{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T08:25:38Z","timestamp":1765268738973,"version":"3.37.3"},"reference-count":99,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2021,6,8]],"date-time":"2021-06-08T00:00:00Z","timestamp":1623110400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,6,8]],"date-time":"2021-06-08T00:00:00Z","timestamp":1623110400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2021,7]]},"DOI":"10.1007\/s10664-021-09978-0","type":"journal-article","created":{"date-parts":[[2021,6,8]],"date-time":"2021-06-08T10:08:40Z","timestamp":1623146920000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Exposed! A case study on the vulnerability-proneness of Google Play Apps"],"prefix":"10.1007","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3192-739X","authenticated-orcid":false,"given":"Andrea","family":"Di Sorbo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sebastiano","family":"Panichella","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,6,8]]},"reference":[{"key":"9978_CR1","doi-asserted-by":"crossref","unstructured":"Acar Y, Backes M, Bugiel S, Fahl S, McDaniel P D, Smith M (2016) Sok: Lessons learned from android security research for appified software platforms. In: IEEE symposium on security and privacy, SP 2016. IEEE Computer Society, San Jose, pp 433\u2013451","DOI":"10.1109\/SP.2016.33"},{"key":"9978_CR2","doi-asserted-by":"crossref","unstructured":"Afroz S, Islam A C, Santell J, Chapin A, Greenstadt R (2013) How privacy flaws affect consumer perception. In: Workshop on Socio-Technical Aspects in Security and Trust, pp 10\u201317","DOI":"10.1109\/STAST.2013.13"},{"key":"9978_CR3","doi-asserted-by":"crossref","unstructured":"Alenezi M, Almomani I (2018) Empirical analysis of static code metrics for predicting risk scores in android applications. In: 5th International Symposium on Data Mining Applications. Springer, pp 84\u201394","DOI":"10.1007\/978-3-319-78753-4_8"},{"key":"9978_CR4","doi-asserted-by":"crossref","unstructured":"Ali M, Joorabchi M E, Mesbah A (2017) Same app, different app stores: A comparative study. In: 4th IEEE\/ACM International Conference on Mobile Software Engineering and Systems, MOBILESoft@ICSE 2017, Buenos Aires, Argentina, May 22-23, 2017, pp 79\u201390","DOI":"10.1109\/MOBILESoft.2017.3"},{"key":"9978_CR5","doi-asserted-by":"crossref","unstructured":"Aliasgari M, Black M, Yadav N (2018) Security vulnerabilities in mobile health applications. In: Conference on Application, Information and Network Security, pp 21\u201326","DOI":"10.1109\/AINS.2018.8631464"},{"key":"9978_CR6","doi-asserted-by":"crossref","unstructured":"Allix K, Bissyand\u00e9 T F, Klein J, Traon Y L (2016) Androzoo: collecting millions of android apps for the research community. In: Proceedings of the 13th International Conference on Mining Software Repositories, MSR 2016, Austin, pp 468\u2013471","DOI":"10.1145\/2901739.2903508"},{"issue":"10","key":"9978_CR7","doi-asserted-by":"publisher","first-page":"326","DOI":"10.3390\/info10100326","volume":"10","author":"A Amin","year":"2019","unstructured":"Amin A, Eldessouki A, Magdy M T, Abdeen N, Hindy H, Hegazy I (2019) Androshield: Automated android applications vulnerability detection, a hybrid static and dynamic analysis approach. Inf 10(10):326. https:\/\/doi.org\/10.3390\/info10100326","journal-title":"Inf"},{"key":"9978_CR8","doi-asserted-by":"crossref","unstructured":"Antoniol G, Ayari K, Penta M D, Khomh F, Gu\u00e9h\u00e9neuc Y-G (2008) Is it a bug or an enhancement?: a text-based approach to classify change requests. In: Proceedings of Centre for Advanced Studies on Collaborative Research, p 23","DOI":"10.1145\/1463788.1463819"},{"key":"9978_CR9","unstructured":"Baeza-Yates R, Ribeiro-Neto B, et al. (1999) Modern information retrieval, vol 463. ACM press New York"},{"issue":"4","key":"9978_CR10","doi-asserted-by":"publisher","first-page":"384","DOI":"10.1109\/TSE.2014.2367027","volume":"41","author":"G Bavota","year":"2015","unstructured":"Bavota G, V\u00e1squez M L, Bernal-C\u00e1rdenas C E, Penta M D, Oliveto R, Poshyvanyk D (2015) The impact of API change- and fault-proneness on the user ratings of android apps. IEEE Trans Softw Eng 41(4):384\u2013407. https:\/\/doi.org\/10.1109\/TSE.2014.2367027","journal-title":"IEEE