Detecting privacy leaks in Android Apps
Li Li, Alexandre Bartel, Jacques Klein, Yves Le Traon · 2014
Abstract. The number of Android apps have grown explosively in re-cent years and the number of apps leaking private data have also grown. It is necessary to make sure all the apps are not leaking private data before putting them to the app markets and thereby a privacy leaks detection tool is needed. We propose a static taint analysis approach which leverages the control-flow graph (CFG) of apps to detect privacy leaks among Android apps. We tackle three problems related to inter-component communication (ICC), lifecycle of components and callback mechanism making the CFG imprecision. To bridge this gap, we ex-plicitly connect the discontinuities of the CFG to provide a precise CFG. Based on the precise CFG, we aim at providing a taint analysis approach to detect intra-component privacy leaks, inter-component privacy leaks and also inter-app privacy leaks.