Static analysis of android apps: A systematic literature review

被引:178
|
作者
Li, Li [1 ]
Bissyande, Tegawende F. [1 ]
Papadakis, Mike [1 ]
Rasthofer, Siegfried [2 ]
Bartel, Alexandre [1 ,4 ]
Octeau, Damien [3 ]
Klein, Jacques [1 ]
Traon, Le [1 ]
机构
[1] Univ Luxembourg, Interdisciplinary Ctr Secur, Reliabil & Trust SnT, Luxembourg, Luxembourg
[2] Fraunhofer SIT, Darmstadt, Germany
[3] Univ Wisconsin, Dept Comp Sci, 1210 W Dayton St, Madison, WI 53706 USA
[4] Tech Univ Darmstadt, Darmstadt, Germany
关键词
CODE ANALYSIS; SECURITY; PROGRAMS; FLOW;
D O I
10.1016/j.infsof.2017.04.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: Static analysis exploits techniques that parse program source code or bytecode, often traversing program paths to check some program properties. Static analysis approaches have been proposed for different tasks, including for assessing the security of Android apps, detecting app clones, automating test cases generation, or for uncovering non-functional issues related to performance or energy. The literature thus has proposed a large body of works, each of which attempts to tackle one or more of the several challenges that program analyzers face when dealing with Android apps. Objective: We aim to provide a clear view of the state-of-the-art works that statically analyze Android apps, from which we highlight the trends of static analysis approaches, pinpoint where the focus has been put, and enumerate the key aspects where future researches are still needed. Method: We have performed a systematic literature review (SLR) which involves studying 124 research papers published in software engineering, programming languages and security venues in the last 5 years (January 2011-December 2015). This review is performed mainly in five dimensions: problems targeted by the approach, fundamental techniques used by authors, static analysis sensitivities considered, android characteristics taken into account and the scale of evaluation performed. Results: Our in-depth examination has led to several key findings: 1) Static analysis is largely performed to uncover security and privacy issues; 2) The Soot framework and the Jimple intermediate representation are the most adopted basic support tool and format, respectively; 3) Taint analysis remains the most applied technique in research approaches; 4) Most approaches support several analysis sensitivities, but very few approaches consider path-sensitivity; 5) There is no single work that has been proposed to tackle all challenges of static analysis that are related to Android programming; and 6) Only a small portion of state-of-the-art works have made their artifacts publicly available. Conclusion: The research community is still facing a number of challenges for building approaches that are aware altogether of implicit-Flows, dynamic code loading features, reflective calls, native code and multi-threading, in order to implement sound and highly precise static analyzers. (C) 2017 Elsevier B.V. All rights reserved.
引用
收藏
页码:67 / 95
页数:29
相关论文
共 50 条
  • [1] Automated Testing of Android Apps: A Systematic Literature Review
    Kong, Pingfan
    Li, Li
    Gao, Jun
    Liu, Kui
    Bissyande, Tegawende F.
    Klein, Jacques
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2019, 68 (01) : 45 - 66
  • [2] A Systematic Literature Review of Android Malware Detection Using Static Analysis
    Pan, Ya
    Ge, Xiuting
    Fang, Chunrong
    Fan, Yong
    [J]. IEEE ACCESS, 2020, 8 : 116363 - 116379
  • [3] Kunai: A static analysis framework for Android apps
    Blazquez, Eduardo
    Tapiador, Juan
    [J]. SOFTWAREX, 2023, 22
  • [4] Research on Third-Party Libraries in Android Apps: A Taxonomy and Systematic Literature Review
    Zhan, Xian
    Liu, Tianming
    Fan, Lingling
    Li, Li
    Chen, Sen
    Luo, Xiapu
    Liu, Yang
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (10) : 4181 - 4213
  • [5] Reflection-Aware Static Analysis of Android Apps
    Li, Li
    Bissyande, Tegawende F.
    Octeauo, Damien
    Klein, Jacques
    [J]. 2016 31ST IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE), 2016, : 756 - 761
  • [6] Malware Detection in Android Apps Using Static Analysis
    Paul, Nishtha
    Bhatt, Arpita Jadhav
    Rizvi, Sakeena
    Shubhangi
    [J]. Journal of Cases on Information Technology, 2021, 24 (03)
  • [7] Android Apps:Static Analysis Based on Permission Classification
    Zhenjiang Dong
    Hui Ye
    Yan Wu
    Shaoyin Cheng
    Fan Jiang
    [J]. ZTE Communications, 2013, 11 (01) : 62 - 66
  • [8] Dynamic Security Analysis on Android: A Systematic Literature Review
    Sutter, Thomas
    Kehrer, Timo
    Rennhard, Marc
    Tellenbach, Bernhard
    Klein, Jacques
    [J]. IEEE ACCESS, 2024, 12 : 57261 - 57287
  • [9] Detecting Energy Bugs in Android Apps Using Static Analysis
    Jiang, Hao
    Yang, Hongli
    Qin, Shengchao
    Su, Zhendong
    Zhang, Jian
    Yan, Jun
    [J]. FORMAL METHODS AND SOFTWARE ENGINEERING, ICFEM 2017, 2017, 10610 : 192 - 208
  • [10] Android Multitasking Mechanism: Formal Semantics and Static Analysis of Apps
    He, Jinlong
    Chen, Taolue
    Wang, Ping
    Wu, Zhilin
    Yan, Jun
    [J]. PROGRAMMING LANGUAGES AND SYSTEMS, APLAS 2019, 2019, 11893 : 291 - 312