Paper published in a book (Scientific congresses, symposiums and conference proceedings)
IccTA: Detecting Inter-Component Privacy Leaks in Android Apps
Li, Li; BARTEL, Alexandre; Bissyande, Tegawendé François D Assise et al.
2015In 2015 IEEE/ACM 37th IEEE International Conference on Software Engineering (ICSE 2015)
Peer reviewed
 

Files


Full Text
li-iccta-preprint.pdf
Author preprint (210.7 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Abstract :
[en] Shake Them All is a popular "Wallpaper" application exceeding millions of downloads on Google Play. At installation, this application is given permission to (1) access the Internet (for updating wallpapers) and (2) use the device microphone (to change background following noise changes). With these permissions, the application could silently record user conversations and upload them remotely. To give more confidence about how Shake Them All actually processes what it records, it is necessary to build a precise analysis tool that tracks the flow of any sensitive data from its source point to any sink, especially if those are in different components. Since Android applications may leak private data carelessly or maliciously, we propose IccTA, a static taint analyzer to detect privacy leaks among components in Android applications. IccTA goes beyond state-of-the-art approaches by supporting inter-component detection. By propagating context information among components, IccTA improves the precision of the analysis. IccTA outperforms existing tools on two benchmarks for ICC-leak detectors: DroidBench and ICC-Bench. Moreover, our approach detects 534 ICC leaks in 108 apps from MalGenome and 2,395 ICC leaks in 337 apps in a set of 15,000 Google Play apps.
Disciplines :
Computer science
Author, co-author :
Li, Li ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BARTEL, Alexandre ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Bissyande, Tegawendé François D Assise  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Klein, Jacques ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Le Traon, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Arzt, Steven;  TU Darmstadt
Rasthofer, Siegfried;  TU Darmstadt
Bodden, Eric;  TU Darmstadt
Octeau, Damien;  Pennsylvania State University
McDaniel, Patrick;  Pennsylvania State University
Language :
English
Title :
IccTA: Detecting Inter-Component Privacy Leaks in Android Apps
Publication date :
2015
Event name :
2015 IEEE/ACM 37th IEEE International Conference on Software Engineering (ICSE 2015)
Event date :
from 16-05-2015 to 24-05-2015
Audience :
International
Main work title :
2015 IEEE/ACM 37th IEEE International Conference on Software Engineering (ICSE 2015)
Peer reviewed :
Peer reviewed
Funders :
FNR - Fonds National de la Recherche [LU]
Available on ORBilu :
since 16 February 2015

Statistics


Number of views
1179 (41 by Unilu)
Number of downloads
4580 (72 by Unilu)

Scopus citations®
 
500
Scopus citations®
without self-citations
422

Bibliography


Similar publications



Contact ORBilu