Trans Softw Eng"},{"key":"9978_CR11","doi-asserted-by":"crossref","unstructured":"Bhattacharya P, Ulanova L, Neamtiu I, Koduru S C (2013) An empirical analysis of bug reports and bug fixing in open source android apps. In: 17th European Conference on Software Maintenance and Reengineering, CSMR 2013, Genova, pp 133\u2013143","DOI":"10.1109\/CSMR.2013.23"},{"key":"9978_CR12","doi-asserted-by":"crossref","unstructured":"Businge J, Openja M, Kavaler D, Bainomugisha E, Khomh F, Filkov V (2019) Studying android app popularity by cross-linking github and google play store. In: 26th IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2019, Hangzhou, pp 287\u2013297","DOI":"10.1109\/SANER.2019.8667998"},{"key":"9978_CR13","doi-asserted-by":"crossref","unstructured":"Cai Y, Tang Y, Li H, Yu L, Zhou H, Luo X, He L, Su P (2020) Resource race attacks on android. In: 27th IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2020, London, pp 47\u201358","DOI":"10.1109\/SANER48275.2020.9054863"},{"key":"9978_CR14","doi-asserted-by":"crossref","unstructured":"Canfora G, Di Sorbo A, Mercaldo F, Visaggio C A (2016) Exploring mobile user experience through code quality metrics. In: Product-Focused Software Process Improvement - 17th International Conference, Proceedings, pp 705\u2013712","DOI":"10.1007\/978-3-319-49094-6_59"},{"key":"9978_CR15","doi-asserted-by":"publisher","first-page":"102067","DOI":"10.1016\/j.cose.2020.102067","volume":"99","author":"G Canfora","year":"2020","unstructured":"Canfora G, Di Sorbo A, Forootani S, Pirozzi A, Visaggio C A (2020) Investigating the vulnerability fixing process in oss projects: Peculiarities and challenges. Comput Secur 99:102067","journal-title":"Comput Secur"},{"key":"9978_CR16","doi-asserted-by":"crossref","unstructured":"Cao C, Gao N, Liu P, Xiang J (2015) Towards analyzing the input validation vulnerabilities associated with android system services. In: Annual Computer Security Applications Conference, pp 361\u2013370","DOI":"10.1145\/2818000.2818033"},{"key":"9978_CR17","doi-asserted-by":"crossref","unstructured":"Chia P H, Yamamoto Y, Asokan N (2012) Is this app safe?: a large scale study on application permissions and risk signals. In: Proceedings of the World Wide Web Conference, pp 311\u2013320","DOI":"10.1145\/2187836.2187879"},{"key":"9978_CR18","doi-asserted-by":"crossref","unstructured":"Chin E, Felt A P, Greenwood K, Wagner D A (2011) Analyzing inter-application communication in android. In: International Conference on Mobile Systems, pp 239\u2013252","DOI":"10.1145\/1999995.2000018"},{"key":"9978_CR19","doi-asserted-by":"crossref","unstructured":"Chin E, Wagner D A (2013) Bifocals: Analyzing webview vulnerabilities in android applications. In: Information Security Applications - International Workshop, WISA, pp 138\u2013159","DOI":"10.1007\/978-3-319-05149-9_9"},{"key":"9978_CR20","doi-asserted-by":"crossref","unstructured":"Clark J, van Oorschot P C (2013) Sok: SSL and HTTPS: revisiting past challenges and evaluating certificate trust model enhancements. In: Symposium on Security and Privacy, pp 511\u2013525","DOI":"10.1109\/SP.2013.41"},{"key":"9978_CR21","unstructured":"Conover WJ (1998) Practical nonparametric statistics. Wiley series in probability and statistics: Applied probability and statistics, Wiley"},{"key":"9978_CR22","doi-asserted-by":"crossref","unstructured":"Corral L, Fronza I (2015) Better code for better apps: A study on source code quality and market success of android applications. In: International Conference on Mobile Software Engineering and Systems, MOBILESoft, pp 22\u201332","DOI":"10.1109\/MobileSoft.2015.10"},{"key":"9978_CR23","doi-asserted-by":"crossref","unstructured":"Darvish H, Husain M I (2018) Security analysis of mobile money applications on android. In: IEEE international conference on big data, big data 2018, seattle, wa, usa, december 10-13, 2018, pp 3072\u20133078","DOI":"10.1109\/BigData.2018.8622115"},{"key":"9978_CR24","doi-asserted-by":"crossref","unstructured":"Deka B, Huang Z, Franzen C, Hibschman J, Afergan D, Li Y, Nichols J, Kumar R (2017) Rico: A mobile app dataset for building data-driven design applications. In: Annual ACM Symposium on User Interface Software and Technology, pp 