Analyzing the Analyzers: FlowDroid/IccTA, AmanDroid, and DroidSafe
Numerous static analysis techniques have recently been proposed for identifying information flows in mobile applications. These techniques are compared to each other, usually on a set of syntactic benchmarks. Yet, configurations used for such comparisons are rarely described. Our experience also shows that tools are often compared under different setup, rendering the comparisons irreproducible and largely inaccurate. In this paper, we provide a large, controlled, and independent comparison of the three most prominent static analysis tools: FLOWDROID combined with ICCTA, AMANDROID, and DROIDSAFE. We evaluate all tools under the same configuration parameters and on the same set of benchmark applications. We compare the results of our analysis to the results reported in previous studies, identify main reasons for inaccuracy in existing tools, and provide suggestions for future research.
Tue 17 JulDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
09:00 - 10:30 | |||
09:00 20mTalk | Automatically Translating Bug Reports into Test Cases for Mobile Apps ISSTA Technical Papers Mattia Fazzini Georgia Institute of Technology, Martin Prammer Georgia Institute of Technology, Marcelo d'Amorim Federal University of Pernambuco, Alessandro Orso Georgia Tech | ||
09:20 20mTalk | CiD: Automating the Detection of API-related Compatibility Issues in Android Apps ISSTA Technical Papers Li Li Monash University, Australia, Tegawendé F. Bissyandé University of Luxembourg, Luxembourg, Haoyu Wang , Jacques Klein University of Luxembourg, SnT | ||
09:40 20mTalk | Test Migration for Efficient Large-Scale Assessment of Mobile App Coding Assignments ISSTA Technical Papers | ||
10:00 20mTalk | Analyzing the Analyzers: FlowDroid/IccTA, AmanDroid, and DroidSafe ISSTA Technical Papers | ||
10:20 10m | Q&A in groups ISSTA Technical Papers |