A Framework for Static Detection of Privacy Leaks in Android Applications

Free registration required

Executive Summary

The authors report on applying techniques for static information flow analysis to identify privacy leaks in Android applications. They have crafted a framework which checks with the help of a security type system whether the Dalvik bytecode implementation of an Android app conforms to a given privacy policy. They have carefully analyzed the Android API for possible sources and sinks of private data and identified exemplary privacy policies based on this. They explain the applicability of their framework on two case studies showing detection of privacy leaks.

  • Format: PDF
  • Size: 317.61 KB