845\u2013854","DOI":"10.1145\/3126594.3126651"},{"key":"9978_CR25","doi-asserted-by":"publisher","unstructured":"Di Sorbo A, Panichella S, Visaggio C A, Di Penta M, Canfora G, Gall H C (2019) Exploiting natural language structures in software informal documentation. IEEE Trans Softw Eng:1\u20131. https:\/\/doi.org\/10.1109\/TSE.2019.2930519","DOI":"10.1109\/TSE.2019.2930519"},{"issue":"3","key":"9978_CR26","doi-asserted-by":"publisher","first-page":"e2316","DOI":"10.1002\/smr.2316","volume":"33","author":"A Di Sorbo","year":"2021","unstructured":"Di Sorbo A, Grano G, Visaggio C A, Panichella S (2021) Investigating the criticality of user-reported issues through their relations with app rating. J Softw Evol Process 33(3):e2316. https:\/\/doi.org\/10.1002\/smr.2316","journal-title":"J Softw Evol Process"},{"key":"9978_CR27","doi-asserted-by":"crossref","unstructured":"Di Sorbo A, Panichella S, Alexandru C V, Shimagaki J, Visaggio C A, Canfora G, Gall H C (2016) What would users change in my app? summarizing app reviews for recommending software changes. In: Zimmermann T, Cleland-Huang J, Su Z (eds) Proceedings of the 24th ACM SIGSOFT International Symposium on Foundations of Software Engineering, FSE 2016. ACM, Seattle, pp 499\u2013510","DOI":"10.1145\/2950290.2950299"},{"key":"9978_CR28","doi-asserted-by":"crossref","unstructured":"Fahl S, Harbach M, Muders T, Smith M, Baumg\u00e4rtner L, Freisleben B (2012) Why eve and mallory love android: an analysis of android SSL (in)security. In: Conference on Computer and Communications Security, pp 50\u201361","DOI":"10.1145\/2382196.2382205"},{"key":"9978_CR29","doi-asserted-by":"crossref","unstructured":"Felt A P, Chin E, Hanna S, Song D, Wagner D A (2011a) Android permissions demystified. In: ACM Conference on Computer and Communications Security, CCS 2011, Chicago, pp 627\u2013638","DOI":"10.1145\/2046707.2046779"},{"key":"9978_CR30","unstructured":"Felt A P, Wang H J, Moshchuk A, Hanna S, Chin E (2011b) Permission re-delegation: Attacks and defenses. In: USENIX security symposium"},{"issue":"2","key":"9978_CR31","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3376121","volume":"1","author":"J Gajrani","year":"2020","unstructured":"Gajrani J, Tripathi M, Laxmi V, Somani G, Zemmari A, Gaur M S (2020) Vulvet: Vetting of vulnerabilities in android apps to thwart exploitation. Digit Threats Res Practice 1(2):1\u201325","journal-title":"Digit Threats Res Practice"},{"key":"9978_CR32","doi-asserted-by":"publisher","unstructured":"Gao J, Li L, Kong P, Bissyand\u00e9 T F, Klein J (2019) Understanding the evolution of android app vulnerabilities. IEEE Trans Reliab:1\u201319. https:\/\/doi.org\/10.1109\/TR.2019.2956690","DOI":"10.1109\/TR.2019.2956690"},{"key":"9978_CR33","doi-asserted-by":"crossref","unstructured":"Gartner (2015) Gartner Says More than 75 Percent of Mobile Applications will Fail Basic Security Tests Through 2015. https:\/\/tinyurl.com\/uavh5nq. Online; accessed 20 January 2020","DOI":"10.1016\/B978-3-437-22083-8.00008-0"},{"key":"9978_CR34","doi-asserted-by":"crossref","unstructured":"Giger E, D\u2019Ambros M, Pinzger M, Gall H C (2012) Method-level bug prediction. In: International Symposium on Empirical Software Engineering and Measurement, pp 171\u2013180","DOI":"10.1145\/2372251.2372285"},{"key":"9978_CR35","doi-asserted-by":"crossref","unstructured":"Gorla A, Tavecchia I, Gross F, Zeller A (2014) Checking app behavior against app descriptions. In: International Conference on Software Engineering, pp 1025\u20131035","DOI":"10.1145\/2568225.2568276"},{"key":"9978_CR36","doi-asserted-by":"crossref","unstructured":"Grano G, Di Sorbo A, Mercaldo F, Visaggio C A, Canfora G, Panichella S (2017) Android apps and user feedback: a dataset for software evolution and quality improvement. In: Proceedings of the 2nd ACM SIGSOFT International Workshop on App Market Analytics, WAMA@ESEC\/SIGSOFT FSE 2017, Paderborn, pp 8\u201311","DOI":"10.1145\/3121264.3121266"},{"key":"9978_CR37","unstructured":"Grissom R J, Kim J J (2005) Effect sizes for research: A broad practical approach, 2nd edn. Lawrence Earlbaum Associates"},{"key":"9978_CR38","doi-asserted-by":"crossref","unstructured":"Guerrouj L, Azad S, Rigby P C (2015) The influence of app churn on app success and stackoverflow