<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>JoDroid: Adding Android Support to a Static Information Flow Control Tool</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Martin Mohr</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>J u¨rgen Graf</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Martin Hecker</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Karlsruhe Institute of Technology</institution>
        </aff>
      </contrib-group>
      <fpage>140</fpage>
      <lpage>145</lpage>
      <abstract>
        <p>We present our ongoing work on the extension of our PDG-based information flow control tool Joana to handle Android applications. We elaborate on the challenges posed by android applications, outline what we have already done and discuss what we intend to do in the future. In today's world, smartphones are becoming more and more important and contain lots of personal data which needs to be protected from unintended dissemination. Currently, the most widespread smartphone operating system is Android [1]. Android provides a permission-based mechanism to control what apps can do, but this mechanism is not su cient: The user can see which resources an app may access and which action it is allowed to perform, but he cannot see or control how the app uses these rights. A well-known technique called information flow control [2] can tackle this problem. It enables the user to specify how information is allowed to be used inside the app and in particular to specify certain unwanted information flows as forbidden. With information flow control we can guarantee the absence of such information leaks by proving the non-interference property for the given app. In [3], we describe Joana, a state-of-the-art information flow control analysis tool for Java bytecode, which leverages sophisticated static program analyses to construct a program dependence graph (PDG) and uses context-sensitive slicing [4] to verify non-interference. Currently, we are working on extending Joana to handle also Android apps. Among the challenges to be addressed to achieve this goal are (1) that although Android apps are developed in Java, they are not compiled to Java bytecode but to Android's own Dalvik bytecode, (2) that standard Java applications use a single entry point (main), but Android apps have large multitude of possible entry points which are triggered by the Android system throughout the execution of the app and (3) that Android apps employ message-passing to exchange data and start external apps' components, which requires to also analyse information flows between apps. These challenges are not specific to Android. For example, many GUI-based Java applications also have multiple entry points which handle user input. However, di erent frameworks require di erent models specifying how these entry-points are used and Joana currently has no general mechanism to specify such models. Similar considerations can be made for intents: intents are comparable to other message-passing mechanisms which are commonly found in client-server-applications but currently Joana does not provide a general mechanism which applies to a wide variety of message-passing mechanisms. We therefore consider our work on extending Joana to Android as a starting point to addressing these more general challenges. In this work, we present the work we have already done to address the challenges we just sketched. In section 2 we give a short overview of Android apps, in section 3 we discuss some basics of Joana's underlying technology, namely PDGs and slicing, in section 4 we outline how we address the above mentioned challenges and after a discussion of the related work in section 5, we conclude in section 6 by giving an outlook on future work. Submission to: 8. Arbeitstagung Programmiersprachen, Dresden, Germany, 18-Mar-2015, to appear at http://ceur-ws.org</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
    </sec>
    <sec id="sec-2">
      <title>Overview over Android applications</title>
      <p>
        In the following, we briefly discuss the architecture of Android applications. This overview is largely based on [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
Copyright c by the paper’s authors. Copying permitted for private and academic purposes.
      </p>
      <p>An Android application usually consists of multiple components which are loosely bound to each other. These components
can either be Activities, Broadcast Receivers, Services or Content Providers. We now give a quick summary of what these
components do and which roles they play.</p>
      <p>Activities: An activity is an application component that provides a screen with which users can interact in order to do
something. Each activity is given a window in which to draw its user interface.</p>
      <p>Broadcast Receivers: A broadcast receiver responds to system-wide broadcast announcements. Many broadcasts
originate from the system, but can also be initiated by arbitrary app components. Broadcast receivers do not display a
user interface. Typically, a broadcast receiver is just a ”gateway” to other components and is intended to do a very
minimal amount of work. For instance, it might initiate a service to perform some work based on the event.
Services: A service runs in the background to perform long-running operations or to perform work for remote processes.
