RiskRanker: Scalable and Accurate Zero‐day Android Malware Detection.

Slides:



Advertisements
Similar presentations
Module 13: Performance Tuning. Overview Performance tuning methodologies Instance level Database level Application level Overview of tools and techniques.
Advertisements

Dissecting Android Malware : Characterization and Evolution
Next Generation Endpoint Security Jason Brown Enterprise Solution Architect McAfee May 23, 2013.
By Hiranmayi Pai Neeraj Jain
Vaibhav Rastogi, Yan Chen, and Xuxian Jiang
Day anti-virus anti-virus 1 detecting a malicious file malware, detection, hiding, removing.
Policy Weaving for Mobile Devices Drew Davidson. Smartphone security is critical – 1200 to 1400 US Army troops to be equipped with Android smartphones.
1 Detection of Injected, Dynamically Generated, and Obfuscated Malicious Code (DOME) Subha Ramanathan & Arun Krishnamurthy Nov 15, 2005.
Automated Remote Repair for Mobile Malware Yacin Nadji, Jonathon Giffin, Patrick Traynor Georgia Institute of Technology ACSAC’ 11.
DSPIN: Detecting Automatically Spun Content on the Web Qing Zhang, David Y. Wang, Geoffrey M. Voelker University of California, San Diego 1.
Aurasium: Practical Policy Enforcement for Android Applications R. Xu, H. Saidi and R. Anderson Presented By: Rajat Khandelwal – 2009CS10209 Parikshit.
An Authentication Service Against Dishonest Users in Mobile Ad Hoc Networks Edith Ngai, Michael R. Lyu, and Roland T. Chin IEEE Aerospace Conference, Big.
Mobile Malware in the Wild Acknowledgement: Hiromu Enoki.
Presentation By Deepak Katta
Jarhead Analysis and Detection of Malicious Java Applets Johannes Schlumberger, Christopher Kruegel, Giovanni Vigna University of California Annual Computer.
Automated malware classification based on network behavior
Introduction to Mobile Malware
Presentation by Kathleen Stoeckle All Your iFRAMEs Point to Us 17th USENIX Security Symposium (Security'08), San Jose, CA, 2008 Google Technical Report.
Secure Embedded Processing through Hardware-assisted Run-time Monitoring Zubin Kumar.
DroidKungFu and AnserverBot
Lei Wu, Michael Grace, Yajin Zhou, Chiachih Wu, Xuxian Jiang Department of Computer Science North Carolina State University CCS 2013.
Mobile Devices Carry Hidden Threats With Financial Consequences Hold StillInstalled.
Harvesting Developer Credentials in Android Apps
All Your Droid Are Belong To Us: A Survey of Current Android Attacks 단국대학교 컴퓨터 보안 및 OS 연구실 김낙영
Presented by: Kushal Mehta University of Central Florida Michael Spreitzenbarth, Felix Freiling Friedrich-Alexander- University Erlangen, Germany michael.spreitzenbart,
Understanding and Troubleshooting Your PC. Chapter 12: Maintenance and Troubleshooting Fundamentals2 Chapter Objectives  In this chapter, you will learn:
BY ANDREA ALMEIDA T.E COMP DON BOSCO COLLEGE OF ENGINEERING.
Is Your Mobile App Secure. DEF CON 23 Wall of Sheep Sat
Behavior-based Spyware Detection By Engin Kirda and Christopher Kruegel Secure Systems Lab Technical University Vienna Greg Banks, Giovanni Vigna, and.
Cloud-based Antivirus Project Proposal By Yuli Deng, Guofu Xiong.
 Two types of malware propagating through social networks, Cross Site Scripting (XSS) and Koobface worm.  How these two types of malware are propagated.