discussions. In: International Conference on Software Analysis, Evolution, and Reengineering, pp 321\u2013330","DOI":"10.1109\/SANER.2015.7081842"},{"key":"9978_CR39","doi-asserted-by":"crossref","unstructured":"Harman M, Jia Y, Zhang Y (2012) App store mining and analysis: MSR for app stores. In: Working Conference of Mining Software Repositories, pp 108\u2013111","DOI":"10.1109\/MSR.2012.6224306"},{"key":"9978_CR40","doi-asserted-by":"crossref","unstructured":"Hay R, Tripp O, Pistoia M (2015) Dynamic detection of inter-application communication vulnerabilities in android. In: International Symposium on Software Testing and Analysis, pp 118\u2013128","DOI":"10.1145\/2771783.2771800"},{"issue":"2","key":"9978_CR41","first-page":"65","volume":"6","author":"S Holm","year":"1979","unstructured":"Holm S (1979) A simple sequentially rejective multiple test procedure. Scand J Stat 6(2):65\u201370","journal-title":"Scand J Stat"},{"key":"9978_CR42","doi-asserted-by":"crossref","unstructured":"Islam M R (2014) Numeric rating of apps on google play store by sentiment analysis on user reviews. In: International Conference on Electrical Engineering and Information & Communication Technology. IEEE, pp 1\u20134","DOI":"10.1109\/ICEEICT.2014.6919058"},{"key":"9978_CR43","doi-asserted-by":"crossref","unstructured":"Jimenez M, Papadakis M, Bissyand\u00e9 T F, Klein J (2016) Profiling android vulnerabilities. In: International Conference on Software Quality, Reliability and Security, pp 222\u2013229","DOI":"10.1109\/QRS.2016.34"},{"key":"9978_CR44","doi-asserted-by":"crossref","unstructured":"Johann T, Stanik C, B. A M A, Maalej W (2017) SAFE: A simple approach for feature extraction from app descriptions and app reviews. In: International Requirements Engineering Conference, pp 21\u201330","DOI":"10.1109\/RE.2017.71"},{"key":"9978_CR45","doi-asserted-by":"crossref","unstructured":"Kallis R, Di Sorbo A, Canfora G, Panichella S (2019) Ticket tagger: Machine learning driven issue classification. In: 2019 IEEE International Conference on Software Maintenance and Evolution, pp 406\u2013409","DOI":"10.1109\/ICSME.2019.00070"},{"key":"9978_CR46","doi-asserted-by":"crossref","unstructured":"Kantola D, Chin E, He W, Wagner D A (2012) Reducing attack surfaces for intra-application communication in android. In: Workshop on Security and Privacy in Smartphones and Mobile Devices, Co-located with CCS 2012, pp 69\u201380","DOI":"10.1145\/2381934.2381948"},{"issue":"2","key":"9978_CR47","doi-asserted-by":"publisher","first-page":"176","DOI":"10.7763\/LNSE.2014.V2.118","volume":"2","author":"A Kaur","year":"2014","unstructured":"Kaur A, Kaur I (2014) Empirical evaluation of machine learning algorithms for fault prediction. Lect Notes Softw Eng 2(2):176","journal-title":"Lect Notes Softw Eng"},{"issue":"4","key":"9978_CR48","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1109\/MS.2015.29","volume":"33","author":"H Khalid","year":"2016","unstructured":"Khalid H, Nagappan M, Hassan A E (2016) Examining the relationship between findbugs warnings and app ratings. IEEE Softw 33(4):34\u201339. https:\/\/doi.org\/10.1109\/MS.2015.29","journal-title":"IEEE Softw"},{"key":"9978_CR49","doi-asserted-by":"crossref","unstructured":"Kochhar P S, Thung F, Nagappan N, Zimmermann T, Lo D (2015) Understanding the test automation culture of app developers. In: 8th IEEE International Conference on Software Testing, Verification and Validation, ICST 2015, Graz, Austria, April 13-17, 2015, pp 1\u201310","DOI":"10.1109\/ICST.2015.7102609"},{"issue":"260","key":"9978_CR50","doi-asserted-by":"publisher","first-page":"583","DOI":"10.1080\/01621459.1952.10483441","volume":"47","author":"WH Kruskal","year":"1952","unstructured":"Kruskal W H, Wallis W A (1952) Use of ranks in one-criterion variance analysis. J Amer Stat Assocss 47(260):583\u2013621","journal-title":"J Amer Stat Assocss"},{"key":"9978_CR51","doi-asserted-by":"crossref","unstructured":"Krutz D E, Munaiah N, Meneely A, Malachowsky S A (2016) Examining the relationship between security metrics and user ratings of mobile apps: a case study. In: Proceedings of the International Workshop on App Market Analytics, pp 8\u201314","DOI":"10.1145\/2993259.2993260"},{"key":"9978_CR52","doi-asserted-by":"crossref","unstructured":"Li