It does not provide a user interface. Another component, such as an activity, can start the service and let it run or bind
to it in order to interact with it, using a special kind of inter-process communication.</p>
      <p>Content Providers: Content providers manage access to a structured set of data. They encapsulate the data, and provide
mechanisms for defining data security. Content providers are the standard interface that connects data in one process
with code running in another process.</p>
      <p>
        Android components use intents to exchange messages with each other. In particular, intents are used to start components.
Intents can be explicit or implicit. Explicit intents specify a receiver, whereas implicit intents leave it up to the Android
system and/or the user to resolve their receiver. Figure 1 (taken from [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]) shows how Android processes an implicit intent.
In the following, we explain some fundamentals of the technologies used by Joana, namely PDGs and slicing.
      </p>
      <p>PDG basics. A Program Dependence Graph (PDG) is a language-independent representation of a program. The nodes
of a PDG represent statements and expressions, while edges model the syntactic dependencies between them. There exist
di erent kinds of dependencies, among which the most important are data dependencies and control dependencies. Data
dependencies model explicit information flow: they occur whenever a statement uses a value produced by another statement.
Control dependencies arise when a statement or expression controls whether another statement is executed or not, and
hence model implicit flow. As an example, consider the code snippet and its corresponding PDG snippet in figure 2:
bTehcearuesiestahedlaattatedreupseensdtheencvyalbueetowfexenprtohdeuscteadtebmyetnhetsfionr mlienre. I1t aanlsdo icnonlitnaein2s cdoantatrdoledpe.p. x = 1
a control dependency between the if-statement in line 3 and the statements x = 1;
in lines 4 and 6 because whether line 4 or 6 is executed depends on the value y = 2x - 5; y = 2x - 5
of the if-expression in line 3. if (y &gt; 42) {
aSnliacliynsgis-buasseesdcoInntfeoxrtm-seantsioitniveFlsoliwcinCgo[n6t]r,oal.spPeDciGal-bfoarsmedoifngfroarpmharteioanchflaboiwl- } zels=e 1;{ y &gt; 42
ity: given a node n of the PDG, the backwards slice of n contains all nodes z = 2; z = 2 z = 1
from which n is reachable by a path in the PDG that respects calling-contexts.</p>
      <p>
        For sequential programs, it has been shown [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] that a node m not contained
1
2
3
4
5
6
7 }
Figure 2: A code snippet and the corresponding
part of its PDG
in the backwards slice of n cannot influence n, hence PDG-based slicing on sequential programs guarantees non-interference
[
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. It is also possible to construct and slice [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] PDGs for concurrent programs. However, in this context, additional kinds of
information flows may exist, e.g. probabilistic channels [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], so mere slicing is not enough to cover all possible information
flows between a source and a sink. A PDG- and slicing-based algorithm providing such a guarantee has recently been
developed and integrated into Joana [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
4
      </p>
    </sec>
    <sec id="sec-3">
      <title>Approach</title>
      <p>In this section, we explain how we address the challenges we mentioned in section 1.</p>
      <p>Dalvik Bytecode
create instructions
parse types and</p>
      <p>methods
Analysis options
entry points
life cycle model</p>
      <p>Class Hierarchy</p>
      <p>SSA IR
Cal-graph</p>
      <p>+
Points-to</p>
      <p>PDG
SDG</p>
      <p>Intraprocedural
Slicing</p>
      <p>IFC checker</p>
      <p>Interprocedural
WALA</p>
      <p>
        Joana
Dalvik front-end Figure 3 shows the general architecture of Joana. Joana is based on WALA [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], a program analysis
framework for Java bytecode. WALA provides a front-end which reads and parses the actual bytecode and basic program
analyses and transformations, such as an SSA-based intermediate representation, call graph construction and points-to
analysis. As can be seen in figure 3, the PDG builder of Joana only depends on WALA’s analysis results and hence is
decoupled from WALA’s front-end. As a consequence, we only needed to adapt WALA’s front end to be able to process
Android apps. For this, we integrated the WALA front end code of SCanDroid [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], a security analysis tool which is also
based on WALA. This was a first step to extend Joana to handle also Android apps.
