A Framework for Static Detection of Privacy Leaks in Android Applications

Download Now Date Added: Dec 2011
Format: PDF

The authors report on applying techniques for static information flow analysis to identify privacy leaks in Android applications. They have crafted a framework which checks with the help of a security type system whether the Dalvik bytecode implementation of an Android app conforms to a given privacy policy. They have carefully analyzed the Android API for possible sources and sinks of private data and identified exemplary privacy policies based on this. They explain the applicability of their framework on two case studies showing detection of privacy leaks.