JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native Code
Fengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen, Xiaosong Zhang
摘要
Android allows application developers to use native language (C/C++) to implement a part or the complete program. Recent research and our own statistics show that native payloads are commonly used in both benign and malicious apps. Current state-of-the-art Android static analysis tools, such as Amandroid, FlowDroid, DroidSafe, Ic-cTA, and CHEX avoid handling native method invocation and apply conservative models for their data-flow behavior. None of those tools have the capability to capture the inter-language dataflow. We propose a new approach to conduct inter-language dataflow analysis for security vetting of Android apps and build an analysis framework, called JN-SAF to compute flow and context-sensitive inter-language points-to information in an efficient way. We show that: 1) Precise and efficient inter-language dataflow analysis is completely feasible with support of a summary-based bottom-up dataflow analysis (SBDA) algorithm, 2) A comprehensive model of Java Native Interface (JNI) and Native Development Kit (NDK) for binary analysis is essential as none of the existing binary analysis frameworks is able to handle Android binaries, 3) JN-SAF is capable of capturing inter-language security issues in real-world Android apps as demonstrated by our evaluation result.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper19
- JuCify: A Step Towards Android Code Unification for Enhanced Static AnalysisJordan Samhi, Jun Gao, Nadia Daoudi, Pierre Graux 等ICSE 2022 · 被引用 43 次
- Broadening Horizons of Multilingual Static Analysis: Semantic Summary Extraction from C Code for JNI Program AnalysisSungho Lee, Hyogun Lee, Sukyoung RyuASE 2020 · 被引用 29 次
- Identifying Java calls in native code via binary scanningGeorge Fourtounis, Leonidas Triantafyllou, Yannis SmaragdakisISSTA 2020 · 被引用 23 次
- On the vulnerability proneness of multilingual codeWen Li, Li Li, Haipeng CaiFSE 2022 · 被引用 22 次
- Demystifying Diehard Android AppsHao Zhou, Haoyu Wang, Yajin Zhou, Xiapu Luo 等ASE 2020 · 被引用 17 次
它引用的顶会 Paper6
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 被引用 188 次
- Harvesting Runtime Values in Android Applications That Feature Anti-Analysis TechniquesSiegfried Rasthofer, Steven Arzt, Marc Miltenberger, Eric BoddenNDSS 2016 · 被引用 157 次
- Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing PolicyVitor Monte Afonso, Paulo L. de Geus, Antonio Bianchi, Yanick Fratantonio 等NDSS 2016 · 被引用 119 次
- Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ARTLei Xue, Yajin Zhou, Ting Chen, Xiapu Luo 等USENIX Security 2017 · 被引用 81 次
相关 Paper
- NativeSummary: Summarizing Native Binary Code for Inter-language Static Analysis of Android AppsJikai Wang, Haoyu WangISSTA 2024 · 被引用 8 次
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 被引用 1 次
- DocFlow: Extracting Taint Specifications from Software DocumentationMarcos Tileria, Jorge Blasco, Santanu Kumar DashICSE 2024 · 被引用 5 次
- GlassWing: A Tailored Static Analysis Approach for Flutter Android AppsXiangyu Zhang, Yucheng Su, Lingling Fan, Miaoying Cai 等ASE 2025
- RAICC: Revealing Atypical Inter-Component Communication in Android AppsJordan Samhi, Alexandre Bartel, Tegawendé F. Bissyandé, Jacques KleinICSE 2021 · 被引用 3 次
