Skip to Main Content (Press Enter)

Logo UNITO
  • ×
  • Home
  • Pubblicazioni
  • Progetti
  • Persone
  • Competenze
  • Settori
  • Strutture
  • Terza Missione

UNI-FIND
Logo UNITO

|

UNI-FIND

unito.it
  • ×
  • Home
  • Pubblicazioni
  • Progetti
  • Persone
  • Competenze
  • Settori
  • Strutture
  • Terza Missione
  1. Pubblicazioni

StaDART: Addressing the problem of dynamic code updates in the security analysis of android applications

Articolo
Data di Pubblicazione:
2020
Abstract:
Dynamic code update techniques (Android Studio – support for dynamic delivery), such as dynamic classloading and reflection, enable Android apps to extend their functionality at runtime. At the same time,these techniques are misused by malware developers to transform a seemingly benign app into a mal-ware, once installed on a real device. Among the corpus of evasive techniques used in modern real-worldmalware, evasive usage of dynamic code updates plays a key role.First, we demonstrate the ineffectiveness of existing tools to analyze apps in the presence of dynamiccode updates using our test apps, i.e.,Reflection-Benchand InboxArchiver. Second, we present StaDART,combining static and dynamic analysis of Android apps to reveal the concealed behavior of malware.StaDART performs dynamic code interposition using a vtable tampering technique for API hooking toavoid modifications to the Android framework. Furthermore, we integrate it with a triggering solution,DroidBot, to make it more scalable and fully automated. We present our evaluation results with a datasetof 2000 real world apps; containing 1000 legitimate apps and 1000 malware samples. The evaluationresults with this dataset and Reflection-Bench show that StaDART reveals suspicious behavior that is oth-erwise hidden to static analysis tools.
Tipologia CRIS:
03A-Articolo su Rivista
Keywords:
Android, Dynamic code updates, Reflection, Dynamic class loading, Security analysis
Elenco autori:
Ahmad, Maqsood; Costamagna, Valerio; Crispo, Bruno; Bergadano, Francesco; Zhauniarovich, Yury
Autori di Ateneo:
BERGADANO Francesco
Link alla scheda completa:
https://iris.unito.it/handle/2318/1714320
Link al Full Text:
https://iris.unito.it/retrieve/handle/2318/1714320/1586624/stadart-ahmad-2020.pdf
Pubblicato in:
THE JOURNAL OF SYSTEMS AND SOFTWARE
Journal
  • Dati Generali
  • Aree Di Ricerca

Dati Generali

URL

https://reader.elsevier.com/reader/sd/pii/S0164121219301530?token=AFBB94F9B66C23DC767E20E2EAD1645A604B6D99A962A4620DC2401B4CCD06F6A86477590B713FED5BCD5D52AD67BE1B

Aree Di Ricerca

Settori (4)


PE6_5 - Security, privacy, cryptology, quantum cryptography - (2024)

CIBO, AGRICOLTURA e ALLEVAMENTI - Farmacologia Veterinaria

INFORMATICA, AUTOMAZIONE e INTELLIGENZA ARTIFICIALE - Digitalizzazione della Società e della Pubblica Amministrazione

INFORMATICA, AUTOMAZIONE e INTELLIGENZA ARTIFICIALE - Industria X.0
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 25.6.1.0