Abstract
In the Android ecosystem today, code is often reused by developers in the form of software libraries. This practice not only saves time, but also reduces the complexity of software development. However, like all other software, software libraries are prone to bugs, design flaws, and security vulnerabilities. They too undergo incremental updates to not only add/change features, but also to address their flaws. Unfortunately, the knowledge gap between consumers and maintainers of software libraries presents a barrier to the timely adoption of important library updates.
Therefore we present LibDetector, a tool for identifying the specific version of Java libraries used in Android applications. Using LibDetector, we perform a large empirical analysis of the current trends of library use in the Android ecosystem. We find that a huge proportion of applications currently available on the Google Play Store use outdated libraries. We also explore the potential effects of this lax updating practice. In 2 of the 17 libraries we studied, apps that contain outdated versions of the library had a significantly different average rating than apps that contain more recent versions of the library. Finally, we find in a case study that a vulnerable version of a library is a realistic threat to the security of apps consuming that version of the library.
Library of Congress Subject Headings
Data libraries--Management; Application software--Evaluation; Android (Electronic resource)--Programming
Publication Date
8-15-2016
Document Type
Thesis
Student Type
Graduate
Degree Name
Software Engineering (MS)
Department, Program, or Center
Software Engineering (GCCIS)
Advisor
Meiyappan Nagappan
Advisor/Committee Member
Mehdi Mirakhorli
Advisor/Committee Member
Scott Hawker
Recommended Citation
Chi, Zhihao Mike, "LibDetector: Version Identification of Libraries in Android Applications" (2016). Thesis. Rochester Institute of Technology. Accessed from
https://repository.rit.edu/theses/9211
Campus
RIT – Main Campus
Comments
Physical copy available from RIT's Wallace Library at QA76.76.A65 C44 2016