Logo image
A Plugin for Kotlin based Android Apps to Detect Security Breaches through Dataflow
Conference proceeding   Peer reviewed

A Plugin for Kotlin based Android Apps to Detect Security Breaches through Dataflow

Md Arabin Islam Talukder, Sumaiya Farzana Mishu, Hossain Shahriar, ABM Kamrul Islam Riad, Fan Wu and Akond Rahman
2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC), Vol.2023-, pp.1840-1845
Annual Computers, Software, and Applications Conference (COMPSAC), 47th (Torino, Italy, 06/26/2023–06/30/2023)
08/2023
Web of Science ID: WOS:001046484100275

Metrics

1 Record Views

Abstract

Android Data Flow Analysis Dependency Injection Kotlin Plugin RoomDb Software Security SQL-Injection Static analysis call graph Cybersecurity Software Engineering
Android developers have already adopted Kotlin as their preferred language. Kotlin is more well-accepted than Java because of its simplicity, readability, and new features like scope functions, extension functions, null safety, etc. Google has introduced several new libraries such as RoomDb, Jetpack-Compose, as well as dependency injection frameworks like Dagger-Hilt to enhance Android Development. The question is how secure these libraries are? Are there tools available to analyze new Libraries? DroidPatrol [1] is our existing static analysis plugin that works on Android Apps written in Java. To support Kotlin code analysis we were continuously working on upgrading our plugin. Finally, we released DroidPatrol 2.0 [2] which is compatible to perform static analysis of Android apps developed in Kotlin. It also works on Java-based Android app developed in Java. In this latest edition, we restructured the architecture of the plugin to optimize its efficiency. We also found a vulnerability in RoomDb. The latest version is developed in Kotlin, and we used IntelliJ Idea. Lastly, version 2.0 is independent of Android Studio editions meaning that any version of Android Studio is compatible.

Details

Logo image