Discovering and understanding android sensor usage behaviors with data flow analysis

Citation data:

World Wide Web, ISSN: 1386-145X, Vol: 21, Issue: 1, Page: 105-126

Publication Year:
2018
Usage 24
Abstract Views 14
Downloads 10
Captures 4
Readers 4
Citations 3
Citation Indexes 3
Repository URL:
http://hdl.handle.net/10754/623822
DOI:
10.1007/s11280-017-0446-0
Author(s):
Liu, Xing; Liu, Jiqiang; Wang, Wei; He, Yongzhong; Zhang, Xiangliang
Publisher(s):
Springer Nature
Tags:
Computer Science; Android system; Sensor usage; Data-flow analysis; Clustering
article description
Today’s Android-powered smartphones have various embedded sensors that measure the acceleration, orientation, light and other environmental conditions. Many functions in the third-party applications (apps) need to use these sensors. However, embedded sensors may lead to security issues, as the third-party apps can read data from these sensors without claiming any permissions. It has been proven that embedded sensors can be exploited by well designed malicious apps, resulting in leaking users’ privacy. In this work, we are motivated to provide an overview of sensor usage patterns in current apps by investigating what, why and how embedded sensors are used in the apps collected from both a Chinese app. market called “AppChina” and the official market called “Google Play”. To fulfill this goal, We develop a tool called “SDFDroid” to identify the used sensors’ types and to generate the sensor data propagation graphs in each app. We then cluster the apps to find out their sensor usage patterns based on their sensor data propagation graphs. We apply our method on 22,010 apps collected from AppChina and 7,601 apps from Google Play. Extensive experiments are conducted and the experimental results show that most apps implement their sensor related functions by using the third-party libraries. We further study the sensor usage behaviors in the third-party libraries. Our results show that the accelerometer is the most frequently used sensor. Though many third-party libraries use no more than four types of sensors, there are still some third-party libraries registering all the types of sensors recklessly. These results call for more attentions on better regulating the sensor usage in Android apps.