Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System Emulation
Yue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin, Xiaorui Pan, Tongxin Li, Xueqiang Wang, XiaoFeng Wang
Abstract
The prevalent usage of runtime packers has complicated Android malware analysis, as both legitimate and malicious apps are leveraging packing mechanisms to protect themselves against reverse engineer. Although recent efforts have been made to analyze particular packing techniques, little has been done to study the unique characteristics of Android packers. In this paper, we report the first systematic study on mainstream Android packers, in an attempt to understand their security implications. For this purpose, we developed DROIDUNPACK, a whole-system emulation based Android packing analysis framework, which compared with existing tools, relies on intrinsic characteristics of Android runtime (rather than heuristics), and further enables virtual machine inspection to precisely recover hidden code and reveal packing behaviors. Running our tool on 6 major commercial packers, 93,910 Android malware samples and 3 existing state-of-the-art unpackers, we found that not only are commercial packing services abused to encrypt malicious or plagiarized contents, they themselves also introduce securitycritical vulnerabilities to the apps being packed. Our study further reveals the prevalence and rapid evolution of custom packers used by malware authors, which cannot be defended against using existing techniques, due to their design weaknesses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c94064bf-cb79-47c2-a207-b029acefeb3aCited by top-tier papers15
- Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android MalwareXiaohan Zhang, Yuan Zhang, Ming Zhong, Daizong Ding et al.CCS 2020 · 173 citations
- Tackling runtime-based obfuscation in Android with TIROMichelle Y. Wong, David LieUSENIX Security 2018 · 59 citations
- Happer: Unpacking Android Apps via a Hardware-Assisted ApproachLei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou et al.S&P 2021 · 29 citations
- Understanding Open Ports in Android Applications: Discovery, Diagnosis, and Security AssessmentDaoyuan Wu, Debin Gao, Rocky K. C. Chang, En He et al.NDSS 2019 · 25 citations
- NCScope: hardware-assisted analyzer for native code in Android appsHao Zhou, Shuohan Wu, Xiapu Luo, Ting Wang et al.ISSTA 2022 · 16 citations
Related papers
- Parema: an unpacking framework for demystifying VM-based Android packersLei Xue, Yuxiao Yan, Luyi Yan, Muhui Jiang et al.ISSTA 2021 · 11 citations
- Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance BoostBinlin Cheng, Jiang Ming, Jianming Fu, Guojun Peng et al.CCS 2018 · 68 citations
- Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ARTLei Xue, Yajin Zhou, Ting Chen, Xiapu Luo et al.USENIX Security 2017 · 81 citations
- VAHunt: Warding Off New Repackaged Android Malware in App-Virtualization's ClothingLuman Shi, Jiang Ming, Jianming Fu, Guojun Peng et al.CCS 2020 · 24 citations
- Android on PC: On the Security of End-user Android EmulatorsFenghao Xu, Siyu Shen, Wenrui Diao, Zhou Li et al.CCS 2021 · 5 citations
