Identifying and Evading Android Sandbox Through Usage-Profile Based Fingerprints

被引:7
作者
Costamagna, Valerio [1 ]
Zheng, Cong [2 ]
Huang, Heqing [3 ]
机构
[1] Univ Torino, Turin, Italy
[2] Palo Alto Networks, Santa Clara, CA USA
[3] IBM Corp, TJ Watson Res Ctr, Yorktown Hts, NY USA
来源
PROCEEDINGS OF THE FIRST WORKSHOP ON RADICAL AND EXPERIENTIAL SECURITY (RESEC'18) | 2018年
关键词
Android; Mobile Security; AntiVirus; Sandbox; Fingerprinting;
D O I
10.1145/3203422.3203427
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Android sandbox is built either on the Android emulator or the real device with a hooking framework. Fingerprints of the Android sandbox could be used to evade the dynamic detection. So, in this paper, we first conduct a measurement on eight Android sandboxes and find that their customized usage profile (e.g., contact, SMS) can be fingerprinted by attackers for evading the sandbox. From our measurement results, most Android sandboxes have empty usage profile fingerprints, or fixed fingerprints, or random artifact fingerprints. So, without protections on such user profiles, Android malware can identify these fingerprints that associate with different sandboxes and hide its malicious behaviors. At last, we propose several mitigation solutions trivial to implement, including generating and feeding random real usage profiles to the malware sample every time, as well as a hybrid approach, which combines both random and fixed usage profiles.
引用
收藏
页码:17 / 23
页数:7
相关论文
共 27 条
[1]  
[Anonymous], 2014, Vienna University of Technology
[2]  
[Anonymous], 2015, NDSS
[3]  
[Anonymous], P 2014 ACM C SEC PRI
[4]  
[Anonymous], 2016, JOE MOBILE SANDBOX
[5]  
[Anonymous], 2014, 7 EUR WORKSH SYST SE
[6]  
[Anonymous], 2013, Proceedings of ACM Conference on Data and Application Security and Privacy (CODASPY)
[7]  
B.R. Team, 2014, SANDDROID APK ANAL S
[8]  
Blackthorne J., 2016, Proceedings of the 10th USENIX Conference on Offensive Technologies, P91
[9]  
Carter M.L.W.R.P., 2016, FIN CRYPT DAT SEC 20
[10]  
Chen Y., 2017, ARXIV170705082