Static Analysis for Detecting Deep-Link Security Misconfigurations in Android Applications
2026 (English)Independent thesis Basic level (degree of Bachelor), 180 HE credits
Student thesis
Abstract [en]
In Android application development, developers increasingly rely on deep links to open content from external sources such as websites, emails, and other applications. Although deep links improve usability, incorrect configuration or insecure handling can introduce security risks, including link hijacking, malicious parameter injection, and unsafe WebView usage. This thesis designs, implements, and evaluates a Python-based static analysis tool, intended for use in Continuous Integration (CI) environments, that detects twelve deep-link security misconfigurations across Android manifest files, Digital Asset Links files, and Kotlin/Java source code. The evaluation was carried out in three stages, a controlled test application, a synthetic benchmark of fifteen rule-targeted projects with a labelled ground truth of 53 expected findings, and a study of fifteen real-world open-source Android applications producing 416 findings, each manually verified against the source code. The tool achieved perfect precision, recall, and F1-score on the synthetic benchmark. For real-world applications, it achieved 88.9% precision, increasing to approximately 95% after excluding test files. False-positive analysis identified three concrete causes, test-file scanning, non-deep-link URI utilities, and intra-filter <data> element aggregation. These findings suggest three directions for future improvements, excluding test directories, aggregating split <data> elements, and incorporating inter-procedural data-flow tracking. The tool, benchmark projects, and labelled open-source dataset are released as reusable research artefacts.
Place, publisher, year, edition, pages
2026. , p. 50
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:hj:diva-72816OAI: oai:DiVA.org:hj-72816DiVA, id: diva2:2075694
External cooperation
Aleksandar Gajic
Subject / course
JTH, Computer Engineering
Presentation
2026-05-28, E1028 i JTH, Jönköping, 08:00 (English)
Supervisors
Examiners
2026-08-172026-06-182026-08-17Bibliographically approved