中文版 | English
题名

Automated Third-Party Library Detection for Android Applications: Are We There Yet?

作者
DOI
发表日期
2020-09-01
ISSN
1938-4300
ISBN
978-1-7281-7281-1
会议录名称
页码
919-930
会议日期
21-25 Sept. 2020
会议地点
Melbourne, VIC, Australia
摘要
Third-party libraries (TPLs) have become a significant part of the Android ecosystem. Developers can employ various TPLs with different functionalities to facilitate their app development. Unfortunately, the popularity of TPLs also brings new challenges and even threats. TPLs may carry malicious or vulnerable code, which can infect popular apps to pose threats to mobile users. Besides, the code of third-party libraries could constitute noises in some downstream tasks (e.g., malware and repackaged app detection). Thus, researchers have developed various tools to identify TPLs. However, no existing work has studied these TPL detection tools in detail; different tools focus on different applications with performance differences, but little is known about them. To better understand existing TPL detection tools and dissect TPL detection techniques, we conduct a comprehensive empirical study to fill the gap by evaluating and comparing all publicly available TPL detection tools based on four criteria: effectiveness, efficiency, code obfuscation-resilience capability, and ease of use. We reveal their advantages and disadvantages based on a systematic and thorough empirical study. Furthermore, we also conduct a user study to evaluate the usability of each tool. The results showthat LibScout outperforms others regarding effectiveness, LibRadar takes less time than others and is also regarded as the most easy-to-use one, and LibPecker performs the best in defending against code obfuscation techniques. We further summarize the lessons learned from different perspectives, including users, tool implementation, and researchers. Besides, we enhance these open-sourced tools by fixing their limitations to improve their detection ability. We also build an extensible framework that integrates all existing available TPL detection tools, providing online service for the research community. We make publicly available the evaluation dataset and enhanced tools. We believe our work provides a clear picture of existing TPL detection techniques and also give a road-map for future directions.
关键词
学校署名
其他
语种
英语
相关链接[Scopus记录]
收录类别
WOS记录号
WOS:000651313500077
EI入藏号
20210309773368
EI主题词
Android (operating system) ; Automation ; Inspection equipment ; Libraries ; Malware
EI分类号
Computer Software, Data Handling and Applications:723 ; Data Processing and Image Processing:723.2 ; Automatic Control Principles and Applications:731 ; Libraries:903.4.1 ; Inspection:913.3.1
Scopus记录号
2-s2.0-85099211873
来源库
Scopus
全文链接https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9286020
引用统计
被引频次[WOS]:34
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/221934
专题南方科技大学
工学院_计算机科学与工程系
作者单位
1.The Hong Kong Polytechnic University,Hong Kong,Hong Kong
2.College of Cyber Science,Nankai Univerisity,China
3.Nanyang Technological University,Singapore,Singapore
4.Monash University,Australia
5.College of Intelligence and Computing,Tianjin University,China
6.Beijing University of Posts and Telecommunications,China
7.Southern University of Science and Technology,China
推荐引用方式
GB/T 7714
Zhan,Xian,Fan,Lingling,Liu,Tianming,et al. Automated Third-Party Library Detection for Android Applications: Are We There Yet?[C],2020:919-930.
条目包含的文件
条目无相关文件。
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Zhan,Xian]的文章
[Fan,Lingling]的文章
[Liu,Tianming]的文章
百度学术
百度学术中相似的文章
[Zhan,Xian]的文章
[Fan,Lingling]的文章
[Liu,Tianming]的文章
必应学术
必应学术中相似的文章
[Zhan,Xian]的文章
[Fan,Lingling]的文章
[Liu,Tianming]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。