• Home
  • Search
  • OATs’inside : Retrieving Object Behaviors From Native-based Obfuscated Android Applications
  • https://doi.org/10.1145/3584975Copy DOI Icon

OATs’inside : Retrieving Object Behaviors From Native-based Obfuscated Android Applications

Show More
  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • References
  • Similar Papers
Abstract

Analyzing Android applications is essential to review proprietary code and to understand malware behaviors. However, Android applications use obfuscation techniques to slow down this process. These obfuscation techniques are increasingly based on native code. In this article, we propose OATs’inside , a new analysis tool that focuses on high-level behaviors to circumvent native obfuscation techniques transparently. The targeted high-level behaviors are object-level behaviors, i.e., actions performed on Java objects (e.g., field accesses, method calls), regardless of whether these actions are performed using Java or native code. Our system uses a hybrid approach based on dynamic monitoring and trace-based symbolic execution to output control flow graphs (CFGs), 27 pages. for each method of the analyzed application. CFGs are composed of Java-like actions enriched with condition expressions and dataflows between actions, giving an understandable representation of any code, even those fully native. OATs’inside spares users the need to dive into low-level instructions, which are difficult to reverse engineer. We extensively compare OATs’inside functionalities against state-of-the-art tools to highlight the benefit when observing native operations. Our experiments are conducted on a real smartphone: We discuss the performance impact of OATs’inside , and we demonstrate its practical use on applications containing anti-debugging techniques provided by the OWASP foundation. We also evaluate the robustness of OATs’inside using obfuscated unit tests using the Tigress obfuscator.

Loading PDF

Similar Papers
  • Research Article

Bridging the Compliance Gap: Effective and Efficient Detection of Non-Compliant Behaviors in Android Applications

  • Aug 01, 2026
  • Tsinghua Science and Technology
  • Runqi Fan +5
  • Conference Article
  • Citations61

Analysis of Android Applications' Permissions

  • Jun 01, 2012
  • Ryan Johnson +3
  • Conference Article
  • Citations16

Detecting Android application malicious behaviors based on the analysis of control flows and data flows

  • Oct 13, 2017
  • Peter Zegzhda +3
  • Research Article
  • Citations10

Secure cloud model for intellectual privacy protection of arithmetic expressions in source codes using data obfuscation techniques

  • Apr 26, 2022
  • Theoretical Computer Science
  • Pallavi Ahire +1
  • Conference Article
  • Citations28

SATURN - Software Deobfuscation Framework Based On LLVM

  • Nov 15, 2019
  • Peter Garba +1
  • Conference Article
  • Citations8

AEON

  • Mar 13, 2018
  • D Geethanjali +3
  • Book Chapter
  • Citations8

Protecting Android Apps Against Reverse Engineering by the Use of the Native Code

  • Jan 01, 2015
  • Mykola Protsenko +1
  • Conference Article
  • Citations2

Research on Source Code Static Detection Method Based on Android Application Particularity

  • Feb 24, 2023
  • Jie Zhang +3
  • PDF
  • Book Chapter
  • Citations5

Combating Control Flow Linearization

  • Jan 01, 2017
  • Julian Kirsch +4
  • Conference Article
  • Citations101

NativeGuard

  • Jul 23, 2014
  • Mengtao Sun +1
  • Research Article

Analysis of Android Applications Using Big Data Analytics

  • Jan 01, 2020
  • International Journal of Computing Programming and Database Management
  • Thanneeru Madhu
  • Research Article

Automated System for Numerical Similarity Evaluation of Android Applications

  • Jul 11, 2024
  • Russian Digital Libraries Journal
  • Valery Vladimirovich Petrov
  • Conference Article
  • Citations19

Forced-Path Execution for Android Applications on x86 Platforms

  • Jun 01, 2013
  • Ryan Johnson +1
  • Book Chapter
  • Citations5

An Operational Semantics for Android Applications

  • Jan 01, 2016
  • Mohamed A El-Zawawy
  • Research Article
  • Citations50

Toward a more dependable hybrid analysis of android malware using aspect-oriented programming

  • Nov 21, 2017
  • Computers & Security
  • Aisha I Ali-Gombe +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.