arrow
Return

Auditing Anti-Malware Tools by Evolving Android Malware and Dynamic Loading Technique

delete2017-07-01
delete54
delete
OA
AI
Y
Yinxing Xue *
G
Guozhu Meng
刘洋 (Yang Liu)
T
Tian Tan
H
Hongxu Chen
孙俊 cover
孙俊 (Jun Sun)
J
Jie Zhang
DOI:10.1109/TIFS.2017.2661723delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Although a previous paper shows that existing antimalware tools (AMTs) may have high detection rate, the report is based on existing malware and thus it does not imply that AMTs can effectively deal with future malware. It is desirable to have an alternative way of auditing AMTs. In our previous paper, we use malware samples from android malware collection GENOME to summarize a malware meta-model for modularizing the common attack behaviors and evasion techniques in reusable features. We then combine different features with an evolutionary algorithm, in which way we evolve malware for variants. Previous results have shown that the existing AMTs only exhibit detection rate of 20%-30% for 10 000 evolved malware variants. In this paper, based on the modularized attack features, we apply the dynamic code generation and loading techniques to produce malware, so that we can audit the AMTs at runtime. We implement our approach, named MYSTIQUE-S, as a service-oriented malware generation system. MYSTIQUE-S automatically selects attack features under various user scenarios and delivers the corresponding malicious payloads at runtime. Relying on dynamic code binding (via service) and loading (via reflection) techniques, MYSTIQUE-S enables dynamic execution of payloads on user devices at runtime. Experimental results on real-world devices show that existing AMTs are incapable of detecting most of our generated malware. Last, we propose the enhancements for existing AMTs.
Keywords:
Android feature model
defense capability
malware generation
dynamic loading
linear programming
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

S
singapore university of technology & design
Scholars:
2.8K
Papers: 3.6K
Citations: 5
N
Nanyang Technological University
Scholars:
4.9W
Papers: 4.8W
Citations: 8.1W