StateDroid: Stateful Detection of Stealthy Attacks in Android Apps via Horn-Clause Verification

StateDroid: Stateful Detection of Stealthy Attacks in Android Apps via Horn-Clause Verification
复制标题

StateDroid:通过 Horn-Clause 验证对 Android 应用中的隐形攻击进行状态检测

DOI:
10.1145/3274694.3274707
复制
发表时间:
2018
期刊:
Proceedings of the 34th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
D. Kung
D. Kung
中科院分区:
--
文献类型:
--
作者:
Mohsin Junaid;Jiang Ming;D. Kung

文献摘要

参考文献

被引文献

相似文献

受利润驱动的网络犯罪分子有动机通过隐藏恶意行为以避免引起怀疑来延长Android恶意软件的生命周期。隐形恶意软件已经成为Android安全的一个新兴挑战,因为它可以在相当长一段时间内不被发现。然而,面对这种新的威胁,传统的防御技术是不够的。我们对已发布的恶意软件分析报告和相应的代码分析进行了深入研究,得出了三个关键结论:1)隐形攻击会经历多个状态;2)状态转换是由一系列攻击动作引起的;3)攻击行为通常涉及不同对象上的几个Android api。这些见解促使我们设计一个两层有限状态机(FSM)模型,命名为StateDroid,以描述状态转换方面的多步骤隐形攻击。我们的目标是一次性推断出来自Android应用程序的各种隐形攻击。然而,攻击动作的异构特性使得准确检测模型的自动构建成为一项具有挑战性的工作。为了克服这一障碍,StateDroid将Android api和攻击的语义抽象为Horn子句,然后通过Horn子句验证自动构建两层FSM模型。我们已经开发了StateDroid的开源原型,并使用ground truth数据集,1,505谷歌Play应用程序和1,369恶意应用程序对其进行了广泛评估。令人鼓舞的实验结果证明了StateDroid的有效性。我们的研究表明,隐形攻击在新一代恶意软件中非常普遍,例如臭名昭著的勒索软件,我们甚至发现最近7.5%的b谷歌Play应用程序表现出意想不到的隐形行为。
Profit-driven cyber-criminals are motivated to prolong Android malware's lifetime by hiding malicious behaviors from raising suspicion. Stealthy malware has become an emerging challenge to Android security as it can remain undetected for quite a long time. However, traditional defense techniques are insufficient in face of this new threat. Our in-depth study on published malware analysis reports and corresponding code analysis leads to three key observations: 1) a stealthy attack goes through multiple states; 2) state transitions are caused by a sequence of attack actions; 3) an attack action typically involves several Android APIs on different objects. These insights motivate us to design a two-layer finite state machine (FSM) model, named StateDroid, to depict multi-step stealthy attacks in terms of state transitions. Our goal is to reason about various stealthy attacks from an Android app in one pass. However, the heterogeneous characteristics of attack actions make automatic construction of accurate detection model a challenging work. To overcome this obstacle, StateDroid abstracts the semantics of Android APIs and attacks as Horn clauses, and then it automatically constructs the two-layer FSM model via Horn-clause verification. We have developed an open-source prototype of StateDroid and evaluated it extensively with ground truth dataset, 1, 505 Google Play apps, and 1, 369 malicious apps, respectively. The encouraging experimental results demonstrate the efficacy of StateDroid. Our study shows stealthy attacks have been quite common among new-generation malware such as notorious ransomware, and we even identify 7.5% of recent Google Play apps exhibit unexpected stealthy behaviors.
DOI: 10.1049/iet-net.2017.0207
发表时间: 2018-08
期刊: IET Networks
影响因子: 1.4
作者:
Philip O'Kane;S. Sezer;Domhnall Carlin
通讯作者: Philip O'Kane;S. Sezer;Domhnall Carlin
DOI: 10.1145/3180155.3180169
发表时间: 2018-05
期刊: 2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE)
影响因子: --
作者:
Pei Wang;Qinkun Bao;Li Wang;Shuai Wang;Zhaofeng Chen;Tao Wei;Dinghao Wu
通讯作者: Pei Wang;Qinkun Bao;Li Wang;Shuai Wang;Zhaofeng Chen;Tao Wei;Dinghao Wu