The project consists of the source code files for PIChecker, which include three analysis phases mentioned in this paper - static analysis, dynamic analysis modules written in Java, and a text analysis module written in Python.
It is recommended to import the entire project directly into Intellij IDEA, which allows for the direct import of relevant packages from the lib folder.
Recommended configurations:
Java: JDK 11Python: python 3.11Android Emulator(for dynamic analysis): Google’s android-34 system image (x86_64)
Note: The dynamic analysis process requires the use of DroidBot, which is already included in this project. Manual installation is required.
The following environment is needed for DroidBot:
Python(both 2 and 3 are supported)JavaAndroid SDK- Add
platform_toolsdirectory in Android SDK to `PATH
Execute the following code to install DroidBot:
cd droidbot-master/
pip install -e .If successfully installed, you should be able to execute droidbot -h.
The datasets of the project (including APKs, TPLs and privacy policy documents) are not included in this repository due to their large size. You can download the datasets from the following link: Dataset of PIChecker
The source code files are located in the ./src folder, and the project structure is as follows:
src
│
├── Config
│ ├── Config.java
│ ├── Constant.java
│ └── Environment.java
│
├── DataFlowAnalysis
│ ├── InterProcedureVariableAnalysis.java
│ └── IntraProcedureVariableAnalysis.java
│
├── Main
│ ├── APPAnalysis.java
│ ├── DynamicAnalysis.java
│ └── TPLAnalysis.java
│
└── Util
├── APKInstrumentation.java
├── ApkModifier.java
├── APKParser.java
├── APKSigner.java
├── LogAnalyzer.java
├── ManifestHandler.java
├── SourceSinkHandler.java
└── Utils.javaI will now provide a detailed description of the purpose of each file:
- Config.java: Configuration information for the entire project, requiring manual modifications for different files to be tested, including the location of the APK, TPL, result generation location, dynamic analysis timeout, etc.
- Constant.java: Defines some constants that may be used during the testing process.
- Environment.java: Contains functions for initializing Soot and dynamic testing.
- InterProcedureVariableAnalysis.java: Code related to inter-procedure variable analysis.
- IntraProcedureVariableAnalysis.java: Code related to intra-procedure variable analysis.
- APPAnalysis.java: Entry point for the entire program, used for analyzing the app, integrating static and dynamic analysis phases. Can be executed with a single click, or the static analysis program can be run separately.
- DynamicAnalysis.java: Entry point for dynamic analysis, used for executing the dynamic analysis phase separately.
- TPLAnalysis.java: Entry point for TPL analysis, used for analyzing third-party library files (
aarorjar) in static analysis.
- APKInstrumentation.java: Code related to APK instrumentation, used to insert relevant statements into the app after static analysis.
- ApkModifier.java: Code related to APK modification, mainly used to modify the
minSdkVersionof the APK to avoid errors during Soot output generation. - APKParser.java: Uses the
net.dongliupackage to parse relevant information from the APK, includingminSdkVersion,compileSdkVersion, package name, etc. - APKSigner.java: Used to automatically generate temporary self-signed APK files and sign the APK.
- LogAnalyzer.java: Used to analyze and summarize collected log information after dynamic analysis.
- ManifestHandler.java: Used to analyze the manifest of the APK and extract useful information.
- SourceSinkHandler.java: Used to read and store information related to sources and sinks for easy matching during the static analysis process.
- Utils.java: Various utility code, including creating and deleting files, unzipping
AARand other compressed files, extracting local variables from Soot Unit statements, extracting signatures from Unit statements, storing custom JSON files, and various other custom methods.
The text analysis phase is based on python, with the following file structure:
src
│
├── PrivacyAnalysis
│ ├── pp
│ ├── app_analysis.py
│ └── pp_analysis.py
│ └── TPL_analysis.pyIn this structure, the core file is pp_analysis.py, which serves as the privacy policy document analysis module. app_analysis.py and TPL_analysis.py are codes used to compare the results of text analysis and program analysis and should be executed only after all three analysis phases have been completed. The pp directory is privacy policies we have collected.
Note that you may need the following package to run the script properly.
tiktoken: Any version availableopenai: Any version available
App testing includes static analysis and dynamic analysis.
Before testing, ensure that all the jar files in the ./lib directory are included in the environment. You can download the APK files we have collected, which are recommended to be placed in the ./data directory.
Then you should update the APKS_PATH, INSTRUMENTED_APKS_PATH, APP_RESULTS variables in ./src/Config/Config.java
PS: We also manually wrote a demo apk file containing privacy leakage code in ./resources/app-debug.apk. If you only want to test this demo app, you can directly run the step 2 without any further configuration.
If you want to test the demo app, you can directly build and run the ./src/Main/APPAnalysis.java. Otherwise, you have to uncomment the code for analyze the whole folder, then you can run APPAnalysis.java.
Meanwhile, the dynamic analysis is switched off by default, if you want to run the two analysis phase in one instruction, you can set runDynamicAnalysis = true
After running the static analysis, you can run the ./src/Main/DynamicAnalysis.java. Dynamic running needs android devices (or emulator). After analysis, the result will be at Config.APP_RESULTS path.
After running the app analysis, you can run the ./PrivacyAnalysis/pp_analysis.py to test the privacy policy documents.
Note that you have to set analyze_tpl = False, set document_path and set OpenAI apikey to run the script.
After completing the three analysis phases, you can choose to run ./PrivacyAnalysis/app_analysis.py to compare the results between the app analysis and the privacy policy analysis. If the number of files to test is not too large, manual inspection is recommended instead of using the code.
The steps of the TPL testing are similar to the app testing part. Only dynamic testing is excluded.
Before test, you should involve all the jar files of the ./lib directory in the environment. You can download the third-party libraries we have collected, which are recommended to be placed in the ./data directory.
Then you should update the TPL_PATH and TPL_RESULTS variables in ./src/Config/Config.java
If you want to test the TPL, you can build and run the ./src/Main/TPLAnalysis.java. The result will be generated at Config.TPL_RESULTS path.
After running the static analysis of TPLs, you can run the ./PrivacyAnalysis/pp_analysis.py to test the privacy policy documents.
Note that you have to set analyze_tpl = True, set document_path and set OpenAI apikey to run the script.
After completing the three analysis phases, you can choose to run ./PrivacyAnalysis/tpl_analysis.py to compare the results between the TPL analysis and the privacy policy analysis. If the number of files to test is not too large, manual inspection is recommended instead of using the code.