Systematic Mutation-Based Evaluation of the Soundness of Security-Focused Android Static Analysis Techniques

Systematic Mutation-Based Evaluation of the Soundness of Security-Focused Android Static Analysis Techniques
复制标题

DOI:
10.1145/3439802
复制
发表时间:
2021-02
期刊:
ACM Transactions on Privacy and Security (TOPS)
影响因子:
--
通讯作者:
Amit Seal Ami;Kaushal Kafle;Kevin Moran;Adwait Nadkarni;D. Poshyvanyk
Amit Seal Ami;Kaushal Kafle;Kevin Moran;Adwait Nadkarni;D. Poshyvanyk
中科院分区:
其他
文献类型:
--
作者:
Amit Seal Ami;Kaushal Kafle;Kevin Moran;Adwait Nadkarni;D. Poshyvanyk

文献摘要

相似文献

在过去的十年中,移动应用安全一直是安全研究的一个主要领域。针对恶意、好奇或易受攻击的应用程序,已经提出了许多应用程序分析工具。然而,现有的工具,特别是静态分析工具,以分析的准确性和性能为代价,因此是合理的。不幸的是,这些工具的设计中具体不合理的选择或缺陷通常不为人所知或没有很好的文档记录,导致研究人员、开发人员和用户错误地信任。本文描述了基于突变的健壮性评估(μSE)框架,该框架系统地评估安卓静态分析工具,以发现、记录和修复缺陷,并利用良好的突变分析实践。我们实现了μSE,并将其应用到一组著名的安卓静态分析工具中,这些工具可以检测应用程序中的私人数据泄漏。在之前进行的一项研究中,我们使用μSE在FlowDroid中发现了13个以前没有记录的缺陷,FlowDroid是最著名的安卓应用程序数据泄漏检测器之一。此外,我们还发现,缺陷还会传播到基于FlowDroid或其组件的设计或实现的其他工具。本文极大地扩展了我们的μSE框架,并在2020年的研究中提供了对另外两个主要工具的新的深入分析;我们发现了12个新的未记录的缺陷,并演示了所有25个缺陷都是在多个工具中发现的,而不考虑这些工具之间的任何继承关系。我们的结果激发了对健全工具中不合理选择的系统发现和记录的需要,并展示了利用突变测试实现这一目标的机会。
Mobile application security has been a major area of focus for security research over the course of the last decade. Numerous application analysis tools have been proposed in response to malicious, curious, or vulnerable apps. However, existing tools, and specifically, static analysis tools, trade soundness of the analysis for precision and performance and are hence soundy. Unfortunately, the specific unsound choices or flaws in the design of these tools is often not known or well documented, leading to misplaced confidence among researchers, developers, and users. This article describes the Mutation-Based Soundness Evaluation (μSE) framework, which systematically evaluates Android static analysis tools to discover, document, and fix flaws, by leveraging the well-founded practice of mutation analysis. We implemented μSE and applied it to a set of prominent Android static analysis tools that detect private data leaks in apps. In a study conducted previously, we used μSE to discover 13 previously undocumented flaws in FlowDroid, one of the most prominent data leak detectors for Android apps. Moreover, we discovered that flaws also propagated to other tools that build upon the design or implementation of FlowDroid or its components. This article substantially extends our μSE framework and offers a new in-depth analysis of two more major tools in our 2020 study; we find 12 new, undocumented flaws and demonstrate that all 25 flaws are found in more than one tool, regardless of any inheritance-relation among the tools. Our results motivate the need for systematic discovery and documentation of unsound choices in soundy tools and demonstrate the opportunities in leveraging mutation testing in achieving this goal.