DexLego: Reassembleable Bytecode Extraction for Aiding Static Analysis
DexLego: Reassembleable Bytecode Extraction for Aiding Static Analysis
复制标题
DOI:
10.1109/dsn.2018.00075
复制
发表时间:
2018-03
期刊:
影响因子:
--
通讯作者:
Zhenyu Ning;Fengwei Zhang
中科院分区:
文献类型:
--
作者:
Zhenyu Ning;Fengwei Zhang
The scale of Android applications in the market is growing rapidly. To efficiently detect the malicious behavior in these applications, an array of static analysis tools are proposed. However, static analysis tools suffer from code hiding techniques like packing, dynamic loading, self modifying, and reflection. In this paper, we thus present DexLego, a novel system that performs a reassembleable bytecode extraction for aiding static analysis tools to reveal the malicious behavior of Android applications. DexLego leverages just-in-time collection to extract data and bytecode from an application at runtime, and reassembles them to a new Dalvik Executable (DEX) file offline. The experiments on DroidBench and real-world applications show that DexLego precisely reconstructs the behavior of an application in the reassembled DEX file, and significantly improves analysis result of the existing static analysis systems.