Correlating UI Contexts with Sensitive API Calls: Dynamic Semantic Extraction and Analysis

Authors

Jie Liu Dongjie He Diyu Wu Jingling Xue

Description

APICOG is a novel fine-grained API-level approach for assessing automatically description-to-permission fidelity in Android apps, by checking the legitimacy of an API call under a particular UI context. This work is introduced in our paper titled "Correlating UI Contexts with Sensitive API Calls: Dynamic Semantic Extraction and Analysis".

APICOG can be used either as a market-level vetting tool for App stores such as Google Play or by developers and/or researchers for finding information leaks in apps. Welcome to try!

License

GNU Lesser General Public License v2.1

Downloads

The tar.gz file includes the source code of APICOG, which is a Python project.