PuppetDroid: A User-Centric UI Exerciser for Automatic Dynamic Analysis of Similar Android Applications

PuppetDroid: A User-Centric UI Exerciser for Automatic Dynamic Analysis of Similar Android Applications
复制标题

DOI:
--
复制
发表时间:
2014-02
期刊:
ArXiv
影响因子:
--
通讯作者:
Andrea Gianazza;F. Maggi;Aristide Fattori;L. Cavallaro;S. Zanero
Andrea Gianazza;F. Maggi;Aristide Fattori;L. Cavallaro;S. Zanero
中科院分区:
其他
文献类型:
--
作者:
Andrea Gianazza;F. Maggi;Aristide Fattori;L. Cavallaro;S. Zanero

文献摘要

被引文献

相似文献

恶意移动应用程序的流行程度和复杂性都在上升,这使得分析它们变得困难和费力。移动应用程序分析确实与桌面应用程序分析有本质上的不同:在桌面应用程序分析中,用户(即受害者)的交互对于恶意软件正确暴露其所有恶意行为至关重要。我们提出了一种新的方法来分析(恶意)移动应用程序。目标是练习Android应用程序的用户界面(UI),以有效地自动触发恶意行为。我们的关键直觉是记录和重现恶意软件潜在受害者的UI交互,以便在动态分析期间激发相关行为。为了使我们的方法具有规模性,我们自动地在应用程序上重新执行与原始交互类似的记录UI交互。这些特点使我们的系统与当前的动态分析和ui操作方法是正交和互补的。我们开发了我们的方法,并通过实验表明,我们的刺激可以达到比自动UI执行器更高的代码覆盖率,从而揭示使用其他方法时不会暴露的有趣恶意行为。我们的方法也适用于众包场景,这将进一步推动新刺激痕迹的收集。这可能会改变我们对(移动)应用程序进行动态分析的方式,从完全自动化到以用户为中心和协作。
Popularity and complexity of malicious mobile applications are rising, making their analysis difficult and labor intensive. Mobile application analysis is indeed inherently different from desktop application analysis: In the latter, the interaction of the user (i.e., victim) is crucial for the malware to correctly expose all its malicious behaviors. We propose a novel approach to analyze (malicious) mobile applications. The goal is to exercise the user interface (UI) of an Android application to effectively trigger malicious behaviors, automatically. Our key intuition is to record and reproduce the UI interactions of a potential victim of the malware, so as to stimulate the relevant behaviors during dynamic analysis. To make our approach scale, we automatically re-execute the recorded UI interactions on apps that are similar to the original ones. These characteristics make our system orthogonal and complementary to current dynamic analysis and UI-exercising approaches. We developed our approach and experimentally shown that our stimulation allows to reach a higher code coverage than automatic UI exercisers, so to unveil interesting malicious behaviors that are not exposed when using other approaches. Our approach is also suitable for crowdsourcing scenarios, which would push further the collection of new stimulation traces. This can potentially change the way we conduct dynamic analysis of (mobile) applications, from fully automatic only, to user-centric and collaborative too.