Article (Scientific journals)
Dynamic Security Analysis on Android: A Systematic Literature Review
Sutter, Thomas; Kehrer, Timo; Rennhard, Marc et al.
2024In IEEE Access, 12, p. 57261 - 57287
Peer Reviewed verified by ORBi
 

Files


Full Text
Dynamic_Security_Analysis_on_Android_A_Systematic_Literature_Review.pdf
Author postprint (3.58 MB) Creative Commons License - Attribution
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Android; dynamic analysis; fuzzing; instrumentation; machine learning; monitoring; security; software testing; tracing; vulnerabilities; Code; Dynamics analysis; Fuzzing; Instrumentation; Machine-learning; Operating system; Security; Software testings; Systematic; Tracing; Vulnerability; Computer Science (all); Materials Science (all); Engineering (all)
Abstract :
[en] Dynamic analysis is a technique that is used to fully understand the internals of a system at runtime. On Android, dynamic security analysis involves real-time assessment and active adaptation of an app's behaviour, and is used for various tasks, including network monitoring, system-call tracing, and taint analysis. The research on dynamic analysis has made significant progress in the past years. However, to the best of our knowledge, there is a lack in secondary studies that analyse the novel ideas and common limitations of current security research. The main aim of this work is to understand dynamic security analysis research on Android to present the current state of knowledge, highlight research gaps, and provide insights into the existing body of work in a structured and systematic manner. We conduct a systematic literature review (SLR) on dynamic security analysis for Android. The systematic review establishes a taxonomy, defines a classification scheme, and explores the impact of advanced Android app testing tools on security solutions in software engineering and security research. The study's key findings centre on tool usage, research objectives, constraints, and trends. Instrumentation and network monitoring tools play a crucial role, with research goals focused on app security, privacy, malware detection, and software testing automation. Identified limitations include code coverage constraints, security-related analysis obstacles, app selection adequacy, and non-deterministic behaviour. Our study results deepen the understanding of dynamic analysis in Android security research by an in-depth review of 43 publications. The study highlights recurring limitations with automated testing tools and concerns about detecting or obstructing dynamic analysis.
Disciplines :
Computer science
Author, co-author :
Sutter, Thomas ;  Institute of Computer Science, University of Bern, Bern, Switzerland ; Institute of Computer Science, Zürich University of Applied Sciences, Winterthur, Switzerland
Kehrer, Timo ;  Institute of Computer Science, University of Bern, Bern, Switzerland
Rennhard, Marc ;  Institute of Computer Science, Zürich University of Applied Sciences, Winterthur, Switzerland
Tellenbach, Bernhard ;  Cyber-Defense Campus, Armasuisse Science and Technology, Zürich, Switzerland
KLEIN, Jacques  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
External co-authors :
yes
Language :
English
Title :
Dynamic Security Analysis on Android: A Systematic Literature Review
Publication date :
17 April 2024
Journal title :
IEEE Access
ISSN :
2169-3536
Publisher :
Institute of Electrical and Electronics Engineers Inc.
Volume :
12
Pages :
57261 - 57287
Peer reviewed :
Peer Reviewed verified by ORBi
Funders :
Armasuisse Science and Technology, Cyber-Defense Campus, Switzerland, through the Research Program Cyberspace by the Project Security Analysis of Firmware of Mobile Devices
Available on ORBilu :
since 15 November 2024

Statistics


Number of views
90 (1 by Unilu)
Number of downloads
702 (7 by Unilu)

Scopus citations®
 
15
Scopus citations®
without self-citations
15
OpenCitations
 
0
OpenAlex citations
 
19
WoS citations
 
9

Bibliography


Similar publications



Contact ORBilu