MARATTO

dataset · Zenodo (CERN European Organization for Nuclear Research)

Replication package for "Canonicalisation Policy as a Protocol Parameter: A Silent False-Positive Mechanism in Merkle-Based Android Manifest Verification"

2026Open accessHelwan University

In plain language

The abstract on record is too brief for a reliable plain-language summary, so none has been generated.

Abstract

Data and code supporting the paper “Canonicalisation Policy as a Protocol Parameter: A Silent False-Positive Mechanism in Merkle-Based Android Manifest Verification” (Alsaedy, Ghalwash, Yousif, Azzam; submitted to Computer Standards & Interfaces, 2026). The archive contains: leaf counts for PayPal 8.97.0 and Venmo 26.6.0 under each canonicalisation policy (S1, S1b); the case-variant permission declarations found in each application (S2a, S2b); the full record of the verification campaign — 8,000 tampered submissions across four modification classes, with per-layer attribution of every rejection (S3); the warm-up series behind the measurement-artefact analysis (S4); the extraction and measurement code, including a decoder-free Android binary XML string-pool reader and the reference verifier implementation. The application packages themselves are not redistributed, because their publishers restrict redistribution. Every reported result depends only on the manifest, and each record carries the SHA-256 of the package that produced it, so the extraction can be confirmed against the same builds. A README inside the archive documents each file and the steps to reproduce.

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.5281/zenodo.22647066

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.