      </p>
      <p>Lifecycle modelling. Standard Java applications have a single entry point and every execution of the application starts with
an invocation of this method. Clearly, this assumption is not met by Android apps: As we already mentioned, Android
apps have multiple callbacks, which may be triggered by the user or the Android system as a reaction to certain events.
However, the order and the way these callbacks are triggered is not arbitrary, but follows certain rules. More specifically, the
components of an Android app are driven by their lifecycles. The lifecycle of an activity can be seen in figure 4.</p>
      <p>It is not an option to run a separate analysis for each entry point, since there may be information flows which only occur
if multiple callbacks are executed in sequence. Listing 1 (adapted from [14]) presents an example.</p>
      <p>When onCreate() is executed, line 5 reads the IMEI of the phone and later, upon the invocation of onStart(), line 15
sends the IMEI to a server on the internet. However, such an information flow is not detected if onStart() and onCreate()
were each analysed in isolation, since neither calls the other but both are called by the Android framework.</p>
      <p>To also cover such flows, we synthesize an entry method which simulates the Android framework by invoking all
callbacks of the given app.</p>
      <p>In order to lose not too much precision, we take the lifecycles of the app’s components into account. Consider again
figure 4: When onCreate() is called, either the activity has just been launched, or the app’s process has been destroyed
and re-created. In either case, onCreate() is called on a fresh heap which cannot have been influenced by any other of
the activity’s entry points. Thus, it is safe to assume that none of the activity’s entry points is called before onCreate. An
App process
killed
Activity
running</p>
      <p>Activity
shut down
triggered by user action
example of how this assumption can be exploited to rule out impossible information flows and thus leads to increased
precision is shown in listing 2: In this variant of listing 1, the source is contained in onStart() and the sink is contained in
onCreate(). Since onCreate is never executed after onStart, the sink cannot be influenced by the source.
Intents. Our model also provides basic support for intents. In order to incorporate the intents an application may react to,
the application’s manifest is inspected, the possible intent targets are resolved and appropriate method calls are inserted
into the artificial entry method. Similarly, our approach handles intents which may be issued during the execution of the
application and whose target can be resolved to a component within the same application.
5</p>
    </sec>
    <sec id="sec-4">
      <title>Related Work</title>
      <p>
        From a formal description of a given web framework, the F4F system[
        <xref ref-type="bibr" rid="ref14">15</xref>
        ] generates Java code that specifies the
frameworkrelated behaviour, which allows for static taint analysis of web applications. In [
        <xref ref-type="bibr" rid="ref15">16</xref>
        ], a framework for static detection of
explicit information flow in Android application using a security type system is presented. It is calling-context insensitive;
the application life cycle is not modelled. In addition to explicit flow between all activities of a single Android applications,
the static analysis from [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] also handles inter-application flow. A coarse model of the life cycle is used. Flow Droid[
        <xref ref-type="bibr" rid="ref16">17</xref>
        ]
precisely models life cycle for a static analysis of explicit flow.
6
      </p>
    </sec>
    <sec id="sec-5">
      <title>Conclusion and Future Work</title>
      <p>We presented our work on extending our PDG-based information flow control tool Joana to also properly handle android
applications. To achieve this goal, it was necessary to provide a front end to WALA which is able to process Dalvik bytecode.
