Tackling runtime-based obfuscation in Android with TIRO
Michelle Y. Wong, David Lie
摘要
Obfuscation is used in malware to hide malicious activity from manual or automatic program analysis. On the Android platform, malware has had a history of using obfuscation techniques such as Java reflection, code packing and value encryption. However, more recent malware has turned to employing obfuscation that subverts the integrity of the Android runtime (ART or Dalvik), a technique we call runtime-based obfuscation. Once subverted, the runtime no longer follows the normally expected rules of code execution and method invocation, raising the difficulty of deobfuscating and analyzing malware that use these techniques. In this work, we propose TIRO, a deobfuscation framework for Android using an approach of Target-Instrument-Run-Observe. TIRO provides a unified framework that can deobfuscate malware that use a combination of traditional obfuscation and newer runtimebased obfuscation techniques. We evaluate and use TIRO on a dataset of modern Android malware samples and find that TIRO can automatically detect and reverse language-based and runtime-based obfuscation. We also evaluate TIRO on a corpus of 2000 malware samples from VirusTotal and find that runtime-based obfuscation techniques are present in 80% of the samples, demonstrating that runtime-based obfuscation is a significant tool employed by Android malware authors today.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Mind Your Weight(s): A Large-scale Study on Insufficient Machine Learning Model Protection in Mobile AppsZhichuang Sun, Ruimin Sun, Long Lu, Alan MisloveUSENIX Security 2021 · 被引用 101 次
- Happer: Unpacking Android Apps via a Hardware-Assisted ApproachLei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou 等S&P 2021 · 被引用 29 次
- Understanding Open Ports in Android Applications: Discovery, Diagnosis, and Security AssessmentDaoyuan Wu, Debin Gao, Rocky K. C. Chang, En He 等NDSS 2019 · 被引用 25 次
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo 等FSE 2020 · 被引用 22 次
- ConDySTA: Context-Aware Dynamic Supplement to Static Taint AnalysisXueling Zhang, Xiaoyin Wang, Rocky Slavin, Jianwei NiuS&P 2021 · 被引用 22 次
它引用的顶会 Paper4
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 被引用 253 次
- Harvesting Runtime Values in Android Applications That Feature Anti-Analysis TechniquesSiegfried Rasthofer, Steven Arzt, Marc Miltenberger, Eric BoddenNDSS 2016 · 被引用 157 次
- Statistical Deobfuscation of Android ApplicationsBenjamin Bichsel, Veselin Raychev, Petar Tsankov, Martin T. VechevCCS 2016 · 被引用 128 次
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin 等NDSS 2018 · 被引用 87 次
相关 Paper
- Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ARTLei Xue, Yajin Zhou, Ting Chen, Xiapu Luo 等USENIX Security 2017 · 被引用 81 次
- Prison Break of Android Reflection Restriction and DefenseZhen Ling, Ruizhao Liu, Yue Zhang, Kang Jia 等INFOCOM 2021
- Uncovering and Mitigating the Impact of Code Obfuscation on Dataset Annotation with Antivirus EnginesCuiying Gao, Yueming Wu, Heng Li, Wei Yuan 等ISSTA 2024 · 被引用 4 次
- Parema: an unpacking framework for demystifying VM-based Android packersLei Xue, Yuxiao Yan, Luyi Yan, Muhui Jiang 等ISSTA 2021 · 被引用 11 次
- Inspecting Virtual Machine Diversification Inside Virtualization ObfuscationNaiqian Zhang, Dongpeng Xu, Jiang Ming, Jun Xu 等S&P 2025
