Practical Precise Taint-flow Static Analysis for Android App Sets

SEI Report
This paper describes how to detect taint flow in Android app sets with a static analysis method that is fast and uses little disk and memory space.
Publisher

Software Engineering Institute

Abstract

Colluding apps, or a combination of a malicious app and leaky app, can use intents (messages sent to Android app components) to exfiltrate sensitive or private information from an Android phone. This paper describes a novel static analysis method “Precise-DF” to detect taint flow in Android app sets (including flows involving multiple apps) that is precise, fast, and uses relatively little disk and memory space. Precise-DF re-uses the fast modular analysis of the DidFail static analysis tool, and adds context and therefore precision with parameterized summaries of potential data flows. We added Boolean formulas to DidFail’s flow equations, to record conditions of control flow paths relevant to possible taint flows. The method that we have refined (a modular analysis with parameterized summaries of flow of sensitive information) is generally applicable to the class of problems involving taint flow analysis for software systems that communicate by message passing. This paper also describes how an enterprise architecture could use Precise-DF to analyze and enforce compliance with dataflow policies.

Cite This SEI Report

Klieber, W., Flynn, L., Snavely, W., & Zheng, M. (2018, August 27). Practical Precise Taint-flow Static Analysis for Android App Sets. Retrieved September 17, 2026, from https://www.sei.cmu.edu/library/practical-precise-taint-flow-static-analysis-for-android-app-sets/.

@techreport{klieber_2018,
author={Klieber, William and Flynn, Lori and Snavely, William and Zheng, Michael},
title={Practical Precise Taint-flow Static Analysis for Android App Sets},
month={Aug},
year={2018},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/practical-precise-taint-flow-static-analysis-for-android-app-sets/},
note={Accessed: 2026-Sep-17}
}

Klieber, William, Lori Flynn, William Snavely, and Michael Zheng. "Practical Precise Taint-flow Static Analysis for Android App Sets." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, August 27, 2018. https://www.sei.cmu.edu/library/practical-precise-taint-flow-static-analysis-for-android-app-sets/.

W. Klieber, L. Flynn, W. Snavely, and M. Zheng, "Practical Precise Taint-flow Static Analysis for Android App Sets," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 27-Aug-2018 [Online]. Available: https://www.sei.cmu.edu/library/practical-precise-taint-flow-static-analysis-for-android-app-sets/. [Accessed: 17-Sep-2026].

Klieber, William, Lori Flynn, William Snavely, and Michael Zheng. "Practical Precise Taint-flow Static Analysis for Android App Sets." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 27 Aug. 2018. https://www.sei.cmu.edu/library/practical-precise-taint-flow-static-analysis-for-android-app-sets/. Accessed 17 Sep. 2026.

Klieber, William; Flynn, Lori; Snavely, William; & Zheng, Michael. Practical Precise Taint-flow Static Analysis for Android App Sets. Software Engineering Institute. 2018. https://www.sei.cmu.edu/library/practical-precise-taint-flow-static-analysis-for-android-app-sets/