โปรแกรมการวิจัยด้านความปลอดภัยและความเป็นส่วนตัวของ Android (ASPIRE) ให้ เงินทุนสนับสนุนการวิจัยบางอย่างที่เกี่ยวข้องกับ Android
ASPIRE แก้ปัญหาความท้าทายพื้นฐานผ่านมุมมองด้านการใช้งานจริงและ สนับสนุนการพัฒนาเทคโนโลยีที่อาจกลายเป็นฟีเจอร์หลักของ Android ในอนาคต ซึ่งจะส่งผลต่อระบบนิเวศของ Android ในอีก 2-5 ปีข้างหน้า กรอบเวลาดังกล่าวจะยาวนานกว่าการเปิดตัว Android เวอร์ชันถัดไปในแต่ละปี เพื่อให้มีเวลาเพียงพอในการวิเคราะห์ พัฒนา และทำให้การวิจัยฟีเจอร์ต่างๆ มีความเสถียรก่อนที่จะรวมไว้ในแพลตฟอร์ม โปรดทราบว่าโปรแกรมนี้แตกต่างจากโครงการริเริ่มด้านความปลอดภัยอื่นๆ ของ Android เช่น โปรแกรมการเปิดเผยช่องโหว่
ASPIRE ดำเนินงานโดยการเชิญชวนให้ส่งข้อเสนอหัวข้อการวิจัย ให้เงินทุนสนับสนุนข้อเสนอที่เลือก และจับคู่ผู้ทำงานวิจัยภายนอกกับ Googler เราประกาศรับข้อเสนอปีละ 1 ครั้ง โดยปกติจะประกาศในช่วงกลางปี และประกาศข้อเสนอที่ได้รับเลือกให้รับเงินทุนสนับสนุนภายในสิ้นปีปฏิทิน
นอกเหนือจาก ASPIRE แล้ว หากคุณเป็นนักวิจัยที่สนใจจะขยายขอบเขตด้านความปลอดภัยและความเป็นส่วนตัวของ Android คุณสามารถเข้าร่วมได้หลายวิธี ดังนี้
- สมัครเข้าร่วมการฝึกงานด้านการวิจัยในฐานะนักศึกษาที่กำลังศึกษาต่อในระดับสูงกว่าปริญญาตรี
- สมัครเป็นนักวิจัยผู้มาเยือนที่ Google
- ร่วมเขียนสื่อเผยแพร่กับสมาชิกในทีม Android
- ทำงานร่วมกับสมาชิกในทีม Android เพื่อทำการเปลี่ยนแปลงโปรเจ็กต์โอเพน ซอร์สของ Android
สื่อเผยแพร่ที่ได้รับเงินทุนสนับสนุนจาก ASPIRE
2026
2025
- ScopeVerif: Analyzing the Security of Android's Scoped Storage via Differential Analysis Zeyu Lei, Güliz Seray Tuncay, Beatrice Carissa Williem, Z. Berkay Celik และ Antonio Bianchi Purdue University, Google 2025 [paper]
2024
- SIMurai: Slicing Through the Complexity of SIM Card Security Research Tomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang และ Marius Muench 33rd USENIX Security Symposium [paper] [video] [slides]
- 50 Shades of Support: A Device-Centric Analysis of Android Security Updates. Abbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz, Ahmet Aris และ Selcuk Uluagac Networked and Distributed Systems Security (NDSS) 2024 [paper] [video]
- Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables. Doguhan Yeke, Muhammad Ibrahim, Güliz SerayP Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi และ Z. Berkay Celik. IEEE Symposium on Security and Privacy (S&P) 2024 [paper] [video]
- (In)Security of File Uploads in Node.js. Harun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay, Amin Kharraz, Selcuk Uluagac ACM Web Conference (WWW) 2024 [paper]
2023
- RøB: Ransomware over Modern Web Browsers Oz, Harun, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay, Leonardo Babun และ Selcuk Uluagac USENIX Security Symposium (USENIX Security) 2023 [paper] [video] [slides]
- UE Security Reloaded: Developing a 5G Standalone User-Side Security Testing Framework. E Bitsikas, S Khandker, A Salous, A Ranganathan, R Piqueras Jover, C Pöpper ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) 2023 [paper] [video] [slides]
- The Android Malware Handbook. Qian Han, Salvador Mandujano, Sebastian Porst, V.S. Subrahmanian, Sai Deep Tetali. [book]
- Understanding Dark Patterns in Home IoT Devices Monica Kowalczyk, Johanna T. Gunawan, David Choffnes, Daniel J Dubois, Woodrow Hartzog, Christo Wilson ACM Conference on Human Factors in Computing Systems (CHI) 2023 [paper]
- Continuous Learning for Android Malware Detection Yizheng Chen, Zhoujie Ding และ David Wagner USENIX Security Symposium (USENIX Security) 2023 [paper]
- PolyScope: Multi-Policy Access Control Analysis to Triage Android Scoped Storage. Yu-Tsung Lee, Haining Chen, William Enck, Hayawardh Vijayakumar, Ninghui Li, Zhiyun Qian, Giuseppe Petracca และ Trent Jaeger IEEE Transactions on Dependable and Secure Computing, doi: 10.1109/TDSC.2023.3310402. [paper]
- Triaging Android Systems Using Bayesian Attack Graphs. Yu-Tsung Lee, Rahul George, Haining Chen, Kevin Chan และ Trent Jaeger IEEE Secure Development Conference (SecDev), 2023 [paper]
2022
- SARA: Secure Android Remote Authorization Abdullah Imran, Habiba Farrukh, Muhammad Ibrahim, Z. Berkay Celik และ Antonio Bianchi USENIX Security Symposium (USENIX Security) 2022 [paper] [video] [slides]
- FReD: Identifying File Re-Delegation in Android System Services. Sigmund Albert Gorski III, Seaver Thorn, William Enck และ Haining Chen USENIX Security Symposium (USENIX Security) 2022 [paper] [video] [slides]
- Poirot: Probabilistically Recommending Protections for the Android Framework. Zeinab El-Rewini, Zhuo Zhang, Yousra Aafer ACM Computer and Communication Security (CCS) 2022 [paper]
- Sifter: Protecting Security-Critical Kernel Modules in Android through Attack Surface Reduction. Hsin-Wei Hung, Yingtong Liu, Ardalan Amiri Sani ACM Conference on Mobile Computing And Networking (MobiCom) 2022 [paper]
2021
- An Investigation of the Android Kernel Patch Ecosystem. Zheng Zhang, Hang Zhang, Zhiyun Qian และ Billy Lau USENIX Security Symposium (USENIX Security) 2021 [paper] [video] [slides]
- Demystifying Android's Scoped Storage Defense. Yu-Tsung Lee, Haining Chen และ Trent Jaeger IEEE Security & Privacy, vol. 19, no. 05, pp. 16-25, 2021 [paper]
2019
- Protecting the stack with PACed canaries. ซ. Liljestrand, Z. Gauhar, T. Nyman, J.-E. Ekberg และ N. Asokan [paper]