首页> 外文会议>IFIP WG 11.2 International conference on information security theory and practice >AndroNeo: Hardening Android Malware Sandboxes by Predicting Evasion Heuristics
【24h】

AndroNeo: Hardening Android Malware Sandboxes by Predicting Evasion Heuristics

机译:AndroNeo:通过预测回避启发式分析强化Android恶意软件沙盒

获取原文

摘要

Sophisticated Android malware families often implement techniques aimed at avoiding detection. Split personality malware for example, behaves benignly when it detects that it is running on an analysis environment such as a malware sandbox, and maliciously when running on a real user's device. These kind of techniques are problematic for malware analysts, often rendering them unable to detect or understand the malicious behaviour. This is where sandbox hardening comes into play. In our work, we exploit sandbox detecting heuristic prediction to predict and automatically generate bytecode patches, in order to disable the malware's ability to detect a malware sandbox. Through the development of AndroNeo, we demonstrate the feasibility of our approach by showing that the heuristic prediction basis is a solid starting point to build upon, and demonstrating that when heuristic prediction is followed by bytecode patch generation, split personality can be defeated.
机译:复杂的Android恶意软件家族经常实施旨在避免检测的技术。例如,人格分裂的恶意软件在检测到它正在分析环境(如恶意软件沙箱)上运行时表现良好,而在实际用户的设备上运行时则表现出恶意。这类技术对恶意软件分析人员来说是有问题的,通常使他们无法检测或了解恶意行为。这就是沙箱强化的作用所在。在我们的工作中,我们利用沙盒检测启发式预测来预测并自动生成字节码补丁,以禁用恶意软件检测恶意软件沙盒的能力。通过开发AndroNeo,我们通过证明启发式预测基础是建立的坚实起点,并证明当启发式预测后跟随字节码补丁生成时,可以克服分裂个性,从而证明了该方法的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号