Hybrid Dynamic Analysis for Android Malware Protected by Anti-Analysis Techniques with DOOLDA

Citations

WEB OF SCIENCE

1
Citations

SCOPUS

4

초록

A lot of the recently reported malware is equipped with the anti-analysis techniques (e.g., anti-emulation, antidebugging, etc.) for preventing from being the analyzed, which can delay detection and make malware alive for a longer period. Therefore, it is of the great importance of developing automated approaches to defeat such antianalysis techniques so that we can handle and effectively mitigate numerous malware. In this paper, by analyzing 1,535 malicious applications, we found that 18.31% of them equipped with anti-analysis techniques. Next, we propose a novel, dynamic analyzer, named DOOLDA, for automatically invalidating anti-analysis techniques through dynamic instrumentation. DOOLDA monitors executions of Android applications' entire code layers (i.e., bytecode and native code). Based on monitoring results, DOOLDA finds the code related to anti-analysis techniques and invalidates the antianalysis techniques by instrumenting it. To demonstrate the effectiveness of DOOLDA, we show that it can invalidate all known anti-analysis techniques. Also, we compare DOOLDA with other dynamic analyzers.

키워드

Malware analysisDynamic analysisMobile security
제목
Hybrid Dynamic Analysis for Android Malware Protected by Anti-Analysis Techniques with DOOLDA
저자
Lee, SunjunShin, YongguChoi, MinseongCho, HaehyunYi, Jeong Hyun
DOI
10.53106/160792642024032502003
발행일
2024-03
유형
Article
저널명
Journal of Internet Technology
25
2
페이지
195 ~ 213