首页> 外文会议>IEEE International Conference on Mobile Services >Automated Detection and Classification for Packed Android Applications
【24h】

Automated Detection and Classification for Packed Android Applications

机译:包装的Android应用程序自动检测和分类

获取原文

摘要

Android packing services provide significant benefits in code protection by hiding original executable code, which help app developers to protect their code against reverse engineering. However, adversaries take the advantage of packers to hide their malicious code. A number of unpacking approaches have been proposed to defend against malicious packed apps. Unfortunately, most of the unpacking approaches work only for a limited time or for a particular type of packers. The analysis for different packers often requires specific domain knowledge and a significant amount of manual effort. In this paper, we conducted analyses of known Android packers appeared in recent years and propose to design an automatic detection and classification framework. The framework is capable of identifying packed apps, extracting the execution behavioral pattern of packers, and categorizing packed apps into groups. The variants of packer families share typical behavioral patterns reflecting their activities and packing techniques. The behavioral patterns obtained dynamically can be exploited to detect and classify unknown packers, which shed light on new directions for security researchers.
机译:Android Packing Services通过隐藏原始可执行代码提供了代码保护中的显着优势,帮助应用程序开发人员来保护其代码反对逆向工程。然而,对手采取了包装商的优势来隐藏他们的恶意代码。已经提出了许多拆包方法来防御恶意包装的应用程序。不幸的是,大多数拆包方法仅在有限的时间或特定类型的包装机工作。不同包装机的分析通常需要特定的域知识和大量的手动努力。在本文中,我们在近年来出现了已知的Android封装商的分析,并建议设计自动检测和分类框架。该框架能够识别包装的应用程序,提取封隔器的执行行为模式,并将包装的应用程序分类为组。包装机家族的变种分享了反映其活动和包装技术的典型行为模式。可以利用动态获得的行为模式来检测和分类未知的包装器,该包装器揭示了安全研究人员的新方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号