For this purpose, we integrated code from the SCanDroid project. Furthermore, we had to deal with the fact that Android
apps have multiple entry points, whereas standard Java applications only have a single entry point.</p>
      <p>We did this by synthesizing an artificial main method which calls all the app’s entry points in all possible orders. To not
be overly imprecise, the generated code respects the lifecycle specifications of Android components, e.g. of activities.</p>
      <p>We now elaborate on the work that is left to do.</p>
      <p>At the moment we do not handle callbacks of graphical user interfaces. We plan to integrate these callbacks in the
future. The graphical user interfaces of Android apps are typically described in separate files and these files also contain the
callbacks which are invoked on user input, e.g. when a button is pressed.</p>
      <p>Hence, to also cover GUI callbacks, they have to be extracted from the separate files and integrated into the artificial
main method appropriately.</p>
      <p>Last but not least, we only analyse information flows inside single apps, but no information flows between di erent apps.
This could be achieved by simply analysing all the apps simultaneously. However, such an analysis would have to be re-done
each time an app is added. Additionally, the analysis would have to be adapted in order to not assume that all the apps
under analysis share a single heap (normally, di erent apps run in di erent virtual machines and hence have separate heaps).</p>
      <p>An alternative, more modular approach is outlined in
figure 5: First, the intra-app flows in each single
application are analysed and summaries are generated from
these analysis results. After that, a communication graph
is built by connecting one app’s summary with another
app’s summary if one of the former app’s components
may trigger one of the latter app’s components by issuing
an intent. The paths of such a graph represent the possible
information flows between the apps.</p>
      <sec id="sec-5-1">
        <title>Acknowledgments.</title>
      </sec>
      <sec id="sec-5-2">
        <title>Tobias Blaschke provided an implementation of our approach in his diploma thesis. This work was funded by the DFG under the project in the priority program RS3 (SPP 1496) and by the BMBF under the KASTEL competence center for applied IT security technology.</title>
        <p>[14] DroidBench. http://sseblog.ec-spride.de/tools/droidbench/.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>International</given-names>
            <surname>Data Corporation</surname>
          </string-name>
          .
          <article-title>Smartphone os market share</article-title>
          ,
          <year>q3 2014</year>
          . http://www.idc.com/prodserv/ smartphone-os
          <article-title>-market-share.jsp</article-title>
          . Accessed:
          <fpage>2014</fpage>
          -12-22.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>D. E.</given-names>
            <surname>Denning</surname>
          </string-name>
          and
          <string-name>
            <given-names>P. J.</given-names>
            <surname>Denning</surname>
          </string-name>
          .
          <article-title>Certification of programs for secure information flow</article-title>
          .
          <source>Commun. ACM</source>
          ,
          <volume>20</volume>
          (
          <issue>7</issue>
          ):
          <fpage>504</fpage>
          -
          <lpage>513</lpage>
          ,
          <year>July 1977</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>J.</given-names>
            <surname>Graf</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Hecker</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Mohr</surname>
          </string-name>
          .
          <article-title>Using JOANA for Information Flow Control in Java Programs - A Practical Guide</article-title>
          .
          <source>In Proc. 6th ATPS</source>
          , pages
          <fpage>123</fpage>
          -
          <lpage>138</lpage>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>S.</given-names>
            <surname>Horwitz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Reps</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Binkley</surname>
          </string-name>
          .
          <article-title>Interprocedural Slicing Using Dependence Graphs</article-title>
          .
          <source>ACM Trans. Program. Lang. Syst.</source>
          ,
          <volume>12</volume>
          (
          <issue>1</issue>
          ):
          <fpage>26</fpage>
          -
          <lpage>60</lpage>
          ,
          <year>1990</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Google</surname>
          </string-name>
          . Android API Guide. http://developer.android.com/guide/index.html. Accessed:
          <fpage>2014</fpage>
          -12-23.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>T.</given-names>
            <surname>Reps</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Horwitz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Sagiv</surname>
          </string-name>
          , and
          <string-name>
            <given-names>G.</given-names>
            <surname>Rosay</surname>
          </string-name>
          .
          <article-title>Speeding up slicing</article-title>
          .
