InviSeal: A Stealthy Dynamic Analysis Framework for Android Systems

نویسندگان

چکیده

With wide adaptation of open-source Android into mobile devices by different device vendors, sophisticated malware are developed to exploit security vulnerabilities. As comprehensive analysis on physical impractical and costly, emulator-driven has gained popularity in recent times. Existing dynamic frameworks suffer from two major issues: (i) they do not provide foolproof anti-emulation-detection measures even for fingerprint-based attacks, (ii) lack efficient cross-layer profiling capabilities. In this work, we present InviSeal, a scalable framework that includes low-overhead techniques detailed along with the basic emulation features. While providing an emulator-based platform, InviSeal strives remain behind-the-scene avoid emulation-detection. We empirically demonstrate proposed OS layer utility achieve is ∼1.26× faster than existing strace -based approaches. Overall, average, incurs ∼1.04× overhead terms number operations performed various workloads CaffeineMark-3.0 benchmark, which better contemporary techniques. Furthermore, measure strategies against emulation-detection attacks. Experimental results show attacks carried out samples find as emulated platform.

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Targeted Dynamic Analysis for Android Malware

Targeted Dynamic Analysis for Android Malware Michelle Wong Master of Applied Science Graduate Department of Electrical and Computer Engineering University of Toronto 2015 The identification and analysis of Android malware involves either static or dynamic program analysis of the malware binary. While static analysis has good code coverage, it is not as precise due to the lack of run-time infor...

متن کامل

Building a Comprehensive Conceptual Framework for Power Systems Resilience Metrics

Recently, the frequency and severity of natural and man-made disasters (extreme events), which have a high-impact low-frequency (HILF) property, are increased. These disasters can lead to extensive outages, damages, and costs in electric power systems. A power system must be built with “resilience” against disasters, which means its ability to withstand disasters efficiently while ensuring the ...

متن کامل

A Temporal Permission Analysis and Enforcement Framework for Android

Permission-induced attacks, i.e., security breaches enabled by permission misuse, are among the most critical and frequent issues threatening the security of Android devices. By ignoring the temporal aspects of an attack during the analysis and enforcement, the state-of-the-art approaches aimed at protecting the users against such attacks are prone to have low-coverage in detection and highdisr...

متن کامل

Semeo: a Semantic Equivalence Analysis Framework for Obfuscated Android Applications

Software repackaging is a common approach for creating malware. In this approach, malware authors inject malicious payloads into legitimate applications; then, to render security analysis more difficult, they obfuscate most or all of the code. This forces analysts to spend a large amount of effort filtering out benign obfuscated methods in order to locate potentially malicious methods for furth...

متن کامل

A dynamic taint forensic analysis tool for Android apps

.................................................................................................................................. ix CHAPTER

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Digital threats

سال: 2023

ISSN: ['2692-1626', '2576-5337']

DOI: https://doi.org/10.1145/3567599