JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native Code

JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native Code
复制标题

DOI:
10.1145/3243734.3243835
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Fengguo Wei;Xingwei Lin;Xinming Ou;Ting Chen;Xiaosong Zhang
Fengguo Wei;Xingwei Lin;Xinming Ou;Ting Chen;Xiaosong Zhang
中科院分区:
其他
文献类型:
--
作者:
Fengguo Wei;Xingwei Lin;Xinming Ou;Ting Chen;Xiaosong Zhang

文献摘要

被引文献

相似文献

Android允许应用程序开发者使用本地语言(C/ c++)来实现部分或完整的程序。最近的研究和我们自己的统计数据表明,原生有效负载通常用于良性和恶意应用程序。当前最先进的Android静态分析工具(如Amandroid、FlowDroid、DroidSafe、IccTA和CHEX)避免处理本机方法调用,并对其数据流行为应用保守模型。这些工具都不具备捕获语言间数据流的能力。我们提出了一种针对Android应用安全审查进行跨语言数据流分析的新方法,并构建了一个称为JN-SAF的分析框架,以高效的方式计算流和上下文敏感的跨语言点信息。我们展示了:1)在基于摘要的自底向上数据流分析(SBDA)算法的支持下,精确高效的语言间数据流分析是完全可行的。2)Java Native Interface (JNI)和Native Development Kit (NDK)的综合模型用于二进制分析是必不可少的,因为现有的二进制分析框架都无法处理Android二进制文件。3)我们的评估结果表明,JN-SAF能够捕获真实Android应用程序中的语言间安全问题。
Android allows application developers to use native language (C/C++) to implement a part or the complete program. Recent research and our own statistics show that native payloads are commonly used in both benign and malicious apps. Current state-of-the-art Android static analysis tools, such as Amandroid, FlowDroid, DroidSafe, IccTA, and CHEX avoid handling native method invocation and apply conservative models for their data-flow behavior. None of those tools have capability to capture the inter-language dataflow. We propose a new approach to conduct inter-language dataflow analysis for security vetting of Android apps, and build an analysis framework, called JN-SAF to compute flow and context-sensitive inter-language points-to information in an efficient way. We show that: 1) Precise and efficient inter-language dataflow analysis is completely feasible with support of a summary-based bottom-up dataflow analysis (SBDA) algorithm, 2) A comprehensive model of Java Native Interface (JNI) and Native Development Kit (NDK) for binary analysis is essential as none of the existing binary analysis frameworks is able to handle Android binaries, 3) JN-SAF is capable of capturing inter-language security issues in real-world Android apps as demonstrated by our evaluation result.