          <source>In Proceedings of the 2Nd ACM SIGSOFT Symposium on Foundations of Software Engineering, SIGSOFT '94</source>
          , pages
          <fpage>11</fpage>
          -
          <lpage>20</lpage>
          , New York,
          <year>1994</year>
          . ACM.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>D.</given-names>
            <surname>Wasserrab</surname>
          </string-name>
          and
          <string-name>
            <given-names>D.</given-names>
            <surname>Lohner</surname>
          </string-name>
          .
          <article-title>Proving information flow noninterference by reusing a machine-checked correctness proof for slicing</article-title>
          .
          <source>In 6th Int. Verif. Worksh.</source>
          , pages
          <fpage>141</fpage>
          -
          <lpage>155</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>J.</given-names>
            <surname>Goguen</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Meseguer</surname>
          </string-name>
          .
          <article-title>Security policies and security models</article-title>
          .
          <source>In IEEE Symposium on Sec. &amp; Priv</source>
          ., pages
          <fpage>11</fpage>
          -
          <lpage>20</lpage>
          ,
          <year>1982</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>D.</surname>
          </string-name>
          <article-title>Gi horn. Slicing of Concurrent Programs and its Application to Information Flow Control</article-title>
          .
          <source>PhD thesis</source>
          , Karlsruher Institut fu¨r Technologie,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Sabelfeld</surname>
          </string-name>
          and
          <string-name>
            <given-names>A. C.</given-names>
            <surname>Myers</surname>
          </string-name>
          .
          <article-title>Language-based information-flow security</article-title>
          .
          <source>IEEE Journal on Selected Areas in Communications</source>
          ,
          <volume>21</volume>
          (
          <issue>1</issue>
          ):
          <fpage>5</fpage>
          -
          <lpage>19</lpage>
          ,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>D.</surname>
          </string-name>
          <article-title>Gi horn and G. Snelting. A New Algorithm for Low-Deterministic Security</article-title>
          .
          <source>International Journal of Information Security</source>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>T.J.Watson</surname>
          </string-name>
          <article-title>Library for Analysis (WALA)</article-title>
          , http://wala.sf.net. http://wala.sf.net.
          <source>Accessed on 2014-12-23.</source>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>A. P.</given-names>
            <surname>Fuchs</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Chaudhuri</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J. S.</given-names>
            <surname>Foster</surname>
          </string-name>
          . Scandroid:
          <article-title>Automated security certification of android applications</article-title>
          .
          <source>Technical Report CS-TR-4991</source>
          , University of Maryland, Department of Computer Science,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>M.</given-names>
            <surname>Sridharan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Artzi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Pistoia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Guarnieri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Tripp</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Berg</surname>
          </string-name>
          .
          <article-title>F4F: taint analysis of framework-based web applications</article-title>
          .
          <source>In Proc. 26th OOPSLA/SPLASH (ACM SIGPLAN)</source>
          , pages
          <fpage>1053</fpage>
          -
          <lpage>1068</lpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>C.</given-names>
            <surname>Mann</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Starostin</surname>
          </string-name>
          .
          <article-title>A framework for static detection of privacy leaks in android applications</article-title>
          .
          <source>In Proceedings of the ACM Symposium on Applied Computing, SAC</source>
          <year>2012</year>
          , Riva, Trento, Italy, March
          <volume>26</volume>
          -30,
          <year>2012</year>
          , pages
          <fpage>1457</fpage>
          -
          <lpage>1462</lpage>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>S.</given-names>
            <surname>Arzt</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Rasthofer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Fritz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Bodden</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Bartel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Klein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Le Traon</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Octeau</surname>
          </string-name>
          , and
          <string-name>
            <given-names>P.</given-names>
            <surname>McDaniel. FlowDroid:</surname>
          </string-name>
          <article-title>Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps</article-title>
          .
          <source>In Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation</source>
          , volume
          <volume>49</volume>
          , pages
          <fpage>259</fpage>
          -
          <lpage>269</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>