中文版 | English
题名

Happer: Unpacking android apps via a hardware-assisted approach

作者
通讯作者Luo,Xiapu
DOI
发表日期
2021-05-01
会议名称
42nd IEEE Symposium on Security and Privacy
ISSN
1081-6011
ISBN
978-1-7281-8935-2
会议录名称
卷号
2021-May
页码
1641-1658
会议日期
May, 2021
会议地点
Online
摘要

Malware authors are abusing packers (or runtime-based obfuscators) to protect malicious apps from being analyzed. Although many unpacking tools have been proposed, they can be easily impeded by the anti-analysis methods adopted by the packers, and they fail to effectively collect the hidden Dex data due to the evolving protection strategies of packers. Consequently, many packing behaviors are unknown to analysts and packed malware can circumvent the inspection. To fill the gap, in this paper, we propose a novel hardware-assisted approach that first monitors the packing behaviors and then selects the proper approach to unpack the packed apps. Moreover, we develop a prototype named Happerwith a domain-specific language named behavior description language (BDL) for the ease of extending Happerafter tackling several technical challenges. We conduct extensive experiments with 12 commercial Android packers and more than 24k Android apps to evaluate Happer. The results show that Happerobserved 27 packing behaviors, 17 of which have not been elaborated by previous studies. Based on the observed packing behaviors, Happeradopted proper approaches to collect all the hidden Dex data and assembled them to valid Dex files.

关键词
学校署名
其他
语种
英语
相关链接[Scopus记录]
收录类别
EI入藏号
20213810916605
EI主题词
Android (operating system) ; Malware ; Packers ; Problem oriented languages
EI分类号
Oil Field Equipment:511.2 ; Computer Software, Data Handling and Applications:723
Scopus记录号
2-s2.0-85114659378
来源库
Scopus
全文链接https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9519458
引用统计
被引频次[WOS]:15
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/253546
专题南方科技大学
工学院_计算机科学与工程系
作者单位
1.The Hong Kong Polytechnic University,
2.Zhejiang University,
3.Tongji University,
4.Texas A and M University,
5.Southern University of Science and Technology,
6.The University of Hong Kong,
推荐引用方式
GB/T 7714
Xue,Lei,Zhou,Hao,Luo,Xiapu,et al. Happer: Unpacking android apps via a hardware-assisted approach[C],2021:1641-1658.
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可 操作
happer-sp21.pdf(1887KB)----限制开放--
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Xue,Lei]的文章
[Zhou,Hao]的文章
[Luo,Xiapu]的文章
百度学术
百度学术中相似的文章
[Xue,Lei]的文章
[Zhou,Hao]的文章
[Luo,Xiapu]的文章
必应学术
必应学术中相似的文章
[Xue,Lei]的文章
[Zhou,Hao]的文章
[Luo,Xiapu]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。