TY - GEN
T1 - Catamaran
T2 - 2025 IEEE Secure Development Conference, SecDev 2025
AU - Hou, Chenxi
AU - Chong, Chun Jie
AU - Yao, Zhihao
AU - Peng, Hui
N1 - Publisher Copyright:
©2025 IEEE.
PY - 2025
Y1 - 2025
N2 - Logs are widely used in mobile apps for debugging and diagnosis. Unfortunately, they frequently expose personally identifiable information (PII) due to inattentive logging practices, leading to privacy hazards, which has been categorized as a Common Weakness Enumeration, CWE-532. Existing manual redaction and anonymization techniques are often incomplete and ineffective, as evidenced by the rising number of CWE-532 vulnerabilities. To address this, we introduce Catamaran, a framework to proactively detect PII violations in Android app logs. Catamaran takes a comprehensive approach combining dynamic and static analyses: dynamic analysis captures PII leaks directly at runtime in logcat and other log files, while static analysis expands detection to untriggered code paths by reconstructing contextualized log statements. The static analysis leverages call graph analysis, constant propagation, and Large Language Model (LLM) to intelligently identify potential PII issues. Our extensive evaluation on 3,885 Android apps uncovered runtime PII leakage in 233 apps (approximately 6%), comprising a total of 7,485 violations. The static analysis of 300,073 log statements across 3,994 apps identified 1,788 potential log-based PII leaks in 932 apps and 97 distinct libraries. We have responsibly disclosed our findings, leading to the confirmation of nine vulnerabilities and four patches in the Android Open Source Project (AOSP).
AB - Logs are widely used in mobile apps for debugging and diagnosis. Unfortunately, they frequently expose personally identifiable information (PII) due to inattentive logging practices, leading to privacy hazards, which has been categorized as a Common Weakness Enumeration, CWE-532. Existing manual redaction and anonymization techniques are often incomplete and ineffective, as evidenced by the rising number of CWE-532 vulnerabilities. To address this, we introduce Catamaran, a framework to proactively detect PII violations in Android app logs. Catamaran takes a comprehensive approach combining dynamic and static analyses: dynamic analysis captures PII leaks directly at runtime in logcat and other log files, while static analysis expands detection to untriggered code paths by reconstructing contextualized log statements. The static analysis leverages call graph analysis, constant propagation, and Large Language Model (LLM) to intelligently identify potential PII issues. Our extensive evaluation on 3,885 Android apps uncovered runtime PII leakage in 233 apps (approximately 6%), comprising a total of 7,485 violations. The static analysis of 300,073 log statements across 3,994 apps identified 1,788 potential log-based PII leaks in 932 apps and 97 distinct libraries. We have responsibly disclosed our findings, leading to the confirmation of nine vulnerabilities and four patches in the Android Open Source Project (AOSP).
KW - Logging
KW - Mobile Privacy
KW - Program Analysis
UR - https://www.scopus.com/pages/publications/105025197073
UR - https://www.scopus.com/pages/publications/105025197073#tab=citedBy
U2 - 10.1109/SecDev66745.2025.00013
DO - 10.1109/SecDev66745.2025.00013
M3 - Conference contribution
AN - SCOPUS:105025197073
T3 - Proceedings - 2025 IEEE Secure Development Conference, SecDev 2025
SP - 16
EP - 28
BT - Proceedings - 2025 IEEE Secure Development Conference, SecDev 2025
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 14 October 2025 through 16 October 2025
ER -