题名 | Happer: Unpacking android apps via a hardware-assisted approach |
作者 | |
通讯作者 | Luo,Xiapu |
DOI | |
发表日期 | 2021-05-01
|
会议名称 | 42nd IEEE Symposium on Security and Privacy
|
ISSN | 1081-6011
|
ISBN | 978-1-7281-8935-2
|
会议录名称 | |
卷号 | 2021-May
|
页码 | 1641-1658
|
会议日期 | May, 2021
|
会议地点 | Online
|
摘要 | Malware authors are abusing packers (or runtime-based obfuscators) to protect malicious apps from being analyzed. Although many unpacking tools have been proposed, they can be easily impeded by the anti-analysis methods adopted by the packers, and they fail to effectively collect the hidden Dex data due to the evolving protection strategies of packers. Consequently, many packing behaviors are unknown to analysts and packed malware can circumvent the inspection. To fill the gap, in this paper, we propose a novel hardware-assisted approach that first monitors the packing behaviors and then selects the proper approach to unpack the packed apps. Moreover, we develop a prototype named Happerwith a domain-specific language named behavior description language (BDL) for the ease of extending Happerafter tackling several technical challenges. We conduct extensive experiments with 12 commercial Android packers and more than 24k Android apps to evaluate Happer. The results show that Happerobserved 27 packing behaviors, 17 of which have not been elaborated by previous studies. Based on the observed packing behaviors, Happeradopted proper approaches to collect all the hidden Dex data and assembled them to valid Dex files. |
关键词 | |
学校署名 | 其他
|
语种 | 英语
|
相关链接 | [Scopus记录] |
收录类别 | |
EI入藏号 | 20213810916605
|
EI主题词 | Android (operating system)
; Malware
; Packers
; Problem oriented languages
|
EI分类号 | Oil Field Equipment:511.2
; Computer Software, Data Handling and Applications:723
|
Scopus记录号 | 2-s2.0-85114659378
|
来源库 | Scopus
|
全文链接 | https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9519458 |
引用统计 |
被引频次[WOS]:15
|
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/253546 |
专题 | 南方科技大学 工学院_计算机科学与工程系 |
作者单位 | 1.The Hong Kong Polytechnic University, 2.Zhejiang University, 3.Tongji University, 4.Texas A and M University, 5.Southern University of Science and Technology, 6.The University of Hong Kong, |
推荐引用方式 GB/T 7714 |
Xue,Lei,Zhou,Hao,Luo,Xiapu,et al. Happer: Unpacking android apps via a hardware-assisted approach[C],2021:1641-1658.
|
条目包含的文件 | ||||||
文件名称/大小 | 文献类型 | 版本类型 | 开放类型 | 使用许可 | 操作 | |
happer-sp21.pdf(1887KB) | -- | -- | 限制开放 | -- |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论