iLand: An Instruction-Level Dynamic Binary Instrumentation Framework for iOS
Kaitao Xie, Yizhuo Wang, Xiaolong Bai
摘要
Dynamic binary instrumentation (DBI) enables monitoring and modification of executing programs and forms the foundation for a range of program analysis and security testing. On iOS, however, no DBI is available for non-jailbroken devices. Existing approaches on other platforms (e.g., Android) rely on JIT compilation, which is prohibited by the iOS sandbox. The limited CPU and memory resources of mobile devices further constrain the practical deployment of DBI.
We propose iLand, a novel instruction-level DBI framework for iOS. Instead of JIT compilation, it translates instructions into predefined micro-operations and interprets using precompiled atomic execution units. To reduce CPU and memory overhead, it employs application-only emulation: only the app's code is interpreted, while system libraries run natively. We implement iLand as a standard sandboxed iOS app capable of emulating other apps. It preserves the emulated apps' original functionality and user experience such as dynamic UI rendering, real-time interaction, live video streaming.
Based on this DBI framework, we further implemented an instruction-level dynamic tracing tool and used it to study policy-violation behaviors on 60 top-ranked App Store apps. We found that 13 (21%) apps are still invoking private APIs, of which 2 invoke APIs explicitly prohibited by Apple. Our analysis further revealed the new and stealthy methods employed by apps to evade Apple's App Review. In particular, in 15 (25%) of the apps, we observed a new way to collect sensitive information by direct invocation of the SVC instruction.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Binary rewriting without control flow recoveryGregory J. Duck, Xiang Gao, Abhik RoychoudhuryPLDI 2020 · 被引用 77 次
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang 等USENIX Security 2017 · 被引用 36 次
- Different is Good: Detecting the Use of Uninitialized Variables through Differential ReplayMengchen Cao, Xiantong Hou, Tao Wang, Hunter Qu 等CCS 2019 · 被引用 11 次
- CydiOS: A Model-Based Testing Framework for iOS AppsShuohan Wu, Jianfeng Li, Hao Zhou, Yongsheng Fang 等ISSTA 2023 · 被引用 4 次
- Trinity: High-Performance Mobile Emulation through Graphics ProjectionDi Gao, Hao Lin, Zhenhua Li, Chengen Huang 等OSDI 2022
相关 Paper
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie 等USENIX Security 2024 · 被引用 6 次
- SandScout: Automatic Detection of Flaws in iOS Sandbox ProfilesLuke Deshotels, Razvan Deaconescu, Mihai Chiroiu, Lucas Davi 等CCS 2016 · 被引用 20 次
- OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOSXiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang 等NDSS 2018 · 被引用 34 次
- AirTaint: Making Dynamic Taint Analysis Faster and EasierQian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia 等S&P 2024 · 被引用 11 次
- Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOSLuke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu 等S&P 2020 · 被引用 10 次
