Automated Synthesis of Semantic Malware Signatures using Maximum Satisfiability
Yu Feng, Osbert Bastani, Ruben Martins, Isil Dillig, Saswat Anand
Abstract
This paper proposes a technique for automatically learning semantic malware signatures for Android from very few samples of a malware family. The key idea underlying our technique is to look for a maximally suspicious common subgraph (MSCS) that is shared between all known instances of a malware family. An MSCS describes the shared functionality between multiple Android applications in terms of inter-component call relations and their semantic metadata (e.g., data-flow properties). Our approach identifies such maximally suspicious common subgraphs by reducing the problem to maximum satisfiability. Once a semantic signature is learned, our approach uses a combination of static analysis and a new approximate signature matching algorithm to determine whether an Android application matches the semantic signature characterizing a given malware family. We have implemented our approach in a tool called ASTROID and show that it has a number of advantages over state-of-theart malware detection techniques. First, we compare the semantic malware signatures automatically synthesized by ASTROID with manually-written signatures used in previous work and show that the signatures learned by ASTROID perform better in terms of accuracy as well as precision. Second, we compare ASTROID against two state-of-the-art malware detection tools and demonstrate its advantages in terms of interpretability and accuracy. Finally, we demonstrate that ASTROID's approximate signature matching algorithm is resistant to behavioral obfuscation and that it can be used to detect zero-day malware. In particular, we were able to find 22 instances of zero-day malware in Google Play that are not reported as malware by existing tools. This paper aims to overcome these disadvantages of existing malware detectors by proposing a new technique to automatically infer malware signatures. By identifying malware based on inferred signatures, our approach retains all the advantages of signature-based approaches: it can pinpoint Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 61ec751a-9e79-4ec4-a9ec-5cd5cb42a18cCited by top-tier papers8
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Demystifying the Vetting Process of Voice-controlled Skills on MarketsDawei Wang, Kai Chen, Wei WangUbiComp 2021 · 12 citations
- AlloyMax: bringing maximum satisfaction to relational specificationsChangjian Zhang, Ryan Wagner, Pedro Orvalho, David Garlan et al.FSE 2021 · 10 citations
- Synthesis of web layouts from examplesDylan Lukes, John Sarracino, Cora Coleman, Hila Peleg et al.FSE 2021 · 8 citations
- Black-box Adversarial Example Attack towards FCG Based Android Malware Detection under Incomplete Feature InformationHeng Li, Zhang Cheng, Bang Wu, Liheng Yuan et al.USENIX Security 2023
Related papers
- Enhancing Malware Detection for Android Apps: Detecting Fine-Granularity Malicious ComponentsZhijie Liu, Liang Feng Zhang, Yutian TangASE 2023 · 10 citations
- Rotten Apples Spoil the Bunch: An Anatomy of Google Play MalwareMichael Cao, Khaled Ahmed, Julia RubinICSE 2022 · 13 citations
- ForeDroid: Scenario-Aware Analysis for Android Malware Detection and ExplanationJiaming Li, Sen Chen, Chunlian Wu, Yuxin Zhang et al.CCS 2025
- The Illusion of Success: Learning-Based Android Malware Detectors (Replicability Study)Michael Tegegn, Julia RubinISSTA 2026
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 253 citations