L, Bartel A, Bissyand\u00e9 T F, Klein J, Le Traon Y, Arzt S, Rasthofer S, Bodden E, Octeau D, McDaniel P (2015) Iccta: Detecting inter-component privacy leaks in android apps. In: IEEE International Conference on Software Engineering, vol 1, pp 280\u2013291","DOI":"10.1109\/ICSE.2015.48"},{"key":"9978_CR53","doi-asserted-by":"crossref","unstructured":"Lu L, Li Z, Wu Z, Lee W, Jiang G (2012) CHEX: statically vetting android apps for component hijacking vulnerabilities. In: the ACM Conference on Computer and Communications Security, pp 229\u2013240","DOI":"10.1145\/2382196.2382223"},{"key":"9978_CR54","doi-asserted-by":"crossref","unstructured":"Lyu Y, Gui J, Wan M, Halfond W G J (2017) An empirical study of local database usage in android applications. In: 2017 IEEE International Conference on Software Maintenance and Evolution, ICSME 2017, Shanghai, China, September 17-22, 2017, pp 444\u2013455","DOI":"10.1109\/ICSME.2017.75"},{"key":"9978_CR55","doi-asserted-by":"crossref","unstructured":"Ma Z, Wang H, Guo Y, Chen X (2016) Libradar: fast and accurate detection of third-party libraries in android apps. In: International Conference on Software Engineering, Companion Volume, pp 653\u2013656","DOI":"10.1145\/2889160.2889178"},{"issue":"3","key":"9978_CR56","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1109\/TSE.2010.60","volume":"37","author":"PK Manadhata","year":"2011","unstructured":"Manadhata P K, Wing J M (2011) An attack surface metric. IEEE Trans Softw Eng 37(3):371\u2013386. https:\/\/doi.org\/10.1109\/TSE.2010.60","journal-title":"IEEE Trans Softw Eng"},{"key":"9978_CR57","doi-asserted-by":"crossref","unstructured":"Minelli R, Lanza M (2013a) Software analytics for mobile applications\u2013insights lessons learned. In: 2013 17th European Conference on Software Maintenance and Reengineering, pp 144\u2013153","DOI":"10.1109\/CSMR.2013.24"},{"key":"9978_CR58","doi-asserted-by":"crossref","unstructured":"Minelli R, Lanza M (2013b) Software analytics for mobile applications-insights & lessons learned. In: 17th European Conference on Software Maintenance and Reengineering, CSMR 2013, Genova, Italy, March 5-8, 2013, pp 144\u2013153","DOI":"10.1109\/CSMR.2013.24"},{"key":"9978_CR59","unstructured":"Montealegre C, Njuguna C R, Malik M I, Hannay P, McAteer I N (2018) Security vulnerabilities in android applications. In: Australian Information Security Management Conference. Security Research Institute, Edith Cowan University, pp 14\u201328"},{"key":"9978_CR60","doi-asserted-by":"crossref","unstructured":"Mutchler P, Safaei Y, Doup\u00e9 A, Mitchell J C (2016) Target fragmentation in android apps. In: 2016 IEEE Security and Privacy Workshops, SP Workshops 2016, San Jose, CA, USA, May 22-26, 2016, pp 204\u2013213","DOI":"10.1109\/SPW.2016.31"},{"key":"9978_CR61","doi-asserted-by":"crossref","unstructured":"Nguyen D-C, Derr E, Backes M, Bugiel S (2019) Short text, large effect: Measuring the impact of user reviews on android app security & privacy. In: 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, pp 555\u2013569","DOI":"10.1109\/SP.2019.00012"},{"key":"9978_CR62","unstructured":"Oltrogge M, Huaman N, Amft S, Acar Y, Backes M, Fahl S (2021) Why eve and mallory still love android: Revisiting tls (in) security in android applications. In: 30th USENIX Security Symposium (USENIX Security 21)"},{"key":"9978_CR63","doi-asserted-by":"crossref","unstructured":"Panichella S, Di Sorbo A, Guzman E, Visaggio C A, Canfora G, Gall H C (2015) How can i improve my app? classifying user reviews for software maintenance and evolution. In: Koschke R, Krinke J, Robillard M P (eds) 2015 IEEE International Conference on Software Maintenance and Evolution, ICSME 2015, Bremen, Germany, September 29 - October 1, 2015. IEEE Computer Society, pp 281\u2013290","DOI":"10.1109\/ICSM.2015.7332474"},{"key":"9978_CR64","doi-asserted-by":"crossref","unstructured":"Panichella S (2018) Summarization techniques for code, change, testing, and user feedback (invited paper). In: Artho C, Ramler R (eds) 2018 IEEE Workshop on Validation, Analysis and Evolution of Software Tests, VST@SANER 2018, Campobasso, Italy, March 20, 2018. IEEE, pp 1\u20135","DOI":"10.1109\/VST.2018.8327148"},{"key":"9978_CR65","doi-asserted-by":"publisher","first-page":"9390","DOI":"10.1109\/ACCESS.2018.2799522","volume":"6","author":"A