A study of android application security 论文
详细信息
- 发表日期
- 2011-08-08
- 发表年份
- 2011
关键词
摘要
The fluidity of application markets complicate smart-phone security. Although recent efforts have shed light on particular security issues, there remains little insight into broader security characteristics of smartphone ap-plications. This paper seeks to better understand smart-phone application security by studying 1,100 popular free Android applications. We introduce the ded decom-piler, which recovers Android application source code directly from its installation image. We design and exe-cute a horizontal study of smartphone applications based on static analysis of 21 million lines of recovered code. Our analysis uncovered pervasive use/misuse of person-al/phone identifiers, and deep penetration of advertising and analytics networks. However, we did not find ev-idence of malware or exploitable vulnerabilities in the studied applications. We conclude by considering the implications of these preliminary findings and offer di-rections for future analysis. 1