A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android
Jingyun Zhu, Kaixuan Li, Sen Chen, Lingling Fan, Junjie Wang, and, Xiaofei Xie

TL;DR
This paper introduces VulsTotal, a unified platform for evaluating Android SAST tools, addressing the lack of standardized benchmarks and reports, and providing a comprehensive comparison of 11 tools across diverse vulnerability types.
Contribution
The paper presents VulsTotal, the first unified platform for Android SAST tool evaluation, including a new CVE-based benchmark and standardized reporting for comprehensive analysis.
Findings
VulsTotal enables consistent comparison of SAST tools.
The study reveals varying effectiveness and coverage among tools.
Benchmark results highlight strengths and weaknesses of each tool.
Abstract
To identify security vulnerabilities in Android applications, numerous static application security testing (SAST) tools have been proposed. However, it poses significant challenges to assess their overall performance on diverse vulnerability types. The task is non-trivial and poses considerable challenges. {Firstly, the absence of a unified evaluation platform for defining and describing tools' supported vulnerability types, coupled with the lack of normalization for the intricate and varied reports generated by different tools, significantly adds to the complexity.} Secondly, there is a scarcity of adequate benchmarks, particularly those derived from real-world scenarios. To address these problems, we are the first to propose a unified platform named VulsTotal, supporting various vulnerability types, enabling comprehensive and versatile analysis across diverse SAST tools. Specifically,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · Web Application Security Vulnerabilities
