iLand: An Instruction-Level Dynamic Binary Instrumentation Framework for iOS
Kaitao Xie, Yizhuo Wang, Xiaolong Bai
Abstract
Dynamic binary instrumentation (DBI) enables monitoring and modification of executing programs and forms the foundation for a range of program analysis and security testing. On iOS, however, no DBI is available for non-jailbroken devices. Existing approaches on other platforms (e.g., Android) rely on JIT compilation, which is prohibited by the iOS sandbox. The limited CPU and memory resources of mobile devices further constrain the practical deployment of DBI.
We propose iLand, a novel instruction-level DBI framework for iOS. Instead of JIT compilation, it translates instructions into predefined micro-operations and interprets using precompiled atomic execution units. To reduce CPU and memory overhead, it employs application-only emulation: only the app's code is interpreted, while system libraries run natively. We implement iLand as a standard sandboxed iOS app capable of emulating other apps. It preserves the emulated apps' original functionality and user experience such as dynamic UI rendering, real-time interaction, live video streaming.
Based on this DBI framework, we further implemented an instruction-level dynamic tracing tool and used it to study policy-violation behaviors on 60 top-ranked App Store apps. We found that 13 (21%) apps are still invoking private APIs, of which 2 invoke APIs explicitly prohibited by Apple. Our analysis further revealed the new and stealthy methods employed by apps to evade Apple's App Review. In particular, in 15 (25%) of the apps, we observed a new way to collect sensitive information by direct invocation of the SVC instruction.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ff83ee7e-ba70-4b0d-844b-00a5ac7dcb0bBuilds on5
- Binary rewriting without control flow recoveryGregory J. Duck, Xiang Gao, Abhik RoychoudhuryPLDI 2020 · 77 citations
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang et al.USENIX Security 2017 · 36 citations
- Different is Good: Detecting the Use of Uninitialized Variables through Differential ReplayMengchen Cao, Xiantong Hou, Tao Wang, Hunter Qu et al.CCS 2019 · 11 citations
- CydiOS: A Model-Based Testing Framework for iOS AppsShuohan Wu, Jianfeng Li, Hao Zhou, Yongsheng Fang et al.ISSTA 2023 · 4 citations
- Trinity: High-Performance Mobile Emulation through Graphics ProjectionDi Gao, Hao Lin, Zhenhua Li, Chengen Huang et al.OSDI 2022
Related papers
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie et al.USENIX Security 2024 · 6 citations
- SandScout: Automatic Detection of Flaws in iOS Sandbox ProfilesLuke Deshotels, Razvan Deaconescu, Mihai Chiroiu, Lucas Davi et al.CCS 2016 · 20 citations
- OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOSXiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang et al.NDSS 2018 · 34 citations
- AirTaint: Making Dynamic Taint Analysis Faster and EasierQian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia et al.S&P 2024 · 11 citations
- Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOSLuke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu et al.S&P 2020 · 10 citations
