DAISY: Dynamic-Analysis-Induced Source Discovery for Sensitive Data

DAISY: Dynamic-Analysis-Induced Source Discovery for Sensitive Data
复制标题

DOI:
10.1145/3569936
复制
发表时间:
2022-10
影响因子:
4.4
通讯作者:
Xueling Zhang;John Heaps;Rocky Slavin;Jianwei Niu;T. Breaux;Xiaoyin Wang
Xueling Zhang;John Heaps;Rocky Slavin;Jianwei Niu;T. Breaux;Xiaoyin Wang
中科院分区:
计算机科学1区
文献类型:
--
作者:
Xueling Zhang;John Heaps;Rocky Slavin;Jianwei Niu;T. Breaux;Xiaoyin Wang

文献摘要

相似文献

移动应用程序被广泛使用,并且经常处理用户的敏感数据。许多污点分析工具已被应用于分析应用程序中的敏感信息流并报告数据泄漏。这些工具需要一个源列表(访问敏感数据的地方)作为输入,研究人员通过识别允许访问敏感数据的 Android API 方法,在 Android 平台内构建了此类列表。但是,应用程序开发人员也可以定义方法或使用第三方库的方法来访问数据。收集此类源方法很困难,因为它们是应用程序所独有的,并且市场上有大量可用的第三方库,并且随着时间的推移而不断发展。为了解决这个问题,我们提出了 DAISY,一种动态分析诱导的源发现方法,用于识别从应用程序和第三方库返回敏感信息的方法。 DAISY 在自动标记的方法数据集及其调用上下文上进行训练,可以识别看不见的应用程序中的敏感方法。我们在现实世界的应用程序上评估了 DAISY,结果表明,DAISY 在报告最置信度结果时可以实现 77.9% 的总体精度。现有技术无法检测到大多数已识别的来源和泄漏。
Mobile apps are widely used and often process users’ sensitive data. Many taint analysis tools have been applied to analyze sensitive information flows and report data leaks in apps. These tools require a list of sources (where sensitive data is accessed) as input, and researchers have constructed such lists within the Android platform by identifying Android API methods that allow access to sensitive data. However, app developers may also define methods or use third-party library’s methods for accessing data. It is difficult to collect such source methods, because they are unique to the apps, and there are a large number of third-party libraries available on the market that evolve over time. To address this problem, we propose DAISY, a Dynamic-Analysis-Induced Source discoverY approach for identifying methods that return sensitive information from apps and third-party libraries. Trained on an automatically labeled dataset of methods and their calling context, DAISY identifies sensitive methods in unseen apps. We evaluated DAISY on real-world apps, and the results show that DAISY can achieve an overall precision of 77.9% when reporting the most confident results. Most of the identified sources and leaks cannot be detected by existing technologies.