A Framework for Static Detection of Privacy Leaks in Android Applications

The authors report on applying techniques for static information flow analysis to identify privacy leaks in Android applications. They have crafted a framework which checks with the help of a security type system whether the Dalvik bytecode implementation of an Android app conforms to a given privacy policy. They have carefully analyzed the Android API for possible sources and sinks of private data and identified exemplary privacy policies based on this. They explain the applicability of their framework on two case studies showing detection of privacy leaks.

Provided by: Association for Computing Machinery Topic: Security Date Added: Dec 2011 Format: PDF

Find By Topic