Towards Global Matches for Third-Party Library Detection in Android
Lige Zhan, Jiang Ming, Chenke Luo, Guojun Peng, Jianming Fu
Abstract
The detection of third-party libraries (TPLs) is pivotal in upholding the security of Android supply chains. A significant hurdle in this domain pertains to ensuring accurate detection, particularly in the face of prevalent code obfuscation techniques. Recently, multiple research endeavors have advocated for the adoption of fuzzy library signatures to accommodate specific code features that can be affected by code obfuscation. Despite the potential promise of this approach, the use of such abstractions often results in the identification of multiple candidates that bear a striking resemblance. Unfortunately, prevailing methodologies tend to rely on local maxima of similarity matches, disregarding the broader contextual knowledge encapsulated within surrounding classes. This oversight culminates in suboptimal matching outcomes.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- An Empirical Study on the Robustness of Android Third-Party Library Detection Tools Against Advanced ObfuscationDahan Pan, Zhuohao Zhang, Yunjia Min, Runhan Feng et al.ICSE 2026
- Beyond Fuzzy Matching: Constraint-Guided Patch Presence Testing for Obfuscated Java BinariesLige Zhan, Jiang Ming, Chenke Luo, Letian Sha et al.ICSE 2026
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan et al.USENIX Security 2023
- Precise and Efficient Patch Presence Test for Android Applications against Code ObfuscationZifan Xie, Ming Wen, Haoxiang Jia, Xiaochen Guo et al.ISSTA 2023 · 12 citations
- Automated Third-Party Library Detection for Android Applications: Are We There Yet?Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen et al.ASE 2020 · 55 citations