Papageorgiou","year":"2018","unstructured":"Papageorgiou A, Strigkos M, Politou E A, Alepis E, Solanas A, Patsakis C (2018) Security and privacy analysis of mobile health applications: The alarming state of practice. IEEE Access 6:9390\u20139403. https:\/\/doi.org\/10.1109\/ACCESS.2018.2799522","journal-title":"IEEE Access"},{"key":"9978_CR66","doi-asserted-by":"crossref","unstructured":"Pecorelli F, Catolino G, Ferrucci F, Lucia A D, Palomba F (2020) Testing of mobile applications in the wild: A large-scale empirical study on android apps. In: ICPC \u201920: 28th international conference on program comprehension, seoul, republic of korea, july 13-15, 2020, pp 296\u2013307","DOI":"10.1145\/3387904.3389256"},{"issue":"1","key":"9978_CR67","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/MM.2015.25","volume":"35","author":"C Qian","year":"2015","unstructured":"Qian C, Luo X, Le Y, Gu G (2015) Vulhunter: Toward discovering vulnerabilities in android applications. IEEE Micro 35(1):44\u201353. https:\/\/doi.org\/10.1109\/MM.2015.25","journal-title":"IEEE Micro"},{"issue":"1","key":"9978_CR68","first-page":"81","volume":"1","author":"JR Quinlan","year":"1986","unstructured":"Quinlan J R (1986) Induction of decision trees. Mach Learn 1 (1):81\u2013106","journal-title":"Mach Learn"},{"issue":"6","key":"9978_CR69","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1109\/MS.2014.79","volume":"31","author":"IJM Ruiz","year":"2014","unstructured":"Ruiz I J M, Nagappan M, Adams B, Berger T, Dienst S, Hassan A E (2014) Impact of ad libraries on ratings of android mobile apps. IEEE Softw 31(6):86\u201392. https:\/\/doi.org\/10.1109\/MS.2014.79","journal-title":"IEEE Softw"},{"issue":"6","key":"9978_CR70","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1109\/MS.2015.56","volume":"33","author":"IJM Ruiz","year":"2016","unstructured":"Ruiz I J M, Nagappan M, Adams B, Berger T, Dienst S, Hassan A E (2016) Examining the rating system used in mobile-app stores. IEEE Softw 33(6):86\u201392. https:\/\/doi.org\/10.1109\/MS.2015.56","journal-title":"IEEE Softw"},{"key":"9978_CR71","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1016\/j.jss.2019.06.001","volume":"156","author":"ER Russo","year":"2019","unstructured":"Russo E R, Di Sorbo A, Visaggio C A, Canfora G (2019) Summarizing vulnerabilities\u2019 descriptions to support experts during vulnerability assessment activities. J Syst Softw 156:84\u201399. https:\/\/doi.org\/10.1016\/j.jss.2019.06.001","journal-title":"J Syst Softw"},{"key":"9978_CR72","doi-asserted-by":"crossref","unstructured":"Scandariato R, Walden J (2012) Predicting vulnerable classes in an android application. In: International Workshop on Security Measurements and Metrics, MetriSec \u201912. Association for Computing Machinery, pp 11\u201316","DOI":"10.1145\/2372225.2372231"},{"issue":"3\/4","key":"9978_CR73","doi-asserted-by":"publisher","first-page":"591","DOI":"10.2307\/2333709","volume":"52","author":"SS Shapiro","year":"1965","unstructured":"Shapiro S S, Wilk M B (1965) An analysis of variance test for normality (complete samples). Biometrika 52(3\/4):591\u2013611","journal-title":"Biometrika"},{"key":"9978_CR74","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1016\/j.infsof.2018.05.006","volume":"101","author":"DB Silva","year":"2018","unstructured":"Silva D B, Eler M M, Durelli V H S, Endo A T (2018) Characterizing mobile apps from a source and test code viewpoint. Inf Softw Technol 101:32\u201350. https:\/\/doi.org\/10.1016\/j.infsof.2018.05.006","journal-title":"Inf Softw Technol"},{"key":"9978_CR75","doi-asserted-by":"crossref","unstructured":"Slavin R, Wang X, Hosseini M B, Hester J, Krishnan R, Bhatia J, Breaux T D, Niu J (2016) Toward a framework for detecting privacy policy violations in android application code. In: Dillon L K, Visser W, Williams L (eds) International Conference on Software Engineering. ACM, pp 25\u201336","DOI":"10.1145\/2884781.2884855"},{"key":"9978_CR76","unstructured":"Song W, Huang Q, Huang J (2018) Understanding javascript vulnerabilities in large real-world android applications. IEEE Trans Depend Sec Comput:1\u20131"},{"key":"9978_CR77","doi-asserted-by":"crossref","unstructured":"Sounthiraraj