A STATIC ANALYSIS LANDSCAPE OF ANDROID APPLICATIONS: VULNERABILITY, PERMISSION, AND CODE QUALITY PATTERNS APPLICATIONS
Keywords:
Android security, static analysis, SonarQube, code smells, technical debt, permission model, exported components, vulnerability analysis, software quality, and empirical software engineering.Abstract
The Open Distribution Model of Android coupled with the open source software quality test tools has forced the automated Static Analysis as the main scalable approach to characterise Application Level Security and Quality Risk.The Open Distribution Model of Android and the open source software quality test tools have compelled the automated Static Analysis as the main scalable approach to characterise Application Level Security and Quality Risk. This paper introduces an empirical corpus-wide study of 284 SonarQube static-analysis reports, from 263 different Android applications, containing 8,923 individual findings, both combined into two interconnected and audited relational tables and analysed by descriptive, correlational and comparative statistics. The majority of code smells (44.6%), followed by Security Hotspots (28.5%), Vulnerabilities (15.0%) and Bugs (11.9%). If we look at the rated ones, 85.7% of them have a mid or worst rating in SonarQube, with the most common rule in the corpus being “inadequately restricted exported Android component” (930 times), “dangerous permission declaration” (808 times), and “clear text network communication” (296 times). The highly significant correlation between dangerous permission count and the study's composite risk score (Spearman's rho = 0.83, p < 0.001) suggests that the dangerous permission count is strongly related to the composite risk score; in contrast, the bug counts and security-relevant findings exhibit weak-to-moderate correlations with each other (Spearman's rho ~ 0.2-0.5), suggesting that reliability and security are significantly distinct aspects of Android application quality in this corpus. The results bring the static analysis literature, which is dominated by work focused on open-source infrastructure, into a consumer-facing Android context, and indicate that permission-footprint auditing and exported-component review are reasonable triage priorities for static analysis-based organisations to address Android application risk on a large scale.


