Skip to main navigation Skip to search Skip to main content

Catamaran: User Privacy Violation Detection in Mobile Logging

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Logs are widely used in mobile apps for debugging and diagnosis. Unfortunately, they frequently expose personally identifiable information (PII) due to inattentive logging practices, leading to privacy hazards, which has been categorized as a Common Weakness Enumeration, CWE-532. Existing manual redaction and anonymization techniques are often incomplete and ineffective, as evidenced by the rising number of CWE-532 vulnerabilities. To address this, we introduce Catamaran, a framework to proactively detect PII violations in Android app logs. Catamaran takes a comprehensive approach combining dynamic and static analyses: dynamic analysis captures PII leaks directly at runtime in logcat and other log files, while static analysis expands detection to untriggered code paths by reconstructing contextualized log statements. The static analysis leverages call graph analysis, constant propagation, and Large Language Model (LLM) to intelligently identify potential PII issues. Our extensive evaluation on 3,885 Android apps uncovered runtime PII leakage in 233 apps (approximately 6%), comprising a total of 7,485 violations. The static analysis of 300,073 log statements across 3,994 apps identified 1,788 potential log-based PII leaks in 932 apps and 97 distinct libraries. We have responsibly disclosed our findings, leading to the confirmation of nine vulnerabilities and four patches in the Android Open Source Project (AOSP).

Original languageEnglish (US)
Title of host publicationProceedings - 2025 IEEE Secure Development Conference, SecDev 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages16-28
Number of pages13
ISBN (Electronic)9798331595951
DOIs
StatePublished - 2025
Event2025 IEEE Secure Development Conference, SecDev 2025 - Indianapolis, United States
Duration: Oct 14 2025Oct 16 2025

Publication series

NameProceedings - 2025 IEEE Secure Development Conference, SecDev 2025

Conference

Conference2025 IEEE Secure Development Conference, SecDev 2025
Country/TerritoryUnited States
CityIndianapolis
Period10/14/2510/16/25

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications
  • Software
  • Safety, Risk, Reliability and Quality

Keywords

  • Logging
  • Mobile Privacy
  • Program Analysis

Fingerprint

Dive into the research topics of 'Catamaran: User Privacy Violation Detection in Mobile Logging'. Together they form a unique fingerprint.

Cite this