首页> 外文会议>IEEE International Conference on Mobile Services >Automated Detection and Classification for Packed Android Applications
【24h】

Automated Detection and Classification for Packed Android Applications

机译:打包的Android应用程序的自动检测和分类

获取原文
获取外文期刊封面目录资料

摘要

Android packing services provide significant benefits in code protection by hiding original executable code, which help app developers to protect their code against reverse engineering. However, adversaries take the advantage of packers to hide their malicious code. A number of unpacking approaches have been proposed to defend against malicious packed apps. Unfortunately, most of the unpacking approaches work only for a limited time or for a particular type of packers. The analysis for different packers often requires specific domain knowledge and a significant amount of manual effort. In this paper, we conducted analyses of known Android packers appeared in recent years and propose to design an automatic detection and classification framework. The framework is capable of identifying packed apps, extracting the execution behavioral pattern of packers, and categorizing packed apps into groups. The variants of packer families share typical behavioral patterns reflecting their activities and packing techniques. The behavioral patterns obtained dynamically can be exploited to detect and classify unknown packers, which shed light on new directions for security researchers.
机译:Android打包服务通过隐藏原始可执行代码在代码保护方面提供了显着优势,这可以帮助应用程序开发人员保护其代码免受逆向工程的侵害。但是,攻击者利用打包程序来隐藏其恶意代码。已经提出了许多解压缩方法来防御恶意打包的应用程序。不幸的是,大多数拆箱方法仅在有限的时间内或对于特定类型的包装机起作用。针对不同包装工的分析通常需要特定领域的知识和大量的人工工作。在本文中,我们对近年来出现的已知Android Packers进行了分析,并建议设计一个自动检测和分类框架。该框架能够识别打包的应用程序,提取打包程序的执行行为模式,并将打包的应用程序分类。封隔器系列的变体共有反映其活动和包装技术的典型行为模式。动态获得的行为模式可用于检测和分类未知的包装工,这为安全研究人员提供了新的方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号