A study of android application security 论文

2011引用 858
Advanced Malware Detection TechniquesDigital and Cyber ForensicsAdvanced Data Storage Technologies

详细信息

发表日期
2011-08-08
发表年份
2011

关键词

Advanced Malware Detection TechniquesDigital and Cyber ForensicsAdvanced Data Storage Technologies

摘要

The fluidity of application markets complicate smart-phone security. Although recent efforts have shed light on particular security issues, there remains little insight into broader security characteristics of smartphone ap-plications. This paper seeks to better understand smart-phone application security by studying 1,100 popular free Android applications. We introduce the ded decom-piler, which recovers Android application source code directly from its installation image. We design and exe-cute a horizontal study of smartphone applications based on static analysis of 21 million lines of recovered code. Our analysis uncovered pervasive use/misuse of person-al/phone identifiers, and deep penetration of advertising and analytics networks. However, we did not find ev-idence of malware or exploitable vulnerabilities in the studied applications. We conclude by considering the implications of these preliminary findings and offer di-rections for future analysis. 1