• Home
  • Search
  • NLEU: A Semantic-based Taint Analysis for Vetting Apps in Android
  • Cite Icon6
  • https://doi.org/10.1109/nana53684.2021.00063Copy DOI Icon

NLEU: A Semantic-based Taint Analysis for Vetting Apps in Android

  • Oct 1, 2021
  • Yuanqing Liu +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Due to the widespread of Android apps in our daily life, vulnerable or malicious apps have become two major threats on clients’ privacy. Taint analysis is one of the most widely used approach for detecting information leakage by tracking sensitive flows through the apps in accord with specific taint propagation rules and predefined sensitive sources and sinks. However, most existing static taint analysis tools, including FlowDroid, IccTA, etc., neglect the semantics of detected flows, especially for conditional branch in apps, which may cause a precision loss in practical environment. In this paper, we propose NLEU, a semantic-based taint analysis approach to improve the precision of traditional flow tracking techniques, which introduce a new dimension of information, i.e., the program’s semantics, for vetting Android apps. At the same time, NLEU can eliminate the insensitive flows of flow tracking techniques. The NLP techniques are adopted to extract the program semantics from codes and their comments. Through the experiments and evaluations, the result show that NLEU can improve the overall performance effectively compared with the traditional tools.

Similar Papers
  • Conference Article
  • Citations2

Static Code Analysis Tool for Laravel Framework Based Web Application

  • Nov 03, 2021
  • Ranindya Paramitha +1
  • Research Article
  • Citations107

MalPat: Mining Patterns of Malicious and Benign Android Apps via Permission-Related APIs

  • Mar 01, 2018
  • IEEE Transactions on Reliability
  • Guanhong Tao +3
  • Conference Article
  • Citations7

ActivityHijacker: Hijacking the Android Activity Component for Sensitive Data

  • Aug 01, 2016
  • Zhaoguo Wang +4
  • Research Article
  • Citations1

ARAP: Demystifying Anti Runtime Analysis Code in Android Apps

  • Jan 01, 2025
  • IEEE Transactions on Software Engineering
  • Dewen Suo +5
  • Research Article

Probing the Depths of the Nucleus

  • Oct 11, 1969
  • Science News
  • Dietrick E Thomsen
  • Research Article
  • Citations140

Gold on paper–paper platform for Au-nanoprobe TB detection

  • Jan 01, 2012
  • Lab on a Chip
  • Bruno Veigas +9
  • Conference Article
  • Citations19

Quantitative Material Reconstruction in CT with Spectroscopic X-ray Pixel Detectors -- a Simulation Study

  • Jan 01, 2006
  • M Firsching +3
  • PDF
  • Research Article
  • Citations4

A Multiclass Detection System for Android Malicious Apps Based on Color Image Features

  • Dec 14, 2020
  • Wireless Communications and Mobile Computing
  • Hua Zhang +7
  • Conference Article
  • Citations20

Scaling static taint analysis to industrial SOA applications: a case study at Alibaba

  • Nov 08, 2020
  • Jie Wang +5
  • Conference Article
  • Citations1

NnTaint: An Optimized Dynamic Taint Analysis Method Based on Neural Network

  • Aug 23, 2022
  • Yuming Zhu +1
  • Research Article

The Propagation Strategy Model of Taint Analysis

  • Apr 01, 2020
  • Journal of Physics: Conference Series
  • Yuzhu Ren +2
  • Research Article
  • Citations10

F4F

  • Oct 18, 2011
  • ACM SIGPLAN Notices
  • Manu Sridharan +5
  • Research Article
  • Citations156

Ethereum Smart Contract Analysis Tools: A Systematic Review

  • Jan 01, 2022
  • IEEE Access
  • Satpal Singh Kushwaha +4
  • Conference Article
  • Citations21

Explaining Static Analysis - A Perspective

  • Nov 01, 2019
  • Marcus Nachtigall +2
  • Conference Article
  • Citations2

Static Analysis Warnings and Automatic Fixing: A Replication for C# Projects

  • Mar 01, 2022
  • Martin Odermatt +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.