Finding Unknown Malice in 10 Seconds: Mass Vetting for New Threats at the Google-Play Scale

Finding Unknown Malice in 10 Seconds: Mass Vetting for New Threats at the Google-Play Scale
复制标题

DOI:
--
复制
发表时间:
2015-08
期刊:
--
影响因子:
--
通讯作者:
Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu
Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu
中科院分区:
其他
文献类型:
--
作者:
Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu

文献摘要

被引文献

相似文献

应用市场的审查过程应该是可扩展且有效的。然而,今天的审查机制是缓慢的,捕捉新威胁的能力较弱。在我们的研究中,我们发现可以通过利用Android恶意软件的构造和传播方式找到更强大的解决方案,这通常是通过将合法应用程序重新包装成类似的恶意组件。因此,这样的攻击载荷通常会从相同的重新包装来源中脱颖而出,并且也会出现在本不应该相互关联的应用程序中。基于这种观察,我们开发了一种名为MassVet的新技术,用于在不知道恶意软件的样子和行为的情况下大规模审查应用程序。与现有的检测机制(通常使用重量级程序分析技术)不同,我们的方法只是将提交的应用与市场上已有的应用进行比较,重点关注那些共享相似UI结构(表明可能的重新包装关系)的应用之间的差异,以及那些看似无关的应用之间的共性。一旦公共库和其他合法的代码重用被删除,这些diff/common程序组件就变得非常可疑。在我们的研究中,我们在一个高效的相似性比较算法之上构建了这种“Diff-Com”分析,该算法将应用UI结构的显著特征或方法的控制流图映射到一个值,以便进行快速比较。我们在一个流处理引擎上实现了MassVet,并对来自全球33个应用市场的近120万个应用进行了评估,规模相当于b谷歌Play。我们的研究表明,该技术可以在10秒内以较低的误检率审查应用程序。此外,在检测覆盖率方面,它优于VirusTotal的所有54种扫描程序(NOD32、赛门铁克、McAfee等),捕获了超过10万个恶意应用程序,其中包括20多个可能的零日恶意软件和安装了数百万次的恶意软件。仔细观察这些应用程序会发现一些有趣的新现象,例如b谷歌的检测策略和恶意软件作者的对策,导致一些谷歌Play应用程序神秘地消失和重新出现。
An app market's vetting process is expected to be scalable and effective. However, today's vetting mechanisms are slow and less capable of catching new threats. In our research, we found that a more powerful solution can be found by exploiting the way Android malware is constructed and disseminated, which is typically through repackaging legitimate apps with similar malicious components. As a result, such attack payloads often stand out from those of the same repackaging origin and also show up in the apps not supposed to relate to each other. Based upon this observation, we developed a new technique, called MassVet, for vetting apps at a massive scale, without knowing what malware looks like and how it behaves. Unlike existing detection mechanisms, which often utilize heavyweight program analysis techniques, our approach simply compares a submitted app with all those already on a market, focusing on the difference between those sharing a similar UI structure (indicating a possible repackaging relation), and the commonality among those seemingly unrelated. Once public libraries and other legitimate code reuse are removed, such diff/common program components become highly suspicious. In our research, we built this "Diff-Com" analysis on top of an efficient similarity comparison algorithm, which maps the salient features of an app's UI structure or a method's control-flow graph to a value for a fast comparison. We implemented MassVet over a stream processing engine and evaluated it nearly 1.2 million apps from 33 app markets around the world, the scale of Google Play. Our study shows that the technique can vet an app within 10 seconds at a low false detection rate. Also, it outperformed all 54 scanners in VirusTotal (NOD32, Symantec, McAfee, etc.) in terms of detection coverage, capturing over a hundred thousand malicious apps, including over 20 likely zero-day malware and those installed millions of times. A close look at these apps brings to light intriguing new observations e.g., Google's detection strategy and malware authors' countermoves that cause the mysterious disappearance and reappearance of some Google Play apps.