CRII: SaTC: A Malware-Inspired Approach to Mobile Application Repackaging and Tampering Detection
CRII: SaTC: A Malware-Inspired Approach to Mobile Application Repackaging and Tampering Detection
批准号:
1850278
负责人:
Lannan Luo
金额:
$17.49万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-06-15 至 2022-05-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Mobile application ("app") repackaging is a severe threat to the flourishing mobile market and numerous users. 97% of the top paid Android apps and 87% of the iOS ones have been repackaged. Besides, it is one of the most common ways of propagating mobile malware. Existing countermeasures mostly detect repackaging based on app similarity measurement, which tends to be imprecise when obfuscations are applied to repackaged apps. Moreover, they rely on a centralized party, typically the hosting app store, to perform the detection, but many alternative app stores fail to commit proper effort to piracy detection. This research aims at an effective defense against app repackaging, and will result in substantial progress in tackling malware propagated via repackaged apps. It will help mitigate attacks such as ransomware or DDoS launched from repackaged apps. It will also help reduce the massive monetary loss of legitimate app developers. Industrial collaborations ensure rapidly translate scientific discovery and technical knowledge into beneficial commercial products. Educational resources from this project, including course modules on mobile security and malware detection, will be disseminated through a dedicated web site. This research will foster new research and education opportunities at University of South Carolina. Students from underrepresented groups will participate in the project.This research is to explore a decentralized scheme that adds repackaging detection capability into the app to be protected, such that the host devices are made use of to conduct detection when the app is running. The main challenge is how to protect the repackaging detection code from attacks. The team of research proposes a novel malware-inspired approach to handling the important mobile app repackaging problem. The team will explore a creative use of logic bombs, which are regularly used in malware: the trigger conditions are constructed to exploit the differences between the attacker and users (in terms of hardware, sensor values, and inputs), such that a bomb that lies dormant on the attacker side will be activated on the user side. The repackaging detection code, which is packed as the bomb payload, is executed only if the bomb is activated. (2) Unlike many conventional software tampering detection techniques that try to conceal the detection code, by leveraging various methods used in malware this design is non-stealthy, which means that the detection code is not hidden, yet still resilient to attacks. (3) The proposed system also aims to detect code tampering, which occurs when malicious code is inserted and hence implies extraordinary dangers. (4) The decentralized repackaging/tampering detection is proposed to be used for crowdsourced malware information collection to fight against malware propagation. (5) Finally, the team is to address how to prevent the proposed techniques from being abused by malware authors.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/dsn-w54100.2022.00025
发表时间:
2022-06
期刊:
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W)
影响因子:
--
作者:
[Junzhe Wang;Lannan Luo]
通讯作者:
Junzhe Wang;Lannan Luo
DOI:
10.14722/ndss.2021.24464
发表时间:
2021-01
期刊:
ArXiv
影响因子:
--
作者:
[Haotian Chi;Qiang Zeng;Xiaojiang Du;Lannan Luo]
通讯作者:
Haotian Chi;Qiang Zeng;Xiaojiang Du;Lannan Luo
DOI:
--
发表时间:
2018-12
期刊:
影响因子:
--
作者:
[F. Zuo;Bokai Yang;Xiaopeng Li;Qiang Zeng]
通讯作者:
F. Zuo;Bokai Yang;Xiaopeng Li;Qiang Zeng
DOI:
10.1145/3485832.3488022
发表时间:
2021-12
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Lannan Luo;Qiang Zeng;Bokai Yang;Fei Zuo;Junzhe Wang]
通讯作者:
Lannan Luo;Qiang Zeng;Bokai Yang;Fei Zuo;Junzhe Wang
Tainting-Assisted and Context-Migrated Symbolic Execution of Android Framework for Vulnerability Discovery and Exploit Generation
用于漏洞发现和利用生成的 Android 框架的污染辅助和上下文迁移符号执行
DOI:
10.1109/tmc.2019.2936561
发表时间:
2020-12
期刊:
IEEE Transactions on Mobile Computing
影响因子:
7.9
作者:
[Luo Lannan, Zeng Qiang, Cao Chen, Chen Kai, Liu Jian, Liu Limin, Gao Neng, Yang Min, Xing Xinyu, Liu Peng]
通讯作者:
Liu Peng
共 10 条
SaTC: CORE: Small: Semantics-Oriented Binary Code Analysis Learning from Recent Advances in Deep Learning
-
批准号:2304720
-
项目类别:Standard Grant
-
资助金额:$41.69万
-
财政年份:2022
-
负责人:Lannan Luo
-
依托单位:
SaTC: CORE: Small: Semantics-Oriented Binary Code Analysis Learning from Recent Advances in Deep Learning
-
批准号:1953073
-
项目类别:Standard Grant
-
资助金额:$41.69万
-
财政年份:2020
-
负责人:Lannan Luo
-
依托单位:
SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
-
批准号:1815144
-
项目类别:Standard Grant
-
资助金额:$15.9万
-
财政年份:2018
-
负责人:Lannan Luo
-
依托单位:
海外基金