课题基金 / 基金详情

CRII: SaTC: A Malware-Inspired Approach to Mobile Application Repackaging and Tampering Detection

CRII: SaTC: A Malware-Inspired Approach to Mobile Application Repackaging and Tampering Detection
CRII:SaTC:一种受恶意软件启发的移动应用程序重新打包和篡改检测方法
批准号:
1850278
负责人:
Lannan Luo
金额:
$17.49万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-06-15 至 2022-05-31

项目摘要

项目成果

Lannan Luo的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Mobile application ("app") repackaging is a severe threat to the flourishing mobile market and numerous users. 97% of the top paid Android apps and 87% of the iOS ones have been repackaged. Besides, it is one of the most common ways of propagating mobile malware. Existing countermeasures mostly detect repackaging based on app similarity measurement, which tends to be imprecise when obfuscations are applied to repackaged apps. Moreover, they rely on a centralized party, typically the hosting app store, to perform the detection, but many alternative app stores fail to commit proper effort to piracy detection. This research aims at an effective defense against app repackaging, and will result in substantial progress in tackling malware propagated via repackaged apps. It will help mitigate attacks such as ransomware or DDoS launched from repackaged apps. It will also help reduce the massive monetary loss of legitimate app developers. Industrial collaborations ensure rapidly translate scientific discovery and technical knowledge into beneficial commercial products. Educational resources from this project, including course modules on mobile security and malware detection, will be disseminated through a dedicated web site. This research will foster new research and education opportunities at University of South Carolina. Students from underrepresented groups will participate in the project.This research is to explore a decentralized scheme that adds repackaging detection capability into the app to be protected, such that the host devices are made use of to conduct detection when the app is running. The main challenge is how to protect the repackaging detection code from attacks. The team of research proposes a novel malware-inspired approach to handling the important mobile app repackaging problem. The team will explore a creative use of logic bombs, which are regularly used in malware: the trigger conditions are constructed to exploit the differences between the attacker and users (in terms of hardware, sensor values, and inputs), such that a bomb that lies dormant on the attacker side will be activated on the user side. The repackaging detection code, which is packed as the bomb payload, is executed only if the bomb is activated. (2) Unlike many conventional software tampering detection techniques that try to conceal the detection code, by leveraging various methods used in malware this design is non-stealthy, which means that the detection code is not hidden, yet still resilient to attacks. (3) The proposed system also aims to detect code tampering, which occurs when malicious code is inserted and hence implies extraordinary dangers. (4) The decentralized repackaging/tampering detection is proposed to be used for crowdsourced malware information collection to fight against malware propagation. (5) Finally, the team is to address how to prevent the proposed techniques from being abused by malware authors.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/dsn-w54100.2022.00025
发表时间: 2022-06
期刊: 2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W)
影响因子: --
作者: [Junzhe Wang;Lannan Luo]
通讯作者: Junzhe Wang;Lannan Luo
DOI: 10.14722/ndss.2021.24464
发表时间: 2021-01
期刊: ArXiv
影响因子: --
作者: [Haotian Chi;Qiang Zeng;Xiaojiang Du;Lannan Luo]
通讯作者: Haotian Chi;Qiang Zeng;Xiaojiang Du;Lannan Luo
DOI: --
发表时间: 2018-12
期刊:
影响因子: --
作者: [F. Zuo;Bokai Yang;Xiaopeng Li;Qiang Zeng]
通讯作者: F. Zuo;Bokai Yang;Xiaopeng Li;Qiang Zeng
DOI: 10.1145/3485832.3488022
发表时间: 2021-12
期刊: Proceedings of the 37th Annual Computer Security Applications Conference
影响因子: --
作者: [Lannan Luo;Qiang Zeng;Bokai Yang;Fei Zuo;Junzhe Wang]
通讯作者: Lannan Luo;Qiang Zeng;Bokai Yang;Fei Zuo;Junzhe Wang
10
    SaTC: CORE: Small: Semantics-Oriented Binary Code Analysis Learning from Recent Advances in Deep Learning
    • 批准号:
      2304720
    • 项目类别:
      Standard Grant
    • 资助金额:
      $41.69万
    • 财政年份:
      2022
    • 负责人:
      Lannan Luo
    • 依托单位:
    SaTC: CORE: Small: Semantics-Oriented Binary Code Analysis Learning from Recent Advances in Deep Learning
    SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
    海外基金