runtime (ART) based app compartmentalization mechanism to achieve separation between trusted app code and untrusted library code without system modification and application rewriting. With our approach, advertising libraries will be isolated from the host app and the original app will be partitioned into two sub-apps that run independently, with the host app's resources and permissions being protected by Android's app sandboxing mechanism. ARTist [1], a compiler-based Android app instrumentation framework, is utilized here to recreate the communication channels between host and advertisement library. The result is a robust toolchain on device which provides a clean separation of developer-written app code and third-party advertisement code, allowing for finer-grained access control policies and information flow control without OS customization and application rebuilding. Michael Backes 0001, Sven Bugiel, Jie Huang 0010, Oliver Schranz |
CCS | 4 |
| 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART)abstractDynamic analysis and taint tracking on Android was typically implemented by instrumenting the Dalvik Virtual Machine. However, the new Android Runtime (ART) introduced in Android 5 replaces the interpreter with an on-device compiler suite. Therefore as of Android 5, the applicability of interpreter instrumentation-based approaches like TaintDroid is limited to Android versions up to 4.4 Kitkat. In this poster, we present ongoing work on re-enabling taint tracking for apps by instrumenting the Optimizing backend, used by the new ART compiler suite for code generation. As Android now compiles apps ahead-of-time from dex bytecode to platform specific native code on the device itself, an instrumented compiler provides the opportunity to emit additional instructions that enable the actual taint tracking. The result is a custom compiler that takes arbitrary app APKs and transforms them into self-taint tracking native code, executable by the Android Runtime. Michael Backes 0001, Oliver Schranz, Philipp von Styp-Rekowsky |
CCS | 2 |
| 2015 | Boxify: Full-fledged App Sandboxing for Stock Android
Michael Backes 0001, Sven Bugiel, Christian Hammer 0001, Oliver Schranz, Philipp von Styp-Rekowsky |
USENIX Security Symposium | 4 |