D, Sahs J, Greenwood G, Lin Z, Khan L (2014) Smv-hunter: Large scale, automated detection of SSL\/TLS man-in-the-middle vulnerabilities in android apps. In: 21st Annual Network and Distributed System Security Symposium","DOI":"10.14722\/ndss.2014.23205"},{"key":"9978_CR78","doi-asserted-by":"crossref","unstructured":"Taba S E S, Keivanloo I, Zou Y, Ng J W, Ng T (2014) An exploratory study on the relation between user interface complexity and the perceived quality. In: Web Engineering, International Conference, pp 370\u2013379","DOI":"10.1007\/978-3-319-08245-5_22"},{"key":"9978_CR79","doi-asserted-by":"publisher","first-page":"106290","DOI":"10.1016\/j.infsof.2020.106290","volume":"122","author":"C Tao","year":"2020","unstructured":"Tao C, Guo H, Huang Z (2020) Identifying security issues for mobile applications based on user review summarization. Inf Softw Technol 122:106290. https:\/\/doi.org\/10.1016\/j.infsof.2020.106290","journal-title":"Inf Softw Technol"},{"key":"9978_CR80","doi-asserted-by":"crossref","unstructured":"Taylor V F, Martinovic I (2017a) Short paper: A longitudinal study of financial apps in the google play store. In: Financial Cryptography and Data Security - International Conference, pp 302\u2013309","DOI":"10.1007\/978-3-319-70972-7_16"},{"key":"9978_CR81","doi-asserted-by":"crossref","unstructured":"Taylor V F, Martinovic I (2017b) To update or not to update: Insights from a two-year study of android app evolution. In: ACM on asia conference on computer and communications security, pp 45\u201357","DOI":"10.1145\/3052973.3052990"},{"key":"9978_CR82","doi-asserted-by":"crossref","unstructured":"Thomas D R, Beresford A R, Coudray T, Sutcliffe T, Taylor A (2015a) The lifetime of android API vulnerabilities: Case study on the javascript-to-java interface. In: Security Protocols XXIII - 23rd International Workshop, pp 126\u2013138","DOI":"10.1007\/978-3-319-26096-9_13"},{"key":"9978_CR83","doi-asserted-by":"crossref","unstructured":"Thomas D R, Beresford A R, Rice A C (2015b) Security metrics for the android ecosystem. In: Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, pp 87\u201398","DOI":"10.1145\/2808117.2808118"},{"key":"9978_CR84","doi-asserted-by":"crossref","unstructured":"Tian Y, Nagappan M, Lo D, Hassan A E (2015) What are the characteristics of high-rated apps? A case study on free android applications. In: International Conference on Software Maintenance and Evolution, pp 301\u2013310","DOI":"10.1109\/ICSM.2015.7332476"},{"key":"9978_CR85","doi-asserted-by":"crossref","unstructured":"Tien C-W, Huang T-Y, Huang T-C, Chung W-H, Kuo S-Y (2017) MAS: mobile-apps assessment and analysis system. In: International Conference on Dependable Systems and Networks Workshops, pp 145\u2013148","DOI":"10.1109\/DSN-W.2017.17"},{"key":"9978_CR86","unstructured":"V\u00e1squez M L, Bavota G, Bernal-C\u00e1rdenas C, Penta M D, Oliveto R, Poshyvanyk D (2013) API change and fault proneness: a threat to the success of android apps. In: Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on the Foundations of Software Engineering, pp 477\u2013487"},{"issue":"3","key":"9978_CR87","doi-asserted-by":"publisher","first-page":"582","DOI":"10.1007\/s10664-012-9230-z","volume":"19","author":"ML V\u00e1squez","year":"2014","unstructured":"V\u00e1squez M L, McMillan C, Poshyvanyk D, Grechanik M (2014) On using machine learning to automatically classify software applications into domain categories. Empir Softw Eng 19(3):582\u2013618. https:\/\/doi.org\/10.1007\/s10664-012-9230-z","journal-title":"Empir Softw Eng"},{"key":"9978_CR88","unstructured":"V\u00e1squez M L, Holtzhauer A, Poshyvanyk D (2016) On automatically detecting similar android apps. In: 24th IEEE International Conference on Program Comprehension, ICPC 2016, Austin, TX, USA, May 16-17, 2016, pp 1\u201310"},{"key":"9978_CR89","unstructured":"V\u00e1squez M L, Bavota G, Escobar-Velasquez C (2017) An empirical study on android-related vulnerabilities. In: Proceedings of the 14th International Conference on Mining Software Repositories, MSR 2017, Buenos Aires, Argentina, May 20-28, 2017, pp 2\u201313"},{"key":"9978_CR90","doi-asserted-by":"crossref","unstructured":"Votipka D, Stevens R, Redmiles E M, Hu J, Mazurek M L (2018) Hackers