Lib2Desc: automatic generation of security-centric Android app descriptions using third-party libraries

dc.authoridSen, Sevil/0000-0001-5814-9973
dc.authoridCevik, Beyza/0000-0002-3266-2389
dc.authorwosidSen, Sevil/AGP-4619-2022
dc.contributor.authorÇevik, Beyza
dc.contributor.authorAltıparmak, Nur
dc.contributor.authorAksu, Murat
dc.contributor.authorŞen, Sevil
dc.date.accessioned2023-03-22T19:47:31Z
dc.date.available2023-03-22T19:47:31Z
dc.date.issued2022
dc.departmentBelirleneceken_US
dc.description.abstractAndroid app developers are expected to specify the use of dangerous permissions in their app descriptions. The absence of such data indicates suspicious behavior. However, this is not always caused by the malicious intent of developers; it may be due to the lack of documentation of the third-party libraries they use. To fill this gap in the literature, this study aims to enrich application descriptions with security-centric information of third-party libraries. To automatically generate application definitions, the study explores classifying libraries and extracting code summaries of library methods that use dangerous permissions and/or leak data. Both the textual information of third-party libraries and their source code are used to create these definitions. To the best of our knowledge, this is the first approach in the literature that creates app descriptions based on third-party libraries.en_US
dc.description.sponsorshipTUBITAK; Scientific and Technological Research Council of Turkey [TUBITAK-118E141]en_US
dc.description.sponsorshipWe would like to thank TUBITAK for its support. This study is supported by the Scientific and Technological Research Council of Turkey (TUBITAK-118E141).en_US
dc.identifier.doi10.1007/s10207-022-00601-x
dc.identifier.endpage1125en_US
dc.identifier.issn1615-5262
dc.identifier.issn1615-5270
dc.identifier.issue5en_US
dc.identifier.scopus2-s2.0-85135358336en_US
dc.identifier.scopusqualityQ1en_US
dc.identifier.startpage1107en_US
dc.identifier.urihttps://doi.org/10.1007/s10207-022-00601-x
dc.identifier.urihttps://hdl.handle.net/20.500.14034/748
dc.identifier.volume21en_US
dc.identifier.wosWOS:000836129900001en_US
dc.identifier.wosqualityQ2en_US
dc.indekslendigikaynakWeb of Scienceen_US
dc.indekslendigikaynakScopusen_US
dc.language.isoenen_US
dc.publisherSpringeren_US
dc.relation.journalInternational Journal Of Information Securityen_US
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/closedAccessen_US
dc.subjectAndroid securityen_US
dc.subjectDescription-to-permission fidelityen_US
dc.subjectThird-party librariesen_US
dc.subjectNLPen_US
dc.subjectNLGen_US
dc.subjectSelectionen_US
dc.titleLib2Desc: automatic generation of security-centric Android app descriptions using third-party librariesen_US
dc.typeArticleen_US

Dosyalar

Orijinal paket
Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
murat aksu.pdf
Boyut:
1.12 MB
Biçim:
Adobe Portable Document Format
Açıklama:
Tam metin / Full text