Poster: SPECK: From Google Textual Guidelines to Automatic Detection of Android Apps Vulnerabilities
摘要
This paper addresses vulnerabilities in Android apps introduced by developers failing to follow Google’s security guidelines. Existing tools do not cover all guidelines, leaving many violations undetected. We propose SPECK, a static rule-based taint analysis system that detects violations of all 31 Google guidelines, outperforming current tools. Analyzing 500 popular apps, we find every app has at least one violation, highlighting the need for comprehensive detection.