Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Difuzer: Uncovering Suspicious Hidden Sensitive Operations in Android Apps
SAMHI, Jordan; Li, Li; BISSYANDE, Tegawendé François D Assise et al.
2022In 44th International Conference on Software Engineering (ICSE 2022)
Peer reviewed
 

Documents


Texte intégral
difuzer_preprint.pdf
Preprint Auteur (863.82 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Static Analysis; Android Security; Logic Bomb
Résumé :
[en] One prominent tactic used to keep malicious behavior from being detected during dynamic test campaigns is logic bombs, where malicious operations are triggered only when specific conditions are satisfied. Defusing logic bombs remains an unsolved problem in the literature. In this work, we propose to investigate Suspicious Hidden Sensitive Operations (SHSOs) as a step towards triaging logic bombs. To that end, we develop a novel hybrid approach that combines static analysis and anomaly detection techniques to uncover SHSOs, which we predict as likely implementations of logic bombs. Concretely, Difuzer identifies SHSO entry-points using an instrumentation engine and an inter-procedural data-flow analysis. Then, it extracts trigger-specific features to characterize SHSOs and leverages One-Class SVM to implement an unsupervised learning model for detecting abnormal triggers. We evaluate our prototype and show that it yields a precision of 99.02% to detect SHSOs among which 29.7% are logic bombs. Difuzer outperforms the state-of-the-art in revealing more logic bombs while yielding less false positives in about one order of magnitude less time. All our artifacts are released to the community.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Trustworthy Software Engineering (TruX)
Disciplines :
Sciences informatiques
Auteur, co-auteur :
SAMHI, Jordan  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
Li, Li;  Monash University
BISSYANDE, Tegawendé François D Assise  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KLEIN, Jacques  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Difuzer: Uncovering Suspicious Hidden Sensitive Operations in Android Apps
Date de publication/diffusion :
21 mai 2022
Nom de la manifestation :
44th International Conference on Software Engineering (ICSE 2022)
Lieu de la manifestation :
Pittsburgh, Etats-Unis
Date de la manifestation :
from 21-05-2022 to 29-05-2022
Manifestation à portée :
International
Titre de l'ouvrage principal :
44th International Conference on Software Engineering (ICSE 2022)
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR14596679 - Dissecting Android Applications Using Static Analysis, 2020 (01/03/2020-31/10/2023) - Jordan Samhi
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 04 janvier 2022

Statistiques


Nombre de vues
323 (dont 23 Unilu)
Nombre de téléchargements
118 (dont 7 Unilu)

citations Scopus®
 
32
citations Scopus®
sans auto-citations
19
OpenCitations
 
1
citations OpenAlex
 
25

Bibliographie


Publications similaires



Contacter ORBilu