Detecting Vulnerable Android Inter-App Communication in Dynamically Loaded Code

Detecting Vulnerable Android Inter-App Communication in Dynamically Loaded Code
复制标题

DOI:
10.1109/infocom.2019.8737637
复制
发表时间:
2019-04
期刊:
IEEE INFOCOM 2019 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
Mohannad J. Alhanahnah;Qiben Yan;H. Bagheri;Hao Zhou;Yutaka Tsutano;W. Srisa-an;Xiapu Luo
Mohannad J. Alhanahnah;Qiben Yan;H. Bagheri;Hao Zhou;Yutaka Tsutano;W. Srisa-an;Xiapu Luo
中科院分区:
其他
文献类型:
--
作者:
Mohannad J. Alhanahnah;Qiben Yan;H. Bagheri;Hao Zhou;Yutaka Tsutano;W. Srisa-an;Xiapu Luo

文献摘要

相似文献

Java反射和动态类负载(DCL)是增强Android应用功能的有效功能。但是,这些功能可以被复杂的恶意软件滥用以绕过检测方案。高级恶意软件可以与Android Inter-App Communication(IAC)一起使用反射和DCL使用两个或更多应用程序来启动勾结攻击。这种动态揭示的恶意行为绕过了所有现有的检测机制,使一种新型的隐形,犯罪攻击能够实现一种新型的隐形,辅助攻击。在本文中,我们提出了DINA,这是一种新型混合分析方法,用于通过反思/DCL调用在动态加载代码中隐藏的恶意行为。 Dina不断地将反射和DCL调用附加到控制流图;然后,它对此类增强图进行了增量的动态分析,以检测可能导致恶意但隐藏的IAC活动的反射和DCL的滥用。我们对3,000个现实世界的Android应用程序和14,000个恶意应用程序的广泛评估证实了反射和DCL的普遍用法,并揭示了现实世界应用中以前未知且可能有害的隐藏的IAC行为。
Java reflection and dynamic class loading (DCL) are effective features for enhancing the functionalities of Android apps. However, these features can be abused by sophisticated malware to bypass detection schemes. Advanced malware can utilize reflection and DCL in conjunction with Android Inter-App Communication (IAC) to launch collusion attacks using two or more apps. Such dynamically revealed malicious behaviors enable a new type of stealthy, collusive attacks, bypassing all existing detection mechanisms. In this paper, we present DINA, a novel hybrid analysis approach for identifying malicious IAC behaviors concealed within dynamically loaded code through reflective/DCL calls. DINA continuously appends reflection and DCL invocations to control-flow graphs; it then performs incremental dynamic analysis on such augmented graphs to detect the misuse of reflection and DCL that may lead to malicious, yet concealed, IAC activities. Our extensive evaluation on 3,000 real-world Android apps and 14,000 malicious apps corroborates the prevalent usage of reflection and DCL, and reveals previously unknown and potentially harmful, hidden IAC behaviors in real-world apps.