StateDroid: Stateful Detection of Stealthy Attacks in Android Apps via Horn-Clause Verification
StateDroid: Stateful Detection of Stealthy Attacks in Android Apps via Horn-Clause Verification
复制标题
StateDroid:通过 Horn-Clause 验证对 Android 应用中的隐形攻击进行状态检测
DOI:
10.1145/3274694.3274707
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
D. Kung
中科院分区:
文献类型:
--
作者:
Mohsin Junaid;Jiang Ming;D. Kung
Profit-driven cyber-criminals are motivated to prolong Android malware's lifetime by hiding malicious behaviors from raising suspicion. Stealthy malware has become an emerging challenge to Android security as it can remain undetected for quite a long time. However, traditional defense techniques are insufficient in face of this new threat. Our in-depth study on published malware analysis reports and corresponding code analysis leads to three key observations: 1) a stealthy attack goes through multiple states; 2) state transitions are caused by a sequence of attack actions; 3) an attack action typically involves several Android APIs on different objects. These insights motivate us to design a two-layer finite state machine (FSM) model, named StateDroid, to depict multi-step stealthy attacks in terms of state transitions. Our goal is to reason about various stealthy attacks from an Android app in one pass. However, the heterogeneous characteristics of attack actions make automatic construction of accurate detection model a challenging work. To overcome this obstacle, StateDroid abstracts the semantics of Android APIs and attacks as Horn clauses, and then it automatically constructs the two-layer FSM model via Horn-clause verification. We have developed an open-source prototype of StateDroid and evaluated it extensively with ground truth dataset, 1, 505 Google Play apps, and 1, 369 malicious apps, respectively. The encouraging experimental results demonstrate the efficacy of StateDroid. Our study shows stealthy attacks have been quite common among new-generation malware such as notorious ransomware, and we even identify 7.5% of recent Google Play apps exhibit unexpected stealthy behaviors.
影响因子:
1.4
作者:
Philip O'Kane;S. Sezer;Domhnall Carlin
通讯作者:
Philip O'Kane;S. Sezer;Domhnall Carlin
DOI:
10.1145/3180155.3180169
发表时间:
2018-05
期刊:
2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE)
影响因子:
--
作者:
Pei Wang;Qinkun Bao;Li Wang;Shuai Wang;Zhaofeng Chen;Tao Wei;Dinghao Wu
通讯作者:
Pei Wang;Qinkun Bao;Li Wang;Shuai Wang;Zhaofeng Chen;Tao Wei;Dinghao Wu