JNFuzz-Droid: A Lightweight Fuzzing and Taint Analysis Framework for Android Native Code
Jianchao Cao, Fan Guo, Yanwen Qu · 2024
The need to account for native code in Android apps is becoming urgent as the usage of native code is growing with both benign and malicious apps. However, most current state-of-the-art analysis tools cannot effectively analyze the data-flow behavior of native code. On the one hand, existing native dynamic analysis tools are primarily based on test input generation tools to analyze Android apps and are therefore unable to locate native code quickly. On the other hand, existing native static analysis tools are based on symbolic execution to analyze native code and are therefore limited by the path and state explosion issues. In order to effectively analyze the behavior of sensitive data in the native world, we first proposed INFuzz, a fuzzing module for Android native libraries based on Client/Server architecture. Then, we propose INFuzz-Droid, a lightweight automated fuzzing and taint analysis framework for Android native code, based on this. INFuzz-Droid first locates the Android native code to which sensitive data is passed and then uses INFuzz to perform fuzzing the native code to improve code coverage while analyzing the data flow in native code with a dynamic binary tool. Experimental results on benchmarks and real-world apps show that IN Fuzz-Droid can effectively detect the leakage or transfer of sensitive data in app native code and outperforms the state-of-the-art native analysis tools.