In this talk, we will discuss three popular static analysis tools for identifying information flows in mobile applications: FlowDroid combined with IccTA, AmanDroid, and DroidSafe. These tools are often compared with each other, yet, our experience shows that they are compared under different setup, rendering the comparisons largely inaccurate. To mitigate this problem, we performed a large, controlled, and independent comparison of the the tools, using common configuration setup and on the same set of benchmark applications. We observed that we cannot reproduce most of the results reported in earlier studies. We discuss reasons for such discrepancy, identify main causes of inaccuracy in existing tools, and provide suggestions for future research.
Program Display Configuration
Fri 20 Jul
Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Viennachange