University of Central Florida TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones Written by Enck, Gilbert,
Effective Real-time Android Application Auditing
AccessMiner Using System- Centric Models for Malware Protection Andrea Lanzi, Davide Balzarotti, Christopher Kruegel, Mihai Christodorescu and Engin Kirda.
Android Security Auditing Slides and projects at samsclass.info.
Attack Tool Repository and Player for ISEAGE May06-11 Abstract Today’s world is changing shape as it increases its dependency on computer technology. As.
CompSci 725 RiskRanker Authors Michael Grace - North Carolina State University, Raleigh, NC, USA & NQ Mobile Security Research Center, Beijing, China Yajin.
Grace. M, Zhou. Y, Shilong. Z, Jiang. X.  RiskRanker analyses the paths within an android application  Potentially malicious security risks are flagged.
Topic 5: Basic Security.
1 Chapter 9 Intruders. 2 Outline Intruders –Intrusion Techniques –Password Protection –Password Selection Strategies –Intrusion Detection Statistical.
DETECTING TARGETED ATTACKS USING SHADOW HONEYPOTS AUTHORS: K. G. Anagnostakisy, S. Sidiroglouz, P. Akritidis, K. Xinidis, E. Markatos, A. D. Keromytisz.
LOGOPolyUnpack: Automating the Hidden-Code Extraction of Unpack-Executing Malware Royal, P.; Halpin, M.; Dagon, D.; Edmonds, R.; Wenke Lee; Computer Security.
Search Worms, ACM Workshop on Recurring Malcode (WORM) 2006 N Provos, J McClain, K Wang Dhruv Sharma
Slides and projects at samsclass.info. Adding Trojans to Apps Slides and projects at samsclass.info.
Malicious Software.
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Wireless and Mobile Security
Title of Presentation DD/MM/YYYY © 2015 Skycure Why Are Hackers Winning the Mobile Malware Battle.
Chapter 9 Intruders.
Introduction Program File Authorization Security Theorem Active Code Authorization Authorization Logic Implementation considerations Conclusion.
Android Permissions Demystified
Chapter 8 System Management Semester 2. Objectives  Evaluating an operating system  Cooperation among components  The role of memory, processor,
VMM Based Rootkit Detection on Android
Keyword search on encrypted data. Keyword search problem  Linux utility: grep  Information retrieval Basic operation Advanced operations – relevance.
THREATS, VULNERABILITIES IN ANDROID OS BY DNYANADA PRAMOD ARJUNWADKAR AJINKYA THORVE Guided by, Prof. Shambhu Upadhyay.
AppAudit Effective Real-time Android Application Auditing Andrew Jeong
Cosc 4765 Antivirus Approaches. In a Perfect world The best solution to viruses and worms to prevent infected the system –Generally considered impossible.
CloudAV: N-Version Antivirus in the Network Cloud Jon Oberheide, Evan Cooke, Farnam Jahanian Electrical Engineering and Computer Science Department, University.
Chapter 40 Internet Security.
Chapter 9 Intruders.
Harvesting Runtime Values in Android Applications That Feature Anti-Analysis Techniques Presented by Vikraman Mohan.
TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTime Sadiq Basha.
Presented by Xiaohui (Amy) Lin
Siegfried Rasthofer, Steven Arzt, Marc Miltenberger, Eric Bodden
Analyzing WebView Vulnerabilities in Android Applications
Android.Adware.Plankton.A % Android.Adware.Wapsx.A – 4.73%
Chapter 9 Intruders.
Ransomware in Web Apps OWASP Singapore.
Mobile App Advertisements
Presentation transcript:

