A Machine-learning Approach for Classifying and Categorizing Android Sources and Sinks

A Machine-learning Approach for Classifying and Categorizing Android Sources and Sinks
复制标题

DOI:
10.14722/ndss.2014.23039
复制
发表时间:
2014
期刊:
--
影响因子:
--
通讯作者:
Siegfried Rasthofer;Steven Arzt;E. Bodden
Siegfried Rasthofer;Steven Arzt;E. Bodden
中科院分区:
其他
文献类型:
--
作者:
Siegfried Rasthofer;Steven Arzt;E. Bodden

文献摘要

被引文献

相似文献

如今的智能手机用户面临着一个安全困境:他们安装的许多应用程序都是基于隐私敏感数据运行的,尽管这些应用程序可能来自那些可信度难以判断的开发人员。研究人员已经使用越来越复杂的静态和动态分析工具来解决这个问题,以帮助评估应用程序如何使用私人用户数据。然而,这些工具依赖于手动配置敏感数据源以及可能向不受信任的观察者泄露数据的接收器的列表。这样的名单很难得到。因此,我们提出了SUSI,一种新的机器学习指导的方法,用于直接从任何Android API的代码中识别源和汇。给定一个手工注释的源和汇的训练集,SUSI识别整个API中的其他源和汇。为了提供更细粒度的信息,SUSI进一步对源进行分类(例如,唯一标识符、位置信息等)和汇(例如,网络、文件等)。对于Android 4.2,SUSI以超过92%的准确率识别了数百个源和汇,其中许多是当前信息流跟踪工具所遗漏的。对大约11,000个恶意软件样本的评估证实,这些源和汇中的许多确实被使用。我们还表明,SUSI可以可靠地分类源和汇,即使在新的,以前看不见的Android版本和组件,如谷歌眼镜或Chromecast API。
Today’s smartphone users face a security dilemma: many apps they install operate on privacy-sensitive data, although they might originate from developers whose trustworthiness is hard to judge. Researchers have addressed the problem with more and more sophisticated static and dynamic analysis tools as an aid to assess how apps use private user data. Those tools, however, rely on the manual configuration of lists of sources of sensitive data as well as sinks which might leak data to untrusted observers. Such lists are hard to come by. We thus propose SUSI, a novel machine-learning guided approach for identifying sources and sinks directly from the code of any Android API. Given a training set of hand-annotated sources and sinks, SUSI identifies other sources and sinks in the entire API. To provide more fine-grained information, SUSI further categorizes the sources (e.g., unique identifier, location information, etc.) and sinks (e.g., network, file, etc.). For Android 4.2, SUSI identifies hundreds of sources and sinks with over 92% accuracy, many of which are missed by current information-flow tracking tools. An evaluation of about 11,000 malware samples confirms that many of these sources and sinks are indeed used. We furthermore show that SUSI can reliably classify sources and sinks even in new, previously unseen Android versions and components like Google Glass or the Chromecast API.