SAND: a static analysis approach for detecting SQL antipatterns
Yingjun Lyu, Sasha Volokh, William G. J. Halfond, Omer Tripp
摘要
Local databases underpin important features in many mobile applications, such as responsiveness in the face of poor connectivity. However, failure to use such databases correctly can lead to high resource consumption or even security vulnerabilities. We present SAND, an extensible static analysis approach that checks for misuse of local databases, also known as SQL antipatterns, in mobile apps. SAND features novel abstractions for common forms of application/database interactions, which enables concise and precise specification of the antipatterns that SAND checks for. To validate the efficacy of SAND, we have experimented with a diverse suite of 1,000 Android apps. We show that the abstractions that power SAND allow concise specification of all the known antipatterns from the literature (12-74 LOC), and that the antipatterns are modeled accurately (99.4-100% precision). As for performance, SAND requires on average 41 seconds to complete a scan on a mobile app.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- SQLCheck: Automated Detection and Diagnosis of SQL Anti-PatternsPrashanth Dintyala, Arpit Narechania, Joy ArulrajSIGMOD 2020 · 被引用 26 次
- IMGDroid: Detecting Image Loading Defects in Android ApplicationsWei Song, Mengqi Han, Jeff HuangICSE 2021 · 被引用 10 次
- Static asynchronous component misuse detection for Android applicationsLinjie Pan, Baoquan Cui, Hao Liu, Jiwei Yan 等FSE 2020 · 被引用 10 次
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 被引用 1 次
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel 等USENIX Security 2016 · 被引用 161 次