vs. testers: A comparison of software vulnerability discovery processes. In: 2018 IEEE symposium on security and privacy, SP 2018, proceedings, 21-23 may 2018, san francisco, california, USA, pp 374\u2013391","DOI":"10.1109\/SP.2018.00003"},{"key":"9978_CR91","doi-asserted-by":"crossref","unstructured":"Wang H, Li H, Li L, Guo Y, Xu G (2018) Why are android apps removed from google play?: a large-scale empirical study. In: Zaidman A, Kamei Y, Hill E (eds) Proceedings of the 15th International Conference on Mining Software Repositories, MSR 2018, Gothenburg, Sweden, May 28-29, 2018. ACM, pp 231\u2013242","DOI":"10.1145\/3196398.3196412"},{"key":"9978_CR92","doi-asserted-by":"crossref","unstructured":"Watanabe T, Akiyama M, Kanei F, Shioji E, Takata Y, Sun B, Ishii Y, Shibahara T, Yagi T, Mori T (2017) Understanding the origins of mobile app vulnerabilities: a large-scale measurement study of free and paid apps. In: International Conference on Mining Software Repositories, pp 14\u201324","DOI":"10.1109\/MSR.2017.23"},{"key":"9978_CR93","doi-asserted-by":"crossref","unstructured":"Wu D, Chang R K C (2014) Analyzing android browser apps for file: \/\/ vulnerabilities. In: Information Security - International Conference, pp 345\u2013363","DOI":"10.1007\/978-3-319-13257-0_20"},{"issue":"2","key":"9978_CR94","doi-asserted-by":"publisher","first-page":"38:1","DOI":"10.1145\/2963145","volume":"49","author":"M Xu","year":"2016","unstructured":"Xu M, Song C, Ji Y, Shih M-W, Lu K, Zheng C, Duan R, Jang Y, Lee B, Qian C, Lee S, Kim T (2016) Toward engineering a secure android ecosystem: A survey of existing techniques. ACM Comput Surv 49(2):38:1\u201338:47. https:\/\/doi.org\/10.1145\/2963145","journal-title":"ACM Comput Surv"},{"key":"9978_CR95","doi-asserted-by":"crossref","unstructured":"Yang Z, Yang M, Zhang Y, Gu G, Ning P, Wang X S (2013) Appintent: analyzing sensitive data transmission in android for privacy leakage detection. In: 2013 ACM SIGSAC Conference on Computer and Communications Security, CCS\u201913, Berlin, Germany, November 4-8, 2013, pp 1043\u20131054","DOI":"10.1145\/2508859.2516676"},{"key":"9978_CR96","doi-asserted-by":"crossref","unstructured":"Yang W, Zhang Y, Li J, Liu H, Wang Q, Zhang Y, Gu D (2017) Show me the money! finding flawed implementations of third-party in-app payment in android apps. In: Annual Network and Distributed System Security Symposium","DOI":"10.14722\/ndss.2017.23091"},{"key":"9978_CR97","doi-asserted-by":"publisher","unstructured":"Yeom C, Won Y (2019) Vulnerability evaluation method through correlation analysis of android applications. Sustainability 11(23). https:\/\/doi.org\/10.3390\/su11236637","DOI":"10.3390\/su11236637"},{"key":"9978_CR98","doi-asserted-by":"publisher","first-page":"106311","DOI":"10.1016\/j.infsof.2020.106311","volume":"123","author":"F Zampetti","year":"2020","unstructured":"Zampetti F, Di Sorbo A, Visaggio C A, Canfora G, Di Penta M (2020) Demystifying the adoption of behavior-driven development in open source projects. Inf Softw Technol 123:106311. https:\/\/doi.org\/10.1016\/j.infsof.2020.106311","journal-title":"Inf Softw Technol"},{"key":"9978_CR99","unstructured":"Zhou Y, Jiang X (2013) Detecting passive content leaks and pollution in android applications. In: Annual Network and Distributed System Security Symposium"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-021-09978-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-021-09978-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-021-09978-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,23]],"date-time":"2021-06-23T12:48:29Z","timestamp":1624452509000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-021-09978-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,8]]},"references-count":99,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,7]]}},"alternative-id":["9978"],"URL":"https:\/\/doi.org\/10.1007\/s10664-021-09978-0","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"type":"print","value":"1382-3256"},{"type":"electronic","value":"1573-7616"}],"subject":[],"published":{"date-parts":[[2021,6,8]]},"assertion":[{"value":"13 May 2021","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 June 2021","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"78"}}