On the evaluation of android malware detectors against code-obfuscation techniques

被引:1
|
作者
Nawaz, Umair [1 ]
Aleem, Muhammad [1 ]
Lin, Jerry Chun-Wei [2 ]
机构
[1] Natl Univ Comp & Emerging Sci, Comp Sci, Islamabad, Pakistan
[2] Western Norway Univ Appl Sci, Comp Sci, Bergen, Norway
关键词
Android; Android's anti-malware system; Obfuscation techniques; Reverse engineering;
D O I
10.7717/peerj-cs.1002
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The Android mobile platform is the most popular and dominates the cell phone market. With the increasing use of Android, malware developers have become active in circumventing security measures by using various obfuscation techniques. The obfuscation techniques are used to hide the malicious code in the Android applications to evade detection by anti-malware tools. Some attackers use the obfuscation techniques in isolation, while some attackers use a mixed approach (i.e., employing multiple obfuscation techniques simultaneously). Therefore, it is crucial to analyze the impact of the different obfuscation techniques, both when they are used in isolation and when they are combined as hybrid techniques. Several studies have suggested that the obfuscation techniques may be more effective when used in a mixed pattern. However, in most of the related works, the obfuscation techniques used for analysis are either based on individual or a combination of primitive obfuscation techniques. In this work, we provide a comprehensive evaluation of anti-malware tools to gauge the impact of complex hybrid code-obfuscations techniques on malware detection capabilities of the prominent anti-malware tools. The evaluation results show that the inter-category-wise hybridized code obfuscation results in more evasion as compared to the individual or simple hybridized code obfuscations (using multiple and similar code obfuscations) which most of the existing related work employed for the evaluation. Obfuscation techniques significantly impact the detection rate of any anti-malware tool. The remarkable result i.e., almost 100% best detection rate is observed for the seven out of 10 tools when analyzed using the individual obfuscation techniques, four out of 10 tools on category-wise obfuscation, and not a single anti-malware tool attained full detection (i.e., 100%) for inter-category obfuscations.
引用
收藏
页数:34
相关论文
共 50 条
  • [1] Testing android malware detectors against code obfuscation: a systematization of knowledge and unified methodology
    Preda M.D.
    Maggi F.
    Journal of Computer Virology and Hacking Techniques, 2017, 13 (3) : 209 - 232
  • [2] Evaluation of Android Anti Malware Techniques against Dalvik Bytecode Obfuscation
    Faruki, Parvez
    Bharmal, Ammar
    Laxmi, Vijay
    Gaur, M. S.
    Conti, Mauro
    Rajarajan, Muttukrishnan
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 414 - 421
  • [3] Analyzing Android Code Graphs against Code Obfuscation and App Hiding Techniques
    Badhani, Shikha
    Muttoo, Sunil K.
    JOURNAL OF APPLIED SECURITY RESEARCH, 2019, 14 (04) : 489 - 510
  • [4] BLADE: Robust malware detection against obfuscation in android
    Sihag, Vikas
    Vardhan, Manu
    Singh, Pradeep
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2021, 38
  • [5] Vulnerability Evaluation of Android Malware Detectors against Adversarial Examples
    Ijas, A. H.
    Vinod, P.
    Zemmari, Akka
    Harikrishnan
    Poulose, Godvin
    Jose, Don
    Mercaldo, Francesco
    Martinelli, Fabio
    Santone, Antonella
    KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS (KSE 2021), 2021, 192 : 3320 - 3331
  • [6] BLADE: Robust malware detection against obfuscation in android
    Sihag, Vikas
    Vardhan, Manu
    Singh, Pradeep
    Forensic Science International: Digital Investigation, 2021, 38
  • [7] A Survey of Obfuscation and Deobfuscation Techniques in Android Code Protection
    Guo, Runsheng
    Liu, Qichao
    Zhang, Man
    Hu, Ning
    Lu, Hui
    Proceedings - 2022 7th IEEE International Conference on Data Science in Cyberspace, DSC 2022, 2022, : 40 - 47
  • [8] Impact of Code Obfuscation on Android Malware Detection based on Static and Dynamic Analysis
    Bacci, Alessandro
    Bartoli, Alberto
    Martinelli, Fabio
    Medvet, Eric
    Mercaldo, Francesco
    Visaggio, Corrado Aaron
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 379 - 385
  • [9] Evasion Attacks Against Statistical Code Obfuscation Detectors
    Su, Jiawei
    Vargas, Danilo Vasconcellos
    Sakurai, Kouichi
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2017, 2017, 10418 : 121 - 137
  • [10] Evasion attacks against statistical code obfuscation detectors
    Su, Jiawei
    Vargas, Danilo Vasconcellos
    Sakurai, Kouichi
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2017, 10418 LNCS : 121 - 137