The Droid is in the Details: Environment-aware Evasion of Android Sandboxes

The Droid is in the Details: Environment-aware Evasion of Android Sandboxes
复制标题

DOI:
10.14722/ndss.2022.23056
复制
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Brian Kondracki
Brian Kondracki
中科院分区:
其他
文献类型:
--
作者:
Brian Kondracki

文献摘要

相似文献

恶意软件沙箱长期以来一直是检测和分析恶意软件的重要工具。移动的设备以及随后的移动的应用的激增已经导致移动终端沙盒的开发和使用的激增,以确保应用市场的完整性。反过来,为了逃避这些沙箱,恶意软件已经发展到在沙箱环境中执行时暂停其恶意活动。复杂的恶意软件沙箱试图通过修补指示恶意软件分析系统的运行时属性来阻止沙箱检测。在本文中,我们提出了一套新的移动沙箱规避技术,我们统称为“环境感知”沙箱检测。我们探索了从现成的API中提取的工件的分布,以区分真实的用户设备和沙箱。为此,我们确定了可用于提取环境相关特征的Android API,例如用户配置的伪影(例如屏幕亮度),设备上的文件数量(例如照片和歌曲的数量)以及硬件传感器(例如存在步数计数器)。通过收集来自真实的用户和Android沙盒的真实数据,我们发现攻击者可以直接构建一个能够区分真实的Android设备和知名移动的沙盒的分类器,准确率为98.54%。此外,为了证明单独在沙箱环境中修补API的不有效性,我们专注于声称的沙箱制造商(三星,LG等)之间的功能不一致性。和来自这些制造商的真实的设备。我们的发现强调了创建强大的沙箱环境的困难,无论其底层平台是模拟环境还是实际的移动终端。
—Malware sandboxes have long been a valuable tool for detecting and analyzing malicious software. The proliferation of mobile devices and, subsequently, mobile applications, has led to a surge in the development and use of mobile device sandboxes to ensure the integrity of application marketplaces. In turn, to evade these sandboxes, malware has evolved to suspend its malicious activity when it is executed in a sandbox environment. Sophisticated malware sandboxes attempt to prevent sandbox detection by patching runtime properties indicative of malware-analysis systems. In this paper, we propose a set of novel mobile-sandbox-evasion techniques that we collectively refer to as “environment-aware” sandbox detection. We explore the distribution of artifacts extracted from readily available APIs in order to distinguish real user devices from sandboxes. To that end, we identify Android APIs that can be used to extract environment-related features, such as artifacts of user configurations (e.g. screen brightness), population of files on the device (e.g. number of photos and songs), and hardware sensors (e.g. presence of a step counter). By collecting ground truth data from real users and Android sandboxes, we show that attackers can straightforwardly build a classifier capable of differentiating between real Android devices and well-known mobile sandboxes with 98.54% accuracy. More-over, to demonstrate the inefficacy of patching APIs in sandbox environments individually, we focus on feature inconsistencies between the claimed manufacturer of a sandbox (Samsung, LG, etc.) and real devices from these manufacturers. Our findings emphasize the difficulty of creating robust sandbox environments regardless of their underlying platform being an emulated environment, or an actual mobile device.