【24h】

Reviving Android Malware with DroidRide: And How Not To

机译:使用DroidRide恢复Android恶意软件:以及如何避免

获取原文

摘要

Malware has started grabbing its undeserved share long before the blossom of Android ecosystem. Injected with malware, malicious applications (apps) may threat users in various ways like financial charges and information stealing. When the severity of a deluge of malware was first noticed, malware detectors delivered unsatisfactory detection accuracy, which further degenerated upon simple transformation of malicious apps. Now years later, we are eager to re-examine the robustness of malware detectors. A surprisingly disappointed finding is that even known malicious apps can evade quite a few detectors. We also find that repackaging with extracted exploitable code instead of readily available malware samples can evade more signature-based detectors. Furthermore, we find Android OS features of Service and Broadcast exploitable to enable malicious apps stealthily active on phones. We implement all these findings through DroidRide, a framework toward making Android malware less catchable to detectors and more active on phones. Our prototype based on two example apps-AndroRAT and MIUI Notes-demonstrates DroidRide's effectiveness in malware evasion. Toward defending against DroidRide alike evasion, we further suggest feasible design enhancements of malware detectors and Android OS.
机译:恶意软件早在Android生态系统蓬勃发展之前就开始抢夺它应得的份额。注入恶意软件后,恶意应用程序可能会以各种方式威胁用户,例如财务费用和信息窃取。当首次注意到大量恶意软件的严重性时,恶意软件检测器提供的检测精度不尽人意,这在恶意应用程序进行简单转换后就进一步恶化了。数年后的今天,我们渴望重新检查恶意软件检测器的健壮性。令人惊讶的令人失望的发现是,即使是已知的恶意应用程序也可以逃避相当多的检测器。我们还发现,使用提取的可利用代码而不是容易获得的恶意软件样本进行重新包装可以逃避更多基于签名的检测器。此外,我们发现可利用服务和广播的Android OS功能来使恶意应用程序在手机上秘密运行。我们通过DroidRide来实现所有这些发现,DroidRide是一个框架,旨在使Android恶意软件不易被检测器捕获,而在手机上更活跃。我们基于两个示例应用程序AndroRAT和MIUI Notes的原型展示了DroidRide在逃避恶意软件方面的有效性。为了防御类似DroidRide的规避行为,我们进一步建议对恶意软件检测器和Android OS进行可行的设计增强。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号