An Empirical Study on the Robustness of Android Third-Party Library Detection Tools Against Advanced Obfuscation
Dahan Pan, Zhuohao Zhang, Yunjia Min, Runhan Feng, Yuanyuan Zhang
摘要
Third-party libraries (TPLs) play a crucial role in Android app development by providing reusable functionalities, improving development efficiency, and reducing time-to-market. However, detecting and analyzing TPLs is essential, as their vulnerabilities, outdated versions, or malicious modifications can introduce security risks and compromise the integrity of Android apps. Existing TPL detection approaches struggle against code obfuscation, a prevalent practice in Android apps. While prior research has explored obfuscation-resistant detection methods, they largely overlook advanced obfuscation techniques such as package hierarchy obfuscation.
To bridge this gap, we first investigate the prevalence of advanced obfuscation in contemporary Android apps using ObfDetector, a novel static analysis tool capable of detecting identifier renaming, package hierarchy obfuscation, and code optimization. Our large-scale study on 77,504 closed-source Google Play apps and 619 widely used apps reveals extensive obfuscation adoption. We further evaluate the resilience of state-of-the-art TPL detection tools under realistic obfuscation conditions using a newly constructed benchmark dataset, exposing significant performance deficiencies, with F1-scores dropping below 50% for library-level detection and under 10% for version-level identification. Finally, we conduct a systematic failure analysis to uncover key architectural limitations in existing TPL detection frameworks and propose design guidelines for next-generation detection tools. We release our obfuscation detection tool and benchmark dataset to support further research in Android security.
• Software and its engineering → Software libraries and repositories.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 被引用 345 次
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu 等ICSE 2021 · 被引用 85 次
- Automated Third-Party Library Detection for Android Applications: Are We There Yet?Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen 等ASE 2020 · 被引用 55 次
- Automated Detection of Password Leakage from Public GitHub RepositoriesRunhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan ZhangICSE 2022 · 被引用 36 次
相关 Paper
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan 等USENIX Security 2023
- How Does Code Optimization Impact Third-party Library Detection for Android Applications?Zifan Xie, Ming Wen, Tinghan Li, Yiding Zhu 等ASE 2024 · 被引用 3 次
- Towards Global Matches for Third-Party Library Detection in AndroidLige Zhan, Jiang Ming, Chenke Luo, Guojun Peng 等ICSE 2026
- Precise and Efficient Patch Presence Test for Android Applications against Code ObfuscationZifan Xie, Ming Wen, Haoxiang Jia, Xiaochen Guo 等ISSTA 2023 · 被引用 12 次
- Beyond Fuzzy Matching: Constraint-Guided Patch Presence Testing for Obfuscated Java BinariesLige Zhan, Jiang Ming, Chenke Luo, Letian Sha 等ICSE 2026
