Happer: Unpacking Android Apps via a Hardware-Assisted Approach
Lei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou, Yang Shi, Guofei Gu, Fengwei Zhang, Man Ho Au
摘要
Malware authors are abusing packers (or runtimebased obfuscators) to protect malicious apps from being analyzed. Although many unpacking tools have been proposed, they can be easily impeded by the anti-analysis methods adopted by the packers, and they fail to effectively collect the hidden Dex data due to the evolving protection strategies of packers. Consequently, many packing behaviors are unknown to analysts and packed malware can circumvent the inspection. To fill the gap, in this paper, we propose a novel hardware-assisted approach that first monitors the packing behaviors and then selects the proper approach to unpack the packed apps. Moreover, we develop a prototype named Happer with a domain-specific language named behavior description language (BDL) for the ease of extending Happer after tackling several technical challenges. We conduct extensive experiments with 12 commercial Android packers and more than 24k Android apps to evaluate Happer. The results show that Happer observed 27 packing behaviors, 17 of which have not been elaborated by previous studies. Based on the observed packing behaviors, Happer adopted proper approaches to collect all the hidden Dex data and assembled them to valid Dex files.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Structural Attack against Graph Based Android Malware DetectionKaifa Zhao, Hao Zhou, Yulin Zhu, Xian Zhan 等CCS 2021 · 被引用 48 次
- NCScope: hardware-assisted analyzer for native code in Android appsHao Zhou, Shuohan Wu, Xiapu Luo, Ting Wang 等ISSTA 2022 · 被引用 16 次
- HyperDbg: Reinventing Hardware-Assisted DebuggingMohammad Sina Karvandi, MohammadHosein Gholamrezaei, Saleh Khalaj Monfared, Soroush Meghdadi Zanjani 等CCS 2022 · 被引用 10 次
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan 等USENIX Security 2024 · 被引用 7 次
- Beyond Raw Bytes: Towards Large Malware Language ModelsLuke Kurlandski, Harel Berger, Yin Pan, Matthew WrightNDSS 2026 · 被引用 5 次
它引用的顶会 Paper7
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 被引用 203 次
- Harvesting Runtime Values in Android Applications That Feature Anti-Analysis TechniquesSiegfried Rasthofer, Steven Arzt, Marc Miltenberger, Eric BoddenNDSS 2016 · 被引用 157 次
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin 等NDSS 2018 · 被引用 87 次
- Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ARTLei Xue, Yajin Zhou, Ting Chen, Xiapu Luo 等USENIX Security 2017 · 被引用 81 次
- Ninja: Towards Transparent Tracing and Debugging on ARMZhenyu Ning, Fengwei ZhangUSENIX Security 2017 · 被引用 62 次
相关 Paper
- Parema: an unpacking framework for demystifying VM-based Android packersLei Xue, Yuxiao Yan, Luyi Yan, Muhui Jiang 等ISSTA 2021 · 被引用 11 次
- Adversarially Robust Assembly Language Model for Packed Executables DetectionShijia Li, Jiang Ming, Lanqing Liu, Longwei Yang 等CCS 2025
- Obfuscation-Resilient Executable Payload Extraction From Packed MalwareBinlin Cheng, Jiang Ming, Erika A. Leal, Haotian Zhang 等USENIX Security 2021 · 被引用 29 次
- Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance BoostBinlin Cheng, Jiang Ming, Jianming Fu, Guojun Peng 等CCS 2018 · 被引用 68 次
- Tackling runtime-based obfuscation in Android with TIROMichelle Y. Wong, David LieUSENIX Security 2018 · 被引用 59 次