RiskRanker: Scalable and Accurate Zero‐day Android Malware Detection

Introduction/Motivation: What was the main problem addressed? Mobile devices have become popular targets for malware authors, threatening privacy, security, and finances.  The growth in the number of malicious and high risk Android apps has far exceeded predictions.

Introduction/Motivation: What was the main problem addressed? From Wiki: Traditionally, antivirus software relies upon signatures to identify malware. This can be very effective, but cannot defend against malware unless samples have already been obtained, signatures generated and updates distributed to users. Because of this, signature‐based approaches are not effective against zero‐day viruses. A Zero day virus is a previously unknown computer virus or other malware for which specific antivirus software signatures are not yet available.

Introduction/Motivation: What was the main problem addressed? Traditional signature based Reactive malware detectionistoo slowtorespondtorateofnewthreatgeneration. Malware is only operating. detected afterit has been installedand GooglePlay and alternative stores make distributingmalware simple. ( Apple’s review process has prevented approving malware at its store. So far ).

Introduction/Motivation: What was the main problem addressed? The authors proposed and implemented a proactive prototype zero‐day malware detection scheme, called RiskRanker, which flags malware while it is still at the app store. Store curators can then remove the app from distribution.

Introduction/Motivation: What will be learned?  The authors wish to demonstrate that a proactive approach can detect zero‐day malware. Their system does not require prior recognition of malware threat and updating of remote devices a new Their system can detect the threat while still in the app store

Related Work: What else has been done to solve this problem? Reactive malware detection systems  ProfileDroid (week 10 paper). Detected various system calls, network access, and resource utilization. Could potentially detect malware in operation.  Stowaway. Static analysis tool to detect over‐privilege access in Droid apps.  TaintDroid. Dynamic analysis to detect information leaks on phones.

Methodology Approach and Design The prototype system was designed to be scalable, paralizable, and accurately sift through a large number of apps from various Android markets The goal was to reduce and rank suspected apps by risk, from a large list to one that was short enough to verify manually. RiskRanker sends apps through 2 sets of analyzers: A set of first order modules evaluate straightforward risks (malware not hiding malicious elements) A set of second order modules looks for techniques that indicate malicious code is being purposely hidden from detection.

Methodology Approach and Design First Order analysis Detecting high‐risk apps Look for known exploits (see table 1) which leverage platform level vulnerabilities from use of native Android code Can reduce search set by finding presence of native code. Such exploits bypass built in security measures Identify vulnerability specific signature of exploit (Exploid utilizing init daemon).

Results Verification experiments First Order Analysis Results High‐risk apps found (Table 3) 24 High risk apps using known root exploits Only 3 Table 1 exploits in use (Exploid, RATC, GingerBreak) Found some exploits repackaged into popular legit apps System also detected legit (??) jail break tool

Methodology Approach and Design First Order analysis Detecting medium‐risk apps Look for behaviors that result in surreptitious charges Sending SMS to premium phone numbers (and earn malware authors $$$) Need to distinguish legitimate use of such functions Assume legitimate actions initiated actions which invoke callbacks (button press callback) Perform static data‐flow and control‐flow of Dalvik bytecode to see that money charging operations trace back to callbacks Such analysis complicated by concurrent operations, code obfuscation, reflection, and actions initiated in external threads. Minimize such issues by employing backward and forward slicing.  Slicing is technique of identifying reachable code or data

Methodology Approach and Design First Order analysis Detecting medium‐risk apps Sources of Ambiguity: 1.Class Hierarchy 2.Possible values each term in a comparison can take 3.Native Code 4.Reflection language Feature

Methodology Approach and Design First Order analysis

Results Verification experiments First Order Analysis Results Medium‐risk apps found (Table 2437 apps were found to send background SMS Of these, only 1223 distinct paths 4) A person manually analyzed these in 2 days. Of these, 94 paths were malicious Overall of 2437 medium‐risk apps, 206 were infected, including 8 zero‐day malware families.

s. Methodology Approach and Design Second Order analysis ‐ Look for patterns common and rare in legitimate apps tomalware, Pre‐processing Look for secondary (child) apps within host app. Look for apk or jar files saved in assets or res directorie Encrypted native code execution Hides signature of malevolent code Look for calls to decryption routines Unsafe Dalvik code loading Load malevolent code at runtime Bypasses discovery during static analysis Look for use of DexClassLoader

Results Verification experiments Second Order Analysis Results Medium-risk apps found (Table 328 apps encrypt native code 5) 4257 apps feature dynamic code loading, 1655 contain a child package, there are 492 apps in common. Some are legit. These signatures were white listed to reduce the number of apps being considered. They found one very nasty zero-day app (AnserverBot, removesmobile security software, and other things), and released a security alert.

Methodology : Prototyping and Evaluation RiskRanker implemented as Linux application, using 3.6 K lines of Python, and 8.7 K of Java. Contains high‐risk root exploit detection module aware of 7 kinds of known exploits (see Table 1, which only shows 6?). Contains medium‐risk detection module which scans for Sending background SMS Making background phone calls Uploading call logs Uploading received SMS messages Apps were preprocessed and data placed into MySQL to allow quick indexