NCScope: hardware-assisted analyzer for native code in Android apps
Hao Zhou, Shuohan Wu, Xiapu Luo, Ting Wang, Yajin Zhou, Chao Zhang, Haipeng Cai
Abstract
More and more Android apps implement their functionalities in native code, so does malware. Although various approaches have been designed to analyze the native code used by apps, they usually generate incomplete and biased results due to their limitations in obtaining and analyzing high-fidelity execution traces and memory data with low overheads. To fill the gap, in this paper, we propose and develop a novel hardware-assisted analyzer for native code in apps. We leverage ETM, a hardware feature of ARM platform, and eBPF, a kernel component of Android system, to collect real execution traces and relevant memory data of target apps, and design new methods to scrutinize native code according to the collected data. To show the unique capability of NCScope, we apply it to four applications that cannot be accomplished by existing tools, including systematic studies on self-protection and anti-analysis mechanisms implemented in native code of apps, analysis of memory corruption in native code, and identification of performance differences between functions in native code. The results uncover that only 26.8% of the analyzed financial apps implement self-protection methods in native code, implying that the security of financial apps is far from expected. Meanwhile, 78.3% of the malicious apps under analysis have anti-analysis behaviors, suggesting that NCScope is very useful to malware analysis. Moreover, NCScope can effectively detect bugs in native code and identify performance differences.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3ae27707-71e8-4944-8578-e665d0e345a7Cited by top-tier papers7
- MOAT: Towards Safe BPF Kernel ExtensionHongyi Lu, Shuai Wang, Yechang Wu, Wanning He et al.USENIX Security 2024 · 18 citations
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan et al.USENIX Security 2024 · 7 citations
- Alligator in Vest: A Practical Failure-Diagnosis Framework via Arm Hardware FeaturesYiming Zhang, Yuxin Hu, Haonan Li, Wenxuan Shi et al.ISSTA 2023 · 4 citations
- Interactive Cross-Language Pointer Analysis for Resolving Native Code in Java ProgramsChenxi Zhang, Yufei Liang, Tian Tan, Chang Xu et al.ICSE 2025 · 1 citation
- Intent-aware Fuzzing for Android Hardened ApplicationSeongyun Jeong, Minseong Choi, Haehyun Cho, Seokwoo Choi et al.CCS 2025 · 1 citation
Builds on17
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 253 citations
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 188 citations
- Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing PolicyVitor Monte Afonso, Paulo L. de Geus, Antonio Bianchi, Yanick Fratantonio et al.NDSS 2016 · 119 citations
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen et al.CCS 2018 · 93 citations
Related papers
- Ninja: Towards Transparent Tracing and Debugging on ARMZhenyu Ning, Fengwei ZhangUSENIX Security 2017 · 62 citations
- NativeSummary: Summarizing Native Binary Code for Inter-language Static Analysis of Android AppsJikai Wang, Haoyu WangISSTA 2024 · 8 citations
- JuCify: A Step Towards Android Code Unification for Enhanced Static AnalysisJordan Samhi, Jun Gao, Nadia Daoudi, Pierre Graux et al.ICSE 2022 · 43 citations
- Fine-Grained Privacy Leakage Detection in OpenHarmony AppsAohan Mei, Guangliang Yang, Xinming Guo, Yi Wang et al.ISSTA 2026
- Happer: Unpacking Android Apps via a Hardware-Assisted ApproachLei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou et al.S&P 2021 · 29 citations
