Analyzing the Analyzers: FlowDroid/IccTA, AmanDroid, and DroidSafeISSTA paper
Numerous static analysis techniques have recently been proposed for identifying information flows in mobile applications. These techniques are compared to each other, usually on a set of syntactic benchmarks. Yet, configurations used for such comparisons are rarely described. Our experience also shows that tools are often compared under different setup, rendering the comparisons irreproducible and largely inaccurate. In this paper, we provide a large, controlled, and independent comparison of the three most prominent static analysis tools: FLOWDROID combined with ICCTA, AMANDROID, and DROIDSAFE. We evaluate all tools under the same configuration parameters and on the same set of benchmark applications. We compare the results of our analysis to the results reported in previous studies, identify main reasons for inaccuracy in existing tools, and provide suggestions for future research.