Back to results

University of Saskatchewan

Security Implications of Reflection across the Android Ecosystem

Abstract

dc:description.abstract

As Android continues to evolve into a general-purpose operating system beyond smartphones, reflection provides adversaries with a practical mechanism to evade modern API restrictions and undermine defenses that rely on static linkage. In this thesis, we show that, despite the mitigation measures introduced by Google, reflection remains a persistent and systemic threat across the Android ecosystem. We position reflection as the central exploitation mechanism and demonstrate how both traditional and novel attacks can be executed using reflection as a gateway. In this work, we implement three representative attacks: an Audio Service attack, an Intent Storm attack, and a Launcher attack. We evaluate them across Android Studio emulator images (mobile, TV, Wear OS, and AAOS/OEM) and multiple physical devices spanning API levels 30–36. The resulting behaviours include service disruption and sustained system server load, with emulator instances often requiring cold boot recovery and physical devices exhibiting auto reboot along with noticeable thermal spikes. Our findings highlight that reflection enables adaptable, version-resilient exploitation patterns that amplify impact through concurrency and runtime discovery, motivating the need for stronger policy enforcement and monitoring of reflective access paths and high frequency system-service interactions across Android form factors.

Degree

thesis:*
Name thesis:degree_name
Master of Science (M.Sc.)
Level thesis:degree_level
Masters
Discipline thesis:degree_discipline
Computer Science
Grantor
University of Saskatchewan
Year dc:date.issued
2026

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Khan, Faiyaz
Advisor dc:contributor.advisor
  • Stakhanova, Natalia
Committee members dc:contributor.committeemember
  • Dutchyn, Christopher
  • Eager, Derek

Subjects

dc:subject × 1

Rights

Language dc:language.iso
en

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10388/17995
OAI identifier oai:identifier
oai:harvest.usask.ca:10388/17995

Chain of custody

source
Harvested from
University of Saskatchewan
Base URL
harvest.usask.ca/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Khan, Faiyaz. Security Implications of Reflection across the Android Ecosystem. Masters thesis, University of Saskatchewan, 2026. https://hdl.handle.net/10388/17995