Android non-SDK interfaces are APIs that are not part of the official SDK and are restricted. Multiple studies have indicated flaws and limitations of the usage of these non-SDK interfaces, prompting Google to introduce restrictions on non-SDK interfaces to regulate access to these interfaces. This study systematically evaluates the alignment between the official Android guidelines for non-SDK interface usage and the findings from Veridex, a Google tool that assesses the existence of these non-SDK interfaces in Android applications. Our analysis considers the three latest Android versions and reveals inconsistencies, including mismatches in non-SDK interfaces and associated restrictions, as well as contradictions in the enforcement of these restrictions. These inconsistencies highlight significant challenges in the regulatory framework, potentially undermining the effectiveness of measures intended to secure the Android platform.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Systematic Evaluation of Non-SDK Interface Restrictions in Android: Bridging the Gap Between Guidelines and Practice

  • George Silva,
  • Norah Ridley,
  • Enrico Branca,
  • Natalia Stakhanova

摘要

Android non-SDK interfaces are APIs that are not part of the official SDK and are restricted. Multiple studies have indicated flaws and limitations of the usage of these non-SDK interfaces, prompting Google to introduce restrictions on non-SDK interfaces to regulate access to these interfaces. This study systematically evaluates the alignment between the official Android guidelines for non-SDK interface usage and the findings from Veridex, a Google tool that assesses the existence of these non-SDK interfaces in Android applications. Our analysis considers the three latest Android versions and reveals inconsistencies, including mismatches in non-SDK interfaces and associated restrictions, as well as contradictions in the enforcement of these restrictions. These inconsistencies highlight significant challenges in the regulatory framework, potentially undermining the effectiveness of measures intended to secure the Android platform.