droid: Assessment and Evaluation of Android Application Analysis Tools

作者:Reaves Bradley*; Bowers Jasmine; Gorski Sigmund Albert III; Anise Olabode; Bobhate Rahul; Cho Raymond; Das Hiranava; Hussain Sharique; Karachiwala Hamza; Scaife Nolen; Wright Byron; Butler Kevin; Enck William; Traynor Patrick
来源:ACM Computing Surveys, 2016, 49(3): 55.
DOI:10.1145/2996358

摘要

The security research community has invested significant effort in improving the security of Android applications over the past half decade. This effort has addressed a wide range of problems and resulted in the creation of many tools for application analysis. In this article, we perform the first systematization of Android security research that analyzes applications, characterizing the work published in more than 17 top venues since 2010. We categorize each paper by the types of problems they solve, highlight areas that have received the most attention, and note whether tools were ever publicly released for each effort. Of the released tools, we then evaluate a representative sample to determine how well application developers can apply the results of our community's efforts to improve their products. We find not only that significant work remains to be done in terms of research coverage but also that the tools suffer from significant issues ranging from lack of maintenance to the inability to produce functional output for applications with known vulnerabilities. We close by offering suggestions on how the community can more successfully move forward.

  • 出版日期2016-12