A Large-Scale Study of Android Malware Development Phenomenon on Public Malware Submission and Scanning Platform

A Large-Scale Study of Android Malware Development Phenomenon on Public Malware Submission and Scanning Platform
复制标题

公共恶意软件提交和扫描平台上Android恶意软件开发现象的大规模研究

DOI:
10.1109/tbdata.2018.2790439
复制
发表时间:
2018-01
影响因子:
7.2
通讯作者:
Quanlong Guan
Quanlong Guan
中科院分区:
计算机科学2区
文献类型:
--
作者:
Heqing Huang;Cong Zheng;Junyuan Zeng;Wu Zhou;Sencun Zhu;Peng Liu;Ian Molloy;Suresh Chari;Ce Zhang;Quanlong Guan

文献摘要

参考文献

相似文献

随着Android恶意软件的稳步增长,我们怀疑,在恶意软件开发阶段,一些Android恶意软件编写者使用流行的公共扫描服务(例如,VirusTotal)来测试其恶意软件样本的逃避能力,我们将其命名为Android恶意软件开发案例(amd)。在这项工作中,我们在VirusTotal的背景下设计了一个AMD猎人来寻找AMD并揭示Android的新威胁。首先,AMD的“猎人”会在VirusTotal上高效地筛选数百万份提交的文件,并提醒更多可疑的提交痕迹。其次,对可疑提交的apk进行包级分析、静态代码和动态分析,验证amd。实施的猎人已经在一家领先的安全公司中使用了4个月,该公司在VirusTotal上处理了1.53亿份提交,并从83个国家的13855个样本中识别出1623个amd。我们还对从已识别的amd中选择的890个恶意软件样本进行了案例研究,发现了许多新的威胁,包括假系统/银行网络钓鱼应用的开发案例,新的扎根漏洞,新的基于JavaScript的威胁,新的逃避和AV探测恶意软件。我们撰写了关于一些amd的行业研究文章,并通知其他安全供应商帮助修补它们的误报。除了提高对amd存在的认识外,更重要的是,我们的研究提供了第一个系统和有效的方法来研究VirusTotal上的恶意软件开发现象。我们将与研究界分享所有已确定的amd样本。
With the steady growth of Android malware, we suspect that, during the malware development phase, some Android malware writers use the popular public scanning services (e.g., VirusTotal) for testing the evasion capability of their malware samples, which we name Android malware development cases (AMDs). In this work, we design an AMD hunter in the context of VirusTotal to hunt for AMDs and reveal new threats for Android. First, the AMD hunter sifts through millions of file submissions on VirusTotal efficiently and alert more suspicious submission traces. Second, it performs package level analysis, static code and dynamic analyses on the APKs of the suspicious submissions to validate the AMDs. The implemented hunter has been used in a leading security company for 4 months, which processed 153 million of submissions on VirusTotal, and identified 1,623 AMDs with 13,855 samples from 83 countries. We also performed case studies on 890 malware samples selected from the identified AMDs, which revealed lots of new threats, including the development cases of fake system/banking phishing app, new rooting exploits, new JavaScript based threats, new evasions and AV probing malware. We wrote industry research articles about some AMDs and notified other security vendors to help patch their false negatives. Besides raising the awareness of the existence of AMDs, more importantly, our research provides the first systematic and efficient way to study the malware development phenomenon on VirusTotal. We will share all the samples of the identified AMDs with the research community.
DOI: 10.1145/2076732.2076738
发表时间: 2011-12
影响因子: 3.9
作者:
Heqing Huang;Su Zhang;Xinming Ou;A. Prakash;K. Sakallah
通讯作者: Heqing Huang;Su Zhang;Xinming Ou;A. Prakash;K. Sakallah
DOI: 10.1109/icmla.2014.10
发表时间: 2014-12
期刊: 2014 13th International Conference on Machine Learning and Applications
影响因子: --
作者:
B. Wolfe;Karim O. Elish;D. Yao
通讯作者: B. Wolfe;Karim O. Elish;D. Yao
DOI: 10.1109/sp.2015.62
发表时间: 2015-05
期刊: 2015 IEEE Symposium on Security and Privacy
影响因子: --
作者:
Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
通讯作者: Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
DOI: 10.14722/ndss.2014.23205
发表时间: 2014
影响因子: 3.5
作者:
David Sounthiraraj;Justin Sahs;G. Greenwood;Zhiqiang Lin;L. Khan
通讯作者: David Sounthiraraj;Justin Sahs;G. Greenwood;Zhiqiang Lin;L. Khan
DOI: --
发表时间: 2015-08
期刊: --
影响因子: --
作者:
Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu
通讯作者: Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu