【24h】

Reviving Android Malware with DroidRide: And How Not To

机译:使用Droidride复活Android Malware:以及如何不

获取原文

摘要

Malware has started grabbing its undeserved share long before the blossom of Android ecosystem. Injected with malware, malicious applications (apps) may threat users in various ways like financial charges and information stealing. When the severity of a deluge of malware was first noticed, malware detectors delivered unsatisfactory detection accuracy, which further degenerated upon simple transformation of malicious apps. Now years later, we are eager to re-examine the robustness of malware detectors. A surprisingly disappointed finding is that even known malicious apps can evade quite a few detectors. We also find that repackaging with extracted exploitable code instead of readily available malware samples can evade more signature-based detectors. Furthermore, we find Android OS features of Service and Broadcast exploitable to enable malicious apps stealthily active on phones. We implement all these findings through DroidRide, a framework toward making Android malware less catchable to detectors and more active on phones. Our prototype based on two example apps-AndroRAT and MIUI Notes-demonstrates DroidRide's effectiveness in malware evasion. Toward defending against DroidRide alike evasion, we further suggest feasible design enhancements of malware detectors and Android OS.
机译:恶意软件已经开始在Android生态系统开花之前抓住其不可期待的股票。注入恶意软件,恶意应用程序(应用程序)可能以各种方式威胁用户,如财务费用和信息窃取。当首先注意到恶意软件的洪水的严重程度时,恶意软件探测器会提供不令人满意的检测精度,这在简单地转换恶意应用程序时进一步退化。现在几年后,我们渴望重新检查恶意软件探测器的稳健性。令人惊讶的失望的发现是,甚至已知的恶意应用程序可以避免相当多的探测器。我们还发现,用提取的可利用代码而不是易于可用的恶意软件样本进行重新包装可以避免更多的基于签名的探测器。此外,我们发现服务和广播的Android操作系统的功能可利用,以便在手机上悄悄地激活恶意应用程序。我们通过DROIDRIDE实施所有这些发现,这是一个框架,旨在使Android恶意软件更少可容纳探测器,并且在手机上更加活跃。我们的原型基于两个示例Apps-Androrat和Miui Notes - 展示了Droidride在恶意软件逃避中的有效性。为了防止Droidride逃避,我们进一步提出了恶意软件探测器和Android操作系统的可行设计增强。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号