EDBT 2026 Demo / reviewers in the wild / expert
Philipp von Styp-Rekowsky
dblp:94/9829
· DBLP profile ↗
6ranked-venue papers
0as first author
0since 2021 · last 2017
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4Software engineering, systems software and programming languages · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Systems and software security · 93% Web and mobile security · 7% | |
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 30% Compilers and program optimization · 30% Operating systems · 30% |
Topics — the 8 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › operating system security
sandboxing |
0.5 | 2 | 2016 | Mining sandboxes · ICSE 2016 Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015 |
Systems and software security › operating system security › mobile OS security
android sandboxing |
0.2 | 1 | 2015 | Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015 |
Systems and software security › information flow tracking
dynamic taint analysis |
0.2 | 1 | 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 |
Operating systems › system security › operating system security › protection mechanism › isolation
application isolation |
0.2 | 1 | 2015 | Boxify: Full-fledged App Sandboxing for Stock Android · USENIX Security Symposium 2015 |
Compilers and program optimization › program instrumentation
compiler instrumentation |
0.2 | 1 | 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 |
Program analysis
dynamic analysis |
0.2 | 1 | 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 |
Software testing › test generation
automated test generation |
0.1 | 1 | 2016 | Mining sandboxes · ICSE 2016 |
Web and mobile security › mobile security
android security |
0.1 | 1 | 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART) · CCS 2015 |
Methods — techniques the papers use, named apart from their topics
resource access profiling · 0.5automatic test generation · 0.5bytecode instrumentation · 0.4app sandboxing · 0.4ahead-of-time compilation · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2017 | ARTist: The Android Runtime Instrumentation and Security ToolkitabstractWith the introduction of Android 5 Lollipop, the Android Runtime (ART) superseded the Dalvik Virtual Machine (DVM) by introducing ahead-of-time compilation and native execution of applications, effectively deprecating seminal works such as TaintDroid that hitherto depend on the DVM. In this paper, we discuss alternatives to overcome those restrictions and highlight advantages for the security community that can be derived from ART's novel on-device compiler dex2oat and its accompanying runtime components. To this end, we introduce ARTist, a compiler-based application instrumentation solution for Android that does not depend on operating system modifications and solely operates on the application layer. Since dex2oat is yet uncharted, our approach required first and foremost a thorough study of the compiler suite's internals and in particular of the new default compiler backend called Optimizing. We document the results of this study in this paper to facilitate independent research on this topic and exemplify the viability of ARTist by realizing two use cases. In particular, we conduct a case study on whether taint tracking can be re-instantiated using a compiler-based app instrumentation framework. Overall, our results provide compelling arguments for the community to choose compiler-based approaches over alternative bytecode or binary rewriting approaches for security solutions on Android. Michael Backes 0001, Sven Bugiel, Oliver Schranz, Philipp von Styp-Rekowsky, Sebastian Weisgerber |
EuroS&P | 4 |
| 2016 | Mining sandboxesabstractWe present sandbox mining, a technique to confine an application to resources accessed during automatic testing. Sandbox mining first explores software behavior by means of automatic test generation, and extracts the set of resources accessed during these tests. This set is then used as a sandbox, blocking access to resources not used during testing. The mined sandbox thus protects against behavior changes such as the activation of latent malware, infections, targeted attacks, or malicious updates. Konrad Jamrozik, Philipp von Styp-Rekowsky, Andreas Zeller |
ICSE | 2 |
| 2015 | POSTER: Towards Compiler-Assisted Taint Tracking on the Android Runtime (ART)abstractDynamic analysis and taint tracking on Android was typically implemented by instrumenting the Dalvik Virtual Machine. However, the new Android Runtime (ART) introduced in Android 5 replaces the interpreter with an on-device compiler suite. Therefore as of Android 5, the applicability of interpreter instrumentation-based approaches like TaintDroid is limited to Android versions up to 4.4 Kitkat. In this poster, we present ongoing work on re-enabling taint tracking for apps by instrumenting the Optimizing backend, used by the new ART compiler suite for code generation. As Android now compiles apps ahead-of-time from dex bytecode to platform specific native code on the device itself, an instrumented compiler provides the opportunity to emit additional instructions that enable the actual taint tracking. The result is a custom compiler that takes arbitrary app APKs and transforms them into self-taint tracking native code, executable by the Android Runtime. Michael Backes 0001, Oliver Schranz, Philipp von Styp-Rekowsky |
CCS | 3 |
| 2015 | Boxify: Full-fledged App Sandboxing for Stock Android
Michael Backes 0001, Sven Bugiel, Christian Hammer 0001, Oliver Schranz, Philipp von Styp-Rekowsky |
USENIX Security Symposium | 5 |
| 2014 | Android security framework: extensible multi-layered access control on AndroidabstractWe introduce the Android Security Framework (ASF), a generic, extensible security framework for Android that enables the development and integration of a wide spectrum of security models in form of code-based security modules. The design of ASF reflects lessons learned from the literature on established security frameworks (such as Linux Security Modules or the BSD MAC Framework) and intertwines them with the particular requirements and challenges from the design of Android's software stack. ASF provides a novel security API that supports authors of Android security extensions in developing their modules. This overcomes the current unsatisfactory situation to provide security solutions as separate patches to the Android software stack or to embed them into Android's mainline codebase. This system security extensibility is of particular benefit for enterprise or government solutions that require deployment of advanced security models, not supported by vanilla Android. We present a prototypical implementation of ASF and demonstrate its effectiveness and efficiency by modularizing different security models from related work, such as dynamic permissions, inlined reference monitoring, and type enforcement. Michael Backes 0001, Sven Bugiel, Sebastian Gerling, Philipp von Styp-Rekowsky |
ACSAC | 4 |
| 2013 | AppGuard - Enforcing User Requirements on Android Apps
Michael Backes 0001, Sebastian Gerling, Christian Hammer 0001, Matteo Maffei, Philipp von Styp-Rekowsky |
TACAS | 5 |