MIME: A Formal Approach to (Android) Emulation Malware Analysis
被引:1
|
作者:
Bellini, Fabio
论文数: 0引用数: 0
h-index: 0
机构:
Univ Verona, Dipartimento Informat, Verona, ItalyUniv Verona, Dipartimento Informat, Verona, Italy
Bellini, Fabio
[1
]
Chiodi, Roberto
论文数: 0引用数: 0
h-index: 0
机构:
Univ Verona, Dipartimento Informat, Verona, ItalyUniv Verona, Dipartimento Informat, Verona, Italy
Chiodi, Roberto
[1
]
论文数: 引用数:
h-index:
机构:
Mastroeni, Isabella
[1
]
机构:
[1] Univ Verona, Dipartimento Informat, Verona, Italy
来源:
FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2015)
|
2016年
/
9482卷
关键词:
Anti-emulation malware;
Abstract non-interference;
Program analysis;
D O I:
10.1007/978-3-319-30303-1_16
中图分类号:
TP [自动化技术、计算机技术];
学科分类号:
0812 ;
摘要:
In this paper, we propose a new dynamic and configurable approach to anti-emulation malware analysis, aiming at improving transparency of existing analyses techniques. We test the effectiveness of existing widespread free analyzers and we observe that the main problem of these analyses is that they provide static and immutable values to the parameter used in anti-emulation tests. Our approach aims at overcoming these limitations by providing an abstract non-interference-based approach modeling the fact that parameters can be modified dynamically, and the corresponding executions compared.