Automated Hybrid Analysis of Android Malware through Augmenting Fuzzing with Forced Execution

被引:17
|
作者
Wang, Xiaolei [1 ]
Yang, Yuexiang [1 ]
Zhu, Sencun [2 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Changsha 410073, Hunan, Peoples R China
[2] Penn State Univ, Coll Informat Sci & Technol, Dept Comp Sci & Engn, State Coll, PA 16801 USA
关键词
Malware; Fuzzing; Computer crashes; Instruments; Mobile computing; Dynamics; Android; malware; dynamic analysis; fuzzing; forced execution;
D O I
10.1109/TMC.2018.2886881
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Automatically triggering malicious behaviors is an essential step to understand malware for developing effective solutions. Existing automated dynamic analysis approaches usually try to trigger the malicious behaviors by relying on simple fuzzing or complex input generation techniques (e.g., concolic execution). However, advanced malware often adopt various evasion techniques to hide malicious behaviors, e.g., by introducing complex condition checks which are very hard to trigger. In this paper, we propose a new approach named DirectDroid, which bypasses related checks through on-demand forced execution while adopting fuzzing to feed the necessary program input. In this way, many hidden malicious behaviors can be successfully triggered. To ensure the normal execution towards the malicious behaviors, DirectDroid also largely handles potential program crashes caused by forced execution. Finally, we implement a prototype of DirectDroid and evaluate it against 951 recent malware samples. Our experiment results show that DirectDroid can trigger many more malicious behaviors than several previous works, even when crashes happened. Our further analysis shows that DirectDroid has a low false positive rate even though it adopts forced execution.
引用
收藏
页码:2768 / 2782
页数:15
相关论文
共 39 条
  • [31] Droid-AntiRM: Taming Control Flow Anti-analysis to Support Automated Dynamic Analysis of Android Malware
    Wang, Xiaolei
    Zhu, Sencun
    Zhou, Dehua
    Yang, Yuexiang
    33RD ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2017), 2017, : 350 - 361
  • [32] Novel Android Malware Detection Method Based on Multi-dimensional Hybrid Features Extraction and Analysis
    Li, Yue
    Xu, Guangquan
    Xian, Hequn
    Rao, Longlong
    Shi, Jiangang
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2019, 25 (03): : 637 - 647
  • [33] Comprehensive Android Malware Detection: Leveraging Machine Learning and Sandboxing Techniques through Static and Dynamic Analysis
    Bhooshan, Prashant
    Darshan, Shiva S. L.
    Sonkar, Nidhi
    2024 IEEE 21ST INTERNATIONAL CONFERENCE ON MOBILE AD-HOC AND SMART SYSTEMS, MASS 2024, 2024, : 580 - 585
  • [34] Augmenting feature model through customer preference mining by hybrid sentiment analysis
    Zhou, Feng
    Jiao, Jianxin Roger
    Yang, Xi Jessie
    Lei, Baiying
    EXPERT SYSTEMS WITH APPLICATIONS, 2017, 89 : 306 - 317
  • [35] Androshield: Automated android applications vulnerability detection, a hybrid static and dynamic analysis approach
    Amin A.
    Eldessouki A.
    Magdy M.T.
    Abdeen N.
    Hindy H.
    Hegazy I.
    Information (Switzerland), 2019, 10 (10):
  • [36] AndroShield: Automated Android Applications Vulnerability Detection, a Hybrid Static and Dynamic Analysis Approach
    Amin, Amr
    Eldessouki, Amgad
    Magdy, Menna Tullah
    Abdeen, Nouran
    Hindy, Hanan
    Hegazy, Islam
    INFORMATION, 2019, 10 (10)
  • [37] A Semi-Automated Explainability-Driven Approach for Malware Analysis through Deep Learning
    Iadarola, Giacomo
    Casolare, Rosangela
    Martinelli, Fabio
    Mercaldo, Francesco
    Peluso, Christian
    Santone, Antonella
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [38] Forced convection analysis of Williamson-based magnetized hybrid nanofluid flow through a porous medium: Nonsimilar modeling
    Farooq, Umer
    Safeer, Musawara
    Cui, Jifeng
    Hussain, Muzamil
    Naheed, Nitasha
    NUMERICAL HEAT TRANSFER PART B-FUNDAMENTALS, 2024,
  • [39] Transient wave scattering and forced response analysis of damaged composite beams through a hybrid finite element-wave based method
    Mallouli, M.
    Ben Souf, M. A.
    Bareille, O.
    Ichchou, M. N.
    Fakhfakh, T.
    Haddar, M.
    FINITE ELEMENTS IN ANALYSIS AND DESIGN, 2018, 147 : 1 - 9