Where Are We Looking? Understanding Android Static Analysis Techniques

Suzanna Schmeelk · 2019

Static analysis is a traditional technique for software transformation and analysis. It has also become a means to detect cyber security vulnerabilities and malware and recently has been extended to the mobile-computing arena for security-related analyses. This paper examines 50 security papers that are published in top conferences, journals and technical reports, and characterizes the current research. The papers were selected based their high citings by other top research or because they introduced either a novel analysis technique or a novel security issue analysis. Our research systematically constructs a static analysis landscape by charting and characterizing analysis strengths and limitations in both accuracy and security threats. For completeness and to aid the community by providing a coverage map, we have connected technique motivations found to Mitre's attack taxonomy and Mitre's vulnerability taxonomy. Our Findings include identifying vulnerabilities which are not being systematically researched.

Read the paper · More papers on PaperTik