Abstract
Insecure applications (apps) are increasingly used to steal users’ location information for illegal purposes, which has aroused great concern in recent years. Although the existing methods, i.e., static and dynamic taint analysis, have shown great merit for identifying such apps, which mainly rely on statically analyzing source code or dynamically monitoring the location data flow, identification accuracy is still under research, since the analysis results contain a certain false positive or true negative rate. In order to improve the accuracy and reduce the misjudging rate in the process of vetting suspicious apps, this paper proposes SAMLDroid, a combined method of static code analysis and machine learning for identifying Android apps with location privacy leakage, which can effectively improve the identification rate compared with existing methods. SAMLDroid first uses static analysis to scrutinize source code to investigate apps with location acquiring intentions. Then it exploits a well-trained classifier and integrates an app’s multiple features to dynamically analyze the pattern and deliver the final verdict about the app’s property. Finally, it is proved by conducting experiments, that the accuracy rate of SAMLDroid is up to 98.4%, which is nearly 20% higher than Apparecium.
Funder
National Natural Science Foundation
National Key Research and Development Program of China
Subject
General Physics and Astronomy
Reference30 articles.
1. Blind evaluation of nearest neighbor queries using space transformation to preserve location privacy;Khoshgozaran,2007
2. k-ANONYMITY: A MODEL FOR PROTECTING PRIVACY
3. Handbook of Research on Modern Cryptographic Solutions for Computer and Cyber Security,2016
Cited by
7 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Android malware analysis and detection: A systematic review;Expert Systems;2023-10-25
2. Cryptocurrency Security Study based on Static Taint Analysis;Highlights in Science, Engineering and Technology;2023-04-01
3. A taint analysis framework applied to android applications in the packed state;China Communications;2023-03
4. Review on the Static Analysis Techniques Used for Privacy Leakage Detection in Android Apps;Lecture Notes in Electrical Engineering;2023
5. ML-based Privacy Leakage Behavior Detection in Android Apps at Scale;2022 IEEE Smartworld, Ubiquitous Intelligence & Computing, Scalable Computing & Communications, Digital Twin, Privacy Computing, Metaverse, Autonomous & Trusted Vehicles (SmartWorld/UIC/ScalCom/DigitalTwin/PriComp/Meta);2022-12