arrow
Return

A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android

delete2024-12-01
delete0
PRE
AI
J
Jingyun Zhu
K
Kaixuan Li
S
Sen Chen *
L
Lingling Fan
W
Wang, Junjie
X
Xiaofei Xie
DOI:10.1109/TSE.2024.3488041delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
To identify security vulnerabilities in Android applications, numerous static application security testing (SAST) tools have been proposed. However, it poses significant challenges to assess their overall performance on diverse vulnerability types. The task is non-trivial and poses considerable challenges. Firstly, the absence of a unified evaluation platform for defining and describing tools' supported vulnerability types, coupled with the lack of normalization for the intricate and varied reports generated by different tools, significantly adds to the complexity. Secondly, there is a scarcity of adequate benchmarks, particularly those derived from real-world scenarios. To address these problems, we are the first to propose a unified platform named VulsTotal, supporting various vulnerability types, enabling comprehensive and versatile analysis across diverse SAST tools. Specifically, we begin by meticulously selecting 11 free and open-sourced SAST tools from a pool of 97 existing options, adhering to clearly defined criteria. After that, we invest significant efforts in comprehending the detection rules of each tool, subsequently unifying 67 general/common vulnerability types for Android SAST tools. We also redefine and implement a standardized reporting format, ensuring uniformity in presenting results across all tools. Additionally, to mitigate the problem of benchmarks, we conducted a manual analysis of huge amounts of CVEs to construct a new CVE-based benchmark based on our comprehension of Android app vulnerabilities. Leveraging the evaluation platform, which integrates both existing synthetic benchmarks and newly constructed CVE-based benchmarks from this study, we conducted a comprehensive analysis to evaluate and compare these selected tools from various perspectives, such as general vulnerability type coverage, type consistency, tool effectiveness, and time performance. Our observations yielded impressive findings, like the technical reasons underlying the performance, which provide insights for different stakeholders.
Keywords:
SAST
vulnerability
Android app
SAST
vulnerability
Android app

Journal

IEEE Transactions on Software Engineering cover
IEEE Transactions on Software Engineering
IF:
5.6
Papers:
2.8K
Citations:
1.1W

Organization

E
east china normal university
Scholars:
3.0W
Papers: 2.1W
Citations: 25
T
tianjin university
Scholars:
7.9W
Papers: 5.7W
Citations: 88
S
Singapore Management University
Scholars:
1.5K
Papers: 2.5K
Citations: 3.5K
N
nankai university
Scholars:
4.7W
Papers: 3.2W
Citations: 74
researcher View more organizations