论文标题

当警卫失败时,机器人:Android恶意软件的案例研究

When the Guard failed the Droid: A case study of Android malware

论文作者

Berger, Harel, Hajaj, Chen, Dvir, Amit

论文摘要

Android恶意软件是对全球数十亿用户的持续威胁。作为对策,有时会实现Android恶意软件检测系统。但是,这些系统通常容易受到\ emph {逃避攻击}的攻击,其中对手会操纵恶意实例,以使它们被误认为是良性的。在本文中,我们针对多种Android恶意软件检测系统发起了各种创新的逃避攻击。所有这些系统固有的漏洞是它们是Androguard〜\ cite {desnos2111androguard}的一部分,这是一个流行的开源库中,用于Android恶意软件检测系统。攻击后,某些检测系统降至0 \%检测率。因此,在恶意软件检测系统中使用开源库需要谨慎。 此外,我们提出了一种新的逃避攻击生成评估方案,该方案利用了已知的Android恶意软件检测系统的弱点。这样一来,我们评估了我们逃避攻击所造成的操纵实例的功能和恶意。我们发现操纵应用程序的恶意和功能测试都有变化。我们表明,非功能性应用程序虽然被认为是恶意的,却不会威胁用户,因此从攻击者的角度来看,无用。我们得出的结论是,必须评估逃避攻击的功能和恶意,以评估其影响,这一步骤远非当今很普遍。

Android malware is a persistent threat to billions of users around the world. As a countermeasure, Android malware detection systems are occasionally implemented. However, these systems are often vulnerable to \emph{evasion attacks}, in which an adversary manipulates malicious instances so that they are misidentified as benign. In this paper, we launch various innovative evasion attacks against several Android malware detection systems. The vulnerability inherent to all of these systems is that they are part of Androguard~\cite{desnos2011androguard}, a popular open source library used in Android malware detection systems. Some of the detection systems decrease to a 0\% detection rate after the attack. Therefore, the use of open source libraries in malware detection systems calls for caution. In addition, we present a novel evaluation scheme for evasion attack generation that exploits the weak spots of known Android malware detection systems. In so doing, we evaluate the functionality and maliciousness of the manipulated instances created by our evasion attacks. We found variations in both the maliciousness and functionality tests of our manipulated apps. We show that non-functional apps, while considered malicious, do not threaten users and are thus useless from an attacker's point of view. We conclude that evasion attacks must be assessed for both functionality and maliciousness to evaluate their impact, a step which is far from commonplace today.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源