首页> 外文期刊>Computers & Security >An efficient approach for taint analysis of android applications
【24h】

An efficient approach for taint analysis of android applications

机译:Android应用的污染分析有效的方法

获取原文
获取原文并翻译 | 示例

摘要

In recent years, sensitive data leaks of Android system attracted significant attention. The traditional facilities proposed for detecting these leaks, i.e. taint analysis, mostly focus on the precision and recall of the result with few of them addressing the importance of the cost and efficiency. As a matter of fact, the high costs of these tools often make them fail in analyzing large-scale apps and thus block them from wide usage in practice. In this paper, we propose FastDroid, an efficient and precise approach for taint analysis in Android apps with flow and context-sensitivity. First, upon groups of taint rules, a preliminary flow-insensitive taint analysis is conducted to construct the taint value graph which is an abstraction defined to describe the process of taint propagation in an app. Then, potential taint flows are extracted from the taint value graphs and further checked on the control flow graph to acquire the real taint flows. FastDroid is evaluated on the benchmark DroidBench, 1517 apps from Google Play store and 1022 apps from AndroZoo. The results show that the F-measure scores of FastDroid on DroidBench 2.0 and 3.0 are 0.89 and 0.75 respectively, the performance is better than the state-of-the-art tool FlowDroid. Further, a comparison on runtime with FlowDroid shows that FastDroid improves the efficiency significantly.
机译:近年来,Android系统的敏感数据泄漏引起了重大关注。所提出的传统设施,用于检测这些泄漏,即污染分析,主要集中在结果的精确度和回忆中,其中很少有人解决了成本和效率的重要性。事实上,这些工具的高成本通常会使它们在分析大型应用程序时,因此阻止他们在实践中广泛使用。在本文中,我们提出了具有流动和背景敏感性的Android应用中的Taint分析的快速,精确方法。首先,在污染规则组上,进行初步流动不敏感的污染污染分析以构造一个被定义的抽象来构造污点图,以描述应用中的污染传播过程。然后,从污染图中提取潜在的污染流,并进一步检查控制流程图以获取真实的污染流。 FastDroid在Genchmark Droidbench,来自Google Play商店的1517个应用程序和来自Androzoo的1022个应用程序。结果表明,在Droidbench 2.0和3.0上的Fastfolid的F测量分数分别为0.89和0.75,性能优于最先进的工具流动性。此外,与流动的流动的运行时间进行比较表明,Fastdroid显着提高了效率。

著录项

  • 来源
    《Computers & Security》 |2021年第5期|102161.1-102161.16|共16页
  • 作者单位

    School of Computer Science and Technology Xidian University Xi'an 710071 P.R. China ICTT and ISN Laboratory Xidian University Xi'an 710071 P.R. China;

    School of Computer Science and Technology Xidian University Xi'an 710071 P.R. China ICTT and ISN Laboratory Xidian University Xi'an 710071 P.R. China;

    School of Computer Science and Technology Xidian University Xi'an 710071 P.R. China ICTT and ISN Laboratory Xidian University Xi'an 710071 P.R. China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Android; Security; Static analysis; Taint analysis; Privacy;

    机译:安卓;安全;静态分析;污点分析;隐私;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号