arrow
Return

Secure Repackage-Proofing Framework for Android Apps Using Collatz Conjecture

delete2022-09-01
delete2
delete
OA
AI
H
Haoyu Ma
S
Shijia Li
D
Debin Gao
C
Chunfu Jia *
DOI:10.1109/TDSC.2021.3091654delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
App repackaging has been raising serious concerns about the health of the Android ecosystem, and repackage-proofing is an important mitigation against threat of such attacks. However, existing app repackage-proofing schemes were only evaluated against trivial adversaries simulated using analyzers for other purposes (e.g., disclosing privacy leakage vulnerabilities), hence were shown effective mainly because their key programming features were not even supported by those toolkits. Furthermore, existing works have also neglected dynamic adversaries capable of manipulating victim apps at runtime, making them vulnerable against such stronger opponents. In this article, we propose a novel repackage-proofing framework, which deploys distributed detection and response sites into the subject app's native partition to cross-verify all its code files. The detection sites transmit obtained integrity metrics to response sites via secure communication channels built on the subject app's own control flows using a specialized obfuscation technique based on Collatz conjecture, turning the repackage-proofing process into complicated implicit flows that are intrinsically difficult to be resolved due to the conjecture's nonlinear dynamical behaviors. We evaluated our framework using sophisticated Android data-flow analyzers. Results showed that our prototype effectively impeded analyses aiming to trace the information flows of its cross-verification.
Keywords:
Payloads
Smart phones
Measurement
Runtime
Communication channels
Weapons
Manipulator dynamics
App repackaging
repackage-proofing
code obfuscation
collatz conjecture

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

S
Singapore Management University
Scholars:
1.5K
Papers: 2.5K
Citations: 3.5K
N
nankai university
Scholars:
4.8W
Papers: 3.3W
Citations: 74
Cited Papers

Cited Papers

errShare
errSave
Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting
err2017-06-01
err106
errOAAI
errLi, Li; Li, Daoyuan; Bissyande, Tegawende F.; Klein, Jacques; Le Traon, Yves; Lo, David; Cavallaro, Lorenzo
errShare
errSave
Anhydrous lithium borate, Li3B11O18, crystal structure, phase transition and thermal expansion
err2014-06-26
err0
PREAI
errNatalia Sennova; Barbara Albert; Rimma Bubnova; Maria Krzhizhanovskaya; Stanislav Filatov
errShare
errSave
err
IF0
err
err0
PREAI
err
errShare
errSave
Deep architectures for protein contact map prediction
err2012-07-30
err0
errOAAI
errPietro Di Lena; Ken Nagata; Pierre Baldi
errShare
errSave
researcher View more