• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Model Generation for Java Frameworks
 
  • Details
  • Full
Options
2023
Conference Paper
Title

Model Generation for Java Frameworks

Abstract
Modern applications often rely on rich frameworks to provide functionality. Android, for instance, handles many aspects of building a mobile app. But these frameworks also have costs. Given the importance of application security and tools to ensure it, one major cost is that framework complicate tools based on static analysis: (1) They hurt analysis quality by including large amounts of complex, dynamic, and native library code. (2) Frameworks like Android become the main program, making whole program analysis of the app problematic.Mechanisms such as Averroes have been developed to handle unknown library code for Java, and have proven effective for some analyses. However, they have two main limitations in the context of our complications: (1) They do not provide the precision required for security analysis. (2) They assume a main program, which is not the case for frameworks. To address this, we present GenCG, which extends Averroes to support taint analysis for Android and Spring. Evaluation with real-world Android applications shows that call graphs using the models generated by GenCG cover significantly more code of the app, improves recall of a client security analysis, and, at the same time, does not introduce more false positives.
Author(s)
Luo, Linghui
Piskachev, Goran
Krishnamurthy, Ranjith
Fraunhofer-Institut für Entwurfstechnik Mechatronik IEM  
Dolby, Julian
Bodden, Eric  
Fraunhofer-Institut für Entwurfstechnik Mechatronik IEM  
Schäf, Martin
Mainwork
IEEE 16th International Conference on Software Testing, Verification and Validation, ICST 2023. Proceedings  
Conference
International Conference on Software Testing, Verification and Validation 2023  
DOI
10.1109/ICST57152.2023.00024
Language
English
Fraunhofer-Institut für Entwurfstechnik Mechatronik IEM  
Keyword(s)
  • call graph

  • framework modeling

  • static analysis

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024