ASPIRE

El programa de investigación de seguridad y privacidad de Android (ASPIRE) proporciona financiamiento para ciertas investigaciones relacionadas con Android.

ASPIRE aborda desafíos fundamentales desde la perspectiva de la practicidad y fomenta el desarrollo de tecnologías que pueden convertirse en funciones principales de Android en el futuro, lo que afectará el ecosistema de Android en los próximos 2 a 5 años. Este período se extiende más allá de la próxima versión anual de Android para permitir el tiempo adecuado para analizar, desarrollar y estabilizar la investigación sobre las funciones antes de incluirlas en la plataforma. Ten en cuenta que esto es distinto de otras iniciativas de seguridad de Android como el programa de divulgación de vulnerabilidades.

ASPIRE funciona invitando propuestas para temas de investigación, proporcionando financiamiento para propuestas seleccionadas y asociando investigadores externos con Googlers. Anunciamos una convocatoria de propuestas una vez al año, por lo general, a mediados de año, y anunciamos las propuestas seleccionadas para financiamiento a fines del año calendario.

Además de ASPIRE, si eres un investigador interesado en ampliar los límites de la seguridad y la privacidad de Android, hay varias formas de participar:

  • Postúlate para una investigación pasantía como estudiante que cursa un título avanzado.
  • Postúlate para convertirte en investigador visitante en Google.
  • Sé coautor de publicaciones con miembros del equipo de Android.
  • Colabora con miembros del equipo de Android para realizar cambios en el Proyecto de código abierto de Android.

Publicaciones financiadas por ASPIRE

2026

  • A Compilation-Based Under-Constrained Execution Engine Mingjun Yin, Zhaorui Li, Ju Chen, Haochen Zeng y Chengyu Song. Universidad de California, Riverside. Diseño e implementación de sistemas operativos (OSDI) 2026. [paper] [slides]

2025

  • ScopeVerif: Analyzing the Security of Android's Scoped Storage via Differential Analysis Zeyu Lei, Güliz Seray Tuncay, Beatrice Carissa Williem, Z. Berkay Celik y Antonio Bianchi. Universidad de Purdue, Google 2025 [paper]
  • LANShield: Analysing and Protecting Local Network Access on Mobile Devices. Angelos Beitis, Jeroen Robben, Alexander Matern, Zhen Lei, Yijia Li, Nian Xue, Yongle Chen, Vik Vanderlinden y Mathy Vanhoef. 25th Privacy Enhancing Technologies Symposium (PETS) 2025. [paper] [website]

2024

  • SIMurai: Slicing Through the Complexity of SIM Card Security Research Tomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang y Marius Muench. 33rd USENIX Security Symposium. [paper] [video] [slides]
  • 50 Shades of Support: A Device-Centric Analysis of Android Security Updates. Abbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz, Ahmet Aris y Selcuk Uluagac. Networked and Distributed Systems Security (NDSS) 2024. [paper] [video]
  • Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables. Doguhan Yeke, Muhammad Ibrahim, Güliz SerayP Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi y Z. Berkay Celik. IEEE Symposium on Security and Privacy (S&P) 2024. [paper] [video]
  • (In)Security of File Uploads in Node.js. Harun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay, Amin Kharraz y Selcuk Uluagac. ACM Web Conference (WWW) 2024. [paper]

2023

  • RøB: Ransomware over Modern Web Browsers. Oz, Harun, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay, Leonardo Babun y Selcuk Uluagac. USENIX Security Symposium (USENIX Security) 2023. [paper] [video] [slides]
  • UE Security Reloaded: Developing a 5G Standalone User-Side Security Testing Framework. E Bitsikas, S Khandker, A Salous, A Ranganathan, R Piqueras Jover y C Pöpper. ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) 2023. [paper] [video] [slides]
  • The Android Malware Handbook. Qian Han, Salvador Mandujano, Sebastian Porst, V.S. Subrahmanian y Sai Deep Tetali. [book]
  • Understanding Dark Patterns in Home IoT Devices. Monica Kowalczyk, Johanna T. Gunawan, David Choffnes, Daniel J Dubois, Woodrow Hartzog, Christo Wilson. ACM Conference on Human Factors in Computing Systems (CHI) 2023. [paper]
  • Continuous Learning for Android Malware Detection. Yizheng Chen, Zhoujie Ding y David Wagner. USENIX Security Symposium (USENIX Security) 2023. [paper]
  • PolyScope: Multi-Policy Access Control Analysis to Triage Android Scoped Storage. Yu-Tsung Lee, Haining Chen, William Enck, Hayawardh Vijayakumar, Ninghui Li, Zhiyun Qian, Giuseppe Petracca y Trent Jaeger. IEEE Transactions on Dependable and Secure Computing, doi: 10.1109/TDSC.2023.3310402. [paper]
  • Triaging Android Systems Using Bayesian Attack Graphs. Yu-Tsung Lee, Rahul George, Haining Chen, Kevin Chan y Trent Jaeger. IEEE Secure Development Conference (SecDev), 2023. [paper]

2022

  • SARA: Secure Android Remote Authorization. Abdullah Imran, Habiba Farrukh, Muhammad Ibrahim, Z. Berkay Celik y Antonio Bianchi. USENIX Security Symposium (USENIX Security) 2022. [paper] [video] [slides]
  • FReD: Identifying File Re-Delegation in Android System Services. Sigmund Albert Gorski III, Seaver Thorn, William Enck y Haining Chen. USENIX Security Symposium (USENIX Security) 2022. [paper] [video] [slides]
  • Poirot: Probabilistically Recommending Protections for the Android Framework. Zeinab El-Rewini, Zhuo Zhang y Yousra Aafer. ACM Computer and Communication Security (CCS) 2022. [paper]
  • Sifter: Protecting Security-Critical Kernel Modules in Android through Attack Surface Reduction. Hsin-Wei Hung, Yingtong Liu y Ardalan Amiri Sani. ACM Conference on Mobile Computing And Networking (MobiCom) 2022. [paper]

2021

  • An Investigation of the Android Kernel Patch Ecosystem. Zheng Zhang, Hang Zhang, Zhiyun Qian y Billy Lau. USENIX Security Symposium (USENIX Security) 2021. [paper] [video] [slides]
  • Demystifying Android's Scoped Storage Defense. Yu-Tsung Lee, Haining Chen y Trent Jaeger. IEEE Security & Privacy, vol. 19, no. 05, pp. 16-25, 2021. [paper]

2019

  • Protecting the stack with PACed canaries. H. Liljestrand, Z. Gauhar, T. Nyman, J.-E. Ekberg y N. Asokan. [paper]