NCScope: hardware-assisted analyzer for native code in Android apps
Hao Zhou, Shuohan Wu, Xiapu Luo, Ting Wang, Yajin Zhou, Chao Zhang, Haipeng Cai
摘要
More and more Android apps implement their functionalities in native code, so does malware. Although various approaches have been designed to analyze the native code used by apps, they usually generate incomplete and biased results due to their limitations in obtaining and analyzing high-fidelity execution traces and memory data with low overheads. To fill the gap, in this paper, we propose and develop a novel hardware-assisted analyzer for native code in apps. We leverage ETM, a hardware feature of ARM platform, and eBPF, a kernel component of Android system, to collect real execution traces and relevant memory data of target apps, and design new methods to scrutinize native code according to the collected data. To show the unique capability of NCScope, we apply it to four applications that cannot be accomplished by existing tools, including systematic studies on self-protection and anti-analysis mechanisms implemented in native code of apps, analysis of memory corruption in native code, and identification of performance differences between functions in native code. The results uncover that only 26.8% of the analyzed financial apps implement self-protection methods in native code, implying that the security of financial apps is far from expected. Meanwhile, 78.3% of the malicious apps under analysis have anti-analysis behaviors, suggesting that NCScope is very useful to malware analysis. Moreover, NCScope can effectively detect bugs in native code and identify performance differences.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- MOAT: Towards Safe BPF Kernel ExtensionHongyi Lu, Shuai Wang, Yechang Wu, Wanning He 等USENIX Security 2024 · 被引用 18 次
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan 等USENIX Security 2024 · 被引用 7 次
- Alligator in Vest: A Practical Failure-Diagnosis Framework via Arm Hardware FeaturesYiming Zhang, Yuxin Hu, Haonan Li, Wenxuan Shi 等ISSTA 2023 · 被引用 4 次
- Interactive Cross-Language Pointer Analysis for Resolving Native Code in Java ProgramsChenxi Zhang, Yufei Liang, Tian Tan, Chang Xu 等ICSE 2025 · 被引用 1 次
- Intent-aware Fuzzing for Android Hardened ApplicationSeongyun Jeong, Minseong Choi, Haehyun Cho, Seokwoo Choi 等CCS 2025 · 被引用 1 次
它引用的顶会 Paper17
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 被引用 253 次
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 被引用 188 次
- Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing PolicyVitor Monte Afonso, Paulo L. de Geus, Antonio Bianchi, Yanick Fratantonio 等NDSS 2016 · 被引用 119 次
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen 等CCS 2018 · 被引用 93 次
相关 Paper
- Ninja: Towards Transparent Tracing and Debugging on ARMZhenyu Ning, Fengwei ZhangUSENIX Security 2017 · 被引用 62 次
- NativeSummary: Summarizing Native Binary Code for Inter-language Static Analysis of Android AppsJikai Wang, Haoyu WangISSTA 2024 · 被引用 8 次
- JuCify: A Step Towards Android Code Unification for Enhanced Static AnalysisJordan Samhi, Jun Gao, Nadia Daoudi, Pierre Graux 等ICSE 2022 · 被引用 43 次
- Fine-Grained Privacy Leakage Detection in OpenHarmony AppsAohan Mei, Guangliang Yang, Xinming Guo, Yi Wang 等ISSTA 2026
- Happer: Unpacking Android Apps via a Hardware-Assisted ApproachLei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou 等S&P 2021 · 被引用 29 次
