FlowDroid: Precise Context, Flow, Field, Object-sensitive and Lifecycle-aware Taint Analysis for Android Apps

FlowDroid: Precise Context, Flow, Field, Object-sensitive and Lifecycle-aware Taint Analysis for Android Apps
复制标题

DOI:
10.1145/2594291.2594299
复制
发表时间:
2014-06-01
影响因子:
--
通讯作者:
McDaniel, Patrick
McDaniel, Patrick
中科院分区:
其他
文献类型:
--
作者:
Arzt, Steven;Rasthofer, Siegfried;McDaniel, Patrick

文献摘要

被引文献

相似文献

如今的智能手机是一个无处不在的私人和机密数据来源。与此同时,智能手机用户也受到编程不严谨的应用程序的困扰,这些应用程序会意外泄露重要数据,而恶意应用程序会利用用户的特权故意复制这些数据。虽然现有的静态污染分析方法具有提前检测此类数据泄漏的潜力,但Android的所有方法都使用大量粗粒度近似,可能会产生大量遗漏的泄漏和假警报。在这项工作中,我们因此提出了FLOWDROID,一种新颖的、高度精确的Android应用程序静态污染分析。Android生命周期的精确模型允许分析正确处理Android框架调用的回调,而上下文,流,字段和对象敏感性允许分析减少假警报的数量。新颖的按需算法帮助FLOWDROID同时保持高效率和精度。我们还提出了DROIDBENCH,这是一个开放的测试套件,用于评估专门针对Android应用程序的污染分析工具的有效性和准确性。正如我们通过使用SecuriBench Micro、DROIDBENCH和一组著名的Android测试应用程序进行的一组实验所示,FLOWDROID发现了非常高的数据泄漏比例,同时保持了低误报率。在DROIDBENCH上,FLOWDROID达到93%的召回率和86%的精度,大大优于商业工具IBM AppScan Source和Fortify SCA。FLOWDROID成功地从b谷歌Play的500个应用程序和VirusShare项目的约1000个恶意软件应用程序中发现了漏洞。
Today's smartphones are a ubiquitous source of private and confidential data. At the same time, smartphone users are plagued by carelessly programmed apps that leak important data by accident, and by malicious apps that exploit their given privileges to copy such data intentionally. While existing static taint-analysis approaches have the potential of detecting such data leaks ahead of time, all approaches for Android use a number of coarse-grain approximations that can yield high numbers of missed leaks and false alarms.In this work we thus present FLOWDROID, a novel and highly precise static taint analysis for Android applications. A precise model of Android's lifecycle allows the analysis to properly handle callbacks invoked by the Android framework, while context, flow, field and object-sensitivity allows the analysis to reduce the number of false alarms. Novel on-demand algorithms help FLOWDROID maintain high efficiency and precision at the same time.We also propose DROIDBENCH, an open test suite for evaluating the effectiveness and accuracy of taint-analysis tools specifically for Android apps. As we show through a set of experiments using SecuriBench Micro, DROIDBENCH, and a set of well-known Android test applications, FLOWDROID finds a very high fraction of data leaks while keeping the rate of false positives low. On DROIDBENCH, FLOWDROID achieves 93% recall and 86% precision, greatly outperforming the commercial tools IBM AppScan Source and Fortify SCA. FLOWDROID successfully finds leaks in a subset of 500 apps from Google Play and about 1,000 malware apps from the VirusShare project.