Call Graph Soundness in Android Static Analysis
Jordan Samhi, René Just, Tegawendé F. Bissyandé, Michael D. Ernst, Jacques Klein
Abstract
Static analysis is sound in theory, but an implementation may unsoundly fail to analyze all of a program's code. Any such omission is a serious threat to the validity of the tool's output. Our work is the first to measure the prevalence of these omissions. Previously, researchers and analysts did not know what is missed by static analysis, what sort of code is missed, or the reasons behind these omissions. To address this gap, we ran 13static analysis tools and a dynamic analysis on 1000 Android apps. Any method in the dynamic analysis but not in a static analysis is an unsoundness. Our findings include the following. (1) Apps built around external frameworks challenge static analyzers. On average, the 13 static analysis tools failed to capture 61% of the dynamically-executed methods. (2) A high level of precision in call graph construction is a synonym for a high level of unsoundness. (3) No existing approach significantly improves static analysis soundness. This includes those specifically tailored for a given mechanism, such as DroidRA to address reflection. It also includes systematic approaches, such as EdgeMiner, capturing all callbacks in the Android framework systematically. (4) Modeling entry point methods challenges call graph construction which jeopardizes soundness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2796fa2c-0115-44a1-874a-00373bb61022Cited by top-tier papers3
- Bridge the Islands: Pointer Analysis for Microservice SystemsTeng Zhang, Yufei Liang, Ganlin Li, Tian Tan et al.ISSTA 2025 · 2 citations
- Is Call Graph Pruning Really Effective?: An Empirical Re-evaluationMohammad Rafieian, Vlad Birsan, Kunal Katiyar, Dylan Zhong et al.ICSE 2026 · 1 citation
- Hercules Droidot and the murder on the JNI ExpressLuca Di Bartolomeo, Philipp Mao, Yu-Jye Tung, Jessy Ayala et al.USENIX Security 2025
Builds on7
- JuCify: A Step Towards Android Code Unification for Enhanced Static AnalysisJordan Samhi, Jun Gao, Nadia Daoudi, Pierre Graux et al.ICSE 2022 · 43 citations
- An infrastructure approach to improving effectiveness of Android UI testing toolsWenyu Wang, Wing Lam, Tao XieISSTA 2021 · 33 citations
- Difuzer: Uncovering Suspicious Hidden Sensitive Operations in Android AppsJordan Samhi, Li Li, Tegawendé F. Bissyandé, Jacques KleinICSE 2022 · 26 citations
- Cross-language Android permission specificationChaoran Li, Xiao Chen, Ruoxi Sun, Minhui Xue et al.FSE 2022 · 13 citations
- Columbus: Android App Testing Through Systematic Callback ExplorationPriyanka Bose, Dipanjan Das, Saastha Vasan, Sebastiano Mariani et al.ICSE 2023 · 8 citations
Related papers
- Identifying Java calls in native code via binary scanningGeorge Fourtounis, Leonidas Triantafyllou, Yannis SmaragdakisISSTA 2020 · 23 citations
- Discovering Flaws in Security-Focused Static Analysis Tools for Android using Systematic MutationRichard Bonett, Kaushal Kafle, Kevin Moran, Adwait Nadkarni et al.USENIX Security 2018 · 35 citations
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 1 citation
- On the recall of static call graph construction in practiceLi Sui, Jens Dietrich, Amjed Tahir, George FourtounisICSE 2020 · 34 citations
- The impact of tool configuration spaces on the evaluation of configurable taint analysis for AndroidAustin Mordahl, Shiyi WeiISSTA 2021 · 13 citations
