DexLego: Reassembleable Bytecode Extraction for Aiding Static Analysis

DexLego: Reassembleable Bytecode Extraction for Aiding Static Analysis
复制标题

DOI:
10.1109/dsn.2018.00075
复制
发表时间:
2018-03
期刊:
2018 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Zhenyu Ning;Fengwei Zhang
Zhenyu Ning;Fengwei Zhang
中科院分区:
其他
文献类型:
--
作者:
Zhenyu Ning;Fengwei Zhang

文献摘要

相似文献

Android应用在市场上的规模正在迅速增长。为了有效地检测这些应用程序中的恶意行为,提出了一系列静态分析工具。然而,静态分析工具受到代码隐藏技术的影响,如打包、动态加载、自修改和反射。因此,在本文中,我们提出了DexLego,一种新的系统,执行可重命名的字节码提取,以帮助静态分析工具,揭示Android应用程序的恶意行为。DexLego利用即时收集在运行时从应用程序中提取数据和字节码,并离线将它们重新组装到新的Dalvik可执行文件(DEX)中。在DroidBench和实际应用中的实验表明,DexLego在重新组装的DEX文件中精确地重构了应用程序的行为,显著改善了现有静态分析系统的分析结果。
The scale of Android applications in the market is growing rapidly. To efficiently detect the malicious behavior in these applications, an array of static analysis tools are proposed. However, static analysis tools suffer from code hiding techniques like packing, dynamic loading, self modifying, and reflection. In this paper, we thus present DexLego, a novel system that performs a reassembleable bytecode extraction for aiding static analysis tools to reveal the malicious behavior of Android applications. DexLego leverages just-in-time collection to extract data and bytecode from an application at runtime, and reassembles them to a new Dalvik Executable (DEX) file offline. The experiments on DroidBench and real-world applications show that DexLego precisely reconstructs the behavior of an application in the reassembled DEX file, and significantly improves analysis result of the existing static analysis systems.