Oliver Schranz

dblp:167/0506 · DBLP profile ↗
← Back
5ranked-venue papers
0as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Systems and software security · 60% Web and mobile security · 37% Authentication and access control · 3%
Software engineering, system software, and programming languages
3 papers
Compilers and program optimization · 41% Program analysis · 29% Operating systems · 29%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Web and mobile security › mobile security
android security
0.632017
The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017
POSTER: The ART of App Compartmentalization · CCS 2016
POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015
Systems and software security
operating system security
0.422017
The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017
POSTER: The ART of App Compartmentalization · CCS 2016
Compilers and program optimization › program instrumentation
compiler instrumentation
0.322017
POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015
The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017
Systems and software security › operating system security
sandboxing
0.322016
Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015
POSTER: The ART of App Compartmentalization · CCS 2016
Systems and software security › operating system security
privilege separation
0.312017
The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android · CCS 2017
Web and mobile security
mobile security
0.212016
POSTER: The ART of App Compartmentalization · CCS 2016
Systems and software security › operating system security › mobile OS security
android sandboxing
0.212015
Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015
Systems and software security › information flow tracking
dynamic taint analysis
0.212015
POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015
Operating systems › system security › operating system security › protection mechanism › isolation
application isolation
0.212015
Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015
Program analysis
dynamic analysis
0.212015
POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015
Authentication and access control
access control
0.112016
POSTER: The ART of App Compartmentalization · CCS 2016

Methods — techniques the papers use, named apart from their topics

inter-process communication protocol design · 0.6compiler instrumentation · 0.6bytecode instrumentation · 0.4app sandboxing · 0.4ahead-of-time compilation · 0.4runtime compartmentalization · 0.2compiler-based instrumentation · 0.2
YearPublicationVenuePosition
2017 The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android
abstract
Third-party libraries are commonly used by app developers for alleviating the development efforts and for monetizing their apps. On Android, the host app and its third-party libraries reside in the same sandbox and share all privileges awarded to the host app by the user, putting the users' privacy at risk of intrusions by third-party libraries. In this paper, we introduce a new privilege separation approach for third-party libraries on stock Android. Our solution partitions Android applications at compile-time into isolated, privilege-separated compartments for the host app and the included third-party libraries. A particular benefit of our approach is that it leverages compiler-based instrumentation available on stock Android versions and thus abstains from modification of the SDK, the app bytecode, or the device firmware. A particular challenge for separating libraries from their host apps is the reconstruction of the communication channels and the preservation of visual fidelity between the now separated app and its libraries. We solve this challenge through new IPC-based protocols to synchronize layout and lifecycle management between different sandboxes. Finally, we demonstrate the efficiency and effectiveness of our solution by applying it to real world apps from the Google Play Store that contain advertisements.
Jie Huang 0010, Oliver Schranz, Sven Bugiel, Michael Backes 0001
CCS2
2017 ARTist: The Android Runtime Instrumentation and Security Toolkit
abstract
With the introduction of Android 5 Lollipop, the Android Runtime (ART) superseded the Dalvik Virtual Machine (DVM) by introducing ahead-of-time compilation and native execution of applications, effectively deprecating seminal works such as TaintDroid that hitherto depend on the DVM. In this paper, we discuss alternatives to overcome those restrictions and highlight advantages for the security community that can be derived from ART's novel on-device compiler dex2oat and its accompanying runtime components. To this end, we introduce ARTist, a compiler-based application instrumentation solution for Android that does not depend on operating system modifications and solely operates on the application layer. Since dex2oat is yet uncharted, our approach required first and foremost a thorough study of the compiler suite's internals and in particular of the new default compiler backend called Optimizing. We document the results of this study in this paper to facilitate independent research on this topic and exemplify the viability of ARTist by realizing two use cases. In particular, we conduct a case study on whether taint tracking can be re-instantiated using a compiler-based app instrumentation framework. Overall, our results provide compelling arguments for the community to choose compiler-based approaches over alternative bytecode or binary rewriting approaches for security solutions on Android.
Michael Backes 0001, Sven Bugiel, Oliver Schranz, Philipp von Styp-Rekowsky, Sebastian Weisgerber
EuroS&P3
2016 POSTER: The ART of App Compartmentalization
abstract
On Android, advertising libraries are commonly integrated with their host apps. Since the host and advertising components share the application's sandbox, advertisement code inherits all permissions and can access host resources with no further approval needed. Motivated by the privacy risks of advertisement libraries as already shown in the literature, this poster introduces an Android Runtime (ART) based app compartmentalization mechanism to achieve separation between trusted app code and untrusted library code without system modification and application rewriting. With our approach, advertising libraries will be isolated from the host app and the original app will be partitioned into two sub-apps that run independently, with the host app's resources and permissions being protected by Android's app sandboxing mechanism. ARTist [1], a compiler-based Android app instrumentation framework, is utilized here to recreate the communication channels between host and advertisement library. The result is a robust toolchain on device which provides a clean separation of developer-written app code and third-party advertisement code, allowing for finer-grained access control policies and information flow control without OS customization and application rebuilding.
Michael Backes 0001, Sven Bugiel, Jie Huang 0010, Oliver Schranz
CCS4
2015 POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART)
abstract
Dynamic analysis and taint tracking on Android was typically implemented by instrumenting the Dalvik Virtual Machine. However, the new Android Runtime (ART) introduced in Android 5 replaces the interpreter with an on-device compiler suite. Therefore as of Android 5, the applicability of interpreter instrumentation-based approaches like TaintDroid is limited to Android versions up to 4.4 Kitkat. In this poster, we present ongoing work on re-enabling taint tracking for apps by instrumenting the Optimizing backend, used by the new ART compiler suite for code generation. As Android now compiles apps ahead-of-time from dex bytecode to platform specific native code on the device itself, an instrumented compiler provides the opportunity to emit additional instructions that enable the actual taint tracking. The result is a custom compiler that takes arbitrary app APKs and transforms them into self-taint tracking native code, executable by the Android Runtime.
Michael Backes 0001, Oliver Schranz, Philipp von Styp-Rekowsky
CCS2
2015 Boxify: Full-fledged App Sandboxing for Stock Android
Michael Backes 0001, Sven Bugiel, Christian Hammer 0001, Oliver Schranz, Philipp von Styp-Rekowsky
USENIX Security Symposium4