首页> 外文会议>IEEE Conference on Dependable and Secure Computing >Resilient and Scalable Cloned App Detection Using Forced Execution and Compression Trees
【24h】

Resilient and Scalable Cloned App Detection Using Forced Execution and Compression Trees

机译:使用强制执行和压缩树的弹性和可扩展克隆应用程序检测

获取原文

摘要

Android markets have grown both in size and diversity, offering apps that are localized or curated for specific use cases. It is not uncommon for users to be unaware of the exact app version or name they should be installing. This has given rise to the threat of app cloning where adversaries copy the package of an app, minimally modify its code, and redistribute the clone on the market to gain a monetary advantage or to distribute malicious payloads. Existing clone detection methods use static signatures that can be evaded using control-and data-flow obfuscation. Moreover, many approaches do not scale with the number of apps, code size, and complexity, leading to prohibitive detection time requirements. In this paper, we introduce Dexsim, a dynamic analysis based system to accurately index apps and identify bytecode similarities. We propose a novel bytecode indexing and matching algorithm that employs concepts from forced execution and LZ78 compression trees, and scales linearly with the number and size of apps. Our experiments on 28k cloned benign and malicious apps showed that Dexsim is both scalable and resilient to obfuscation, ferreting out clones within 8 ms pair-wise on average with at least 90% accuracy.
机译:Android市场的规模和多样性都在增长,提供针对特定用例进行本地化或精选的应用程序。用户不知道确切的应用版本或应安装的名称的情况并不少见。这导致了应用程序克隆的威胁,在这种情况下,对手会复制应用程序的程序包,最小化其代码,然后在市场上重新分发克隆,以获取金钱利益或分发恶意负载。现有的克隆检测方法使用静态签名,可以使用控制和数据流混淆来逃避这些签名。此外,许多方法无法随应用程序的数量,代码大小和复杂性扩展,从而导致检测时间过长。在本文中,我们介绍了Dexsim,这是一个基于动态分析的系统,可以准确地为应用程序编制索引并识别字节码相似性。我们提出了一种新颖的字节码索引和匹配算法,该算法采用了强制执行和LZ78压缩树中的概念,并随应用程序的数量和大小线性扩展。我们对28k克隆的良性和恶意应用程序进行的实验表明,Dexsim具有可扩展性和抗混淆性,它们平均每对在8毫秒内以90%的准确性对克隆进行筛选。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号