상세 보기
Hybrid Dynamic Analysis for Android Malware Protected by Anti-Analysis Techniques with DOOLDA
- Lee, Sunjun;
- Shin, Yonggu;
- Choi, Minseong;
- Cho, Haehyun;
- Yi, Jeong Hyun
WEB OF SCIENCE
1SCOPUS
4초록
A lot of the recently reported malware is equipped with the anti-analysis techniques (e.g., anti-emulation, antidebugging, etc.) for preventing from being the analyzed, which can delay detection and make malware alive for a longer period. Therefore, it is of the great importance of developing automated approaches to defeat such antianalysis techniques so that we can handle and effectively mitigate numerous malware. In this paper, by analyzing 1,535 malicious applications, we found that 18.31% of them equipped with anti-analysis techniques. Next, we propose a novel, dynamic analyzer, named DOOLDA, for automatically invalidating anti-analysis techniques through dynamic instrumentation. DOOLDA monitors executions of Android applications' entire code layers (i.e., bytecode and native code). Based on monitoring results, DOOLDA finds the code related to anti-analysis techniques and invalidates the antianalysis techniques by instrumenting it. To demonstrate the effectiveness of DOOLDA, we show that it can invalidate all known anti-analysis techniques. Also, we compare DOOLDA with other dynamic analyzers.
키워드
- 제목
- Hybrid Dynamic Analysis for Android Malware Protected by Anti-Analysis Techniques with DOOLDA
- 저자
- Lee, Sunjun; Shin, Yonggu; Choi, Minseong; Cho, Haehyun; Yi, Jeong Hyun
- 발행일
- 2024-03
- 유형
- Article
- 권
- 25
- 호
- 2
- 페이지
- 195 ~ 213