Le programme Android Security and Privacy Research (ASPIRE) finance certaines recherches liées à Android.
ASPIRE s'attaque à des défis fondamentaux sous un angle pratique et encourage le développement de technologies qui pourraient devenir des fonctionnalités Android de base à l'avenir, affectant l'écosystème Android dans les deux à cinq prochaines années. Ce délai s'étend au-delà de la prochaine version annuelle d'Android pour laisser suffisamment de temps pour analyser, développer et stabiliser la recherche sur les fonctionnalités avant de les inclure dans la plate-forme. Notez que cela est distinct d'autres initiatives de sécurité Android telles que le programme de divulgation des failles.
ASPIRE fonctionne en invitant les propositions de sujets de recherche, en finançant certaines propositions et en mettant en relation des chercheurs externes avec des employés de Google. Nous publions un appel à propositions une fois par an, généralement au milieu de l'année, et annonçons les propositions sélectionnées pour le financement d'ici la fin de l'année civile.
Au-delà d'ASPIRE, si vous êtes un chercheur intéressé par le développement de la sécurité et de la confidentialité d'Android, vous pouvez participer de plusieurs manières :
- Postulez à un stage de recherche en tant qu'étudiant poursuivant des études supérieures.
- Postulez pour devenir chercheur invité chez Google.
- Coécrivez des publications avec des membres de l'équipe Android.
- Collaborez avec des membres de l'équipe Android pour apporter des modifications au projet Android Open Source.
Publications financées par ASPIRE
2026
2025
- ScopeVerif: Analyzing the Security of Android's Scoped Storage via Differential Analysis Zeyu Lei, Güliz Seray Tuncay, Beatrice Carissa Williem, Z. Berkay Celik et Antonio Bianchi. Université Purdue, Google 2025 [paper]
2024
- SIMurai: Slicing Through the Complexity of SIM Card Security Research Tomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang et Marius Muench. 33e symposium USENIX sur la sécurité. [paper] [video] [slides]
- 50 Shades of Support: A Device-Centric Analysis of Android Security Updates. Abbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz, Ahmet Aris et Selcuk Uluagac. Sécurité des systèmes en réseau et distribués (NDSS) 2024. [paper] [video]
- Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables. Doguhan Yeke, Muhammad Ibrahim, Güliz SerayP Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi et Z. Berkay Celik. IEEE Symposium on Security and Privacy (S&P) 2024. [paper] [video]
- (In)Security of File Uploads in Node.js. Harun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay, Amin Kharraz, Selcuk Uluagac. ACM Web Conference (WWW) 2024. [paper]
2023
- RøB: Ransomware over Modern Web Browsers. Oz, Harun, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay, Leonardo Babun et Selcuk Uluagac. USENIX Security Symposium (USENIX Security) 2023. [paper] [video] [slides]
- UE Security Reloaded: Developing a 5G Standalone User-Side Security Testing Framework. E Bitsikas, S Khandker, A Salous, A Ranganathan, R Piqueras Jover et C Pöpper. ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) 2023. [paper] [video] [slides]
- The Android Malware Handbook. Qian Han, Salvador Mandujano, Sebastian Porst, V.S. Subrahmanian et Sai Deep Tetali. [book]
- Understanding Dark Patterns in Home IoT Devices. Monica Kowalczyk, Johanna T. Gunawan, David Choffnes, Daniel J Dubois, Woodrow Hartzog, Christo Wilson. ACM Conference on Human Factors in Computing Systems (CHI) 2023. [paper]
- Continuous Learning for Android Malware Detection. Yizheng Chen, Zhoujie Ding et David Wagner. USENIX Security Symposium (USENIX Security) 2023. [paper]
- PolyScope: Multi-Policy Access Control Analysis to Triage Android Scoped Storage. Yu-Tsung Lee, Haining Chen, William Enck, Hayawardh Vijayakumar, Ninghui Li, Zhiyun Qian, Giuseppe Petracca et Trent Jaeger. IEEE Transactions on Dependable and Secure Computing, doi: 10.1109/TDSC.2023.3310402. [paper]
- Triaging Android Systems Using Bayesian Attack Graphs. Yu-Tsung Lee, Rahul George, Haining Chen, Kevin Chan et Trent Jaeger. IEEE Secure Development Conference (SecDev), 2023. [paper]
2022
- SARA: Secure Android Remote Authorization. Abdullah Imran, Habiba Farrukh, Muhammad Ibrahim, Z. Berkay Celik et Antonio Bianchi. USENIX Security Symposium (USENIX Security) 2022. [paper] [video] [slides]
- FReD: Identifying File Re-Delegation in Android System Services. Sigmund Albert Gorski III, Seaver Thorn, William Enck et Haining Chen. USENIX Security Symposium (USENIX Security) 2022. [paper] [video] [slides]
- Poirot: Probabilistically Recommending Protections for the Android Framework. Zeinab El-Rewini, Zhuo Zhang et Yousra Aafer. ACM Computer and Communication Security (CCS) 2022. [paper]
- Sifter: Protecting Security-Critical Kernel Modules in Android through Attack Surface Reduction. Hsin-Wei Hung, Yingtong Liu et Ardalan Amiri Sani. ACM Conference on Mobile Computing And Networking (MobiCom) 2022. [paper]
2021
- An Investigation of the Android Kernel Patch Ecosystem. Zheng Zhang, Hang Zhang, Zhiyun Qian et Billy Lau. USENIX Security Symposium (USENIX Security) 2021. [paper] [video] [slides]
- Demystifying Android's Scoped Storage Defense. Yu-Tsung Lee, Haining Chen et Trent Jaeger. IEEE Security & Privacy, vol. 19, no. 05, pp. 16-25, 2021. [paper]
2019
- Protecting the stack with PACed canaries. H. Liljestrand, Z. Gauhar, T. Nyman, J.-E. Ekberg et N. Asokan. [paper]