首页> 外文会议>International Conference on Information Security >How to Make Information-Flow Analysis Based Defense Ineffective: An ART Behavior-Mask Attack
【24h】

How to Make Information-Flow Analysis Based Defense Ineffective: An ART Behavior-Mask Attack

机译:如何使基于信息流分析的防御无效:ART行为面具攻击

获取原文

摘要

Android permission mechanism cannot resist permission abuse, the key of malware detection is to expose its malicious behavior. Although plentiful transformation attacks are used to bypass malware detection, the latest information-flow analysis based defenses claim that they can identify malicious flows with high accuracy. Nevertheless, in this paper, we expose a new attack surface known as Behavior-Mask attack in Android Runtime (ART), which can bypass most known information-flow analysis based defenses in practice. Our attack techniques can be utilized to hide Android applications' actual behavior by only executing some irrelevant Java code in the normal way. We corrupt few runtime data through a small piece of JNI code to hijack the control flow and data flow of Java code dynamically in ART environment. Further, we implement an automatic development framework to demonstrate the viability of Behavior-Mask attack. We analyze the existing defenses on Android and traditional desktop operating systems, and put forward some new ideas for the design and implementation of future defenses against the proposed attack.
机译:Android权限机制无法抵制权限滥用,恶意软件检测的关键是暴露其恶意行为。尽管使用了大量的转换攻击来绕过恶意软件检测,但最新的基于信息流分析的防御方法声称,它们可以高精度地识别恶意流。尽管如此,在本文中,我们还是公开了一种新的攻击面,称为Android Runtime(ART)中的Behavior-Mask攻击,在实践中可以绕过大多数已知的基于信息流分析的防御措施。我们的攻击技术可通过仅以常规方式执行一些无关的Java代码来隐藏Android应用程序的实际行为。我们通过一小段JNI代码破坏了一些运行时数据,以动态劫持ART环境中Java代码的控制流和数据流。此外,我们实现了一个自动开发框架,以证明行为面具攻击的可行性。我们分析了Android和传统台式机操作系统上的现有防御措施,并针对设计和实现针对拟议攻击的未来防御措施提出了一些新思路。

著录项

  • 来源
  • 会议地点 Ho Chi Minh City(VN)
  • 作者单位

    School of Cyber Security University of Chinese Academy of Sciences Beijing China State Key Laboratory of Information Security Institute of Information Engineering Chinese Academy of Sciences Beijing China Data Assurance and Communication Security Research Center Chinese Academy of Sciences Beijing China;

    State Key Laboratory of Information Security Institute of Information Engineering Chinese Academy of Sciences Beijing China Data Assurance and Communication Security Research Center Chinese Academy of Sciences Beijing China;

  • 会议组织
  • 原文格式 PDF
  • 正文语种
  • 中图分类
  • 关键词

    Android; ART; Confusion; Java; Transformation; Code reuse;

    机译:Android;艺术;混乱; Java;转型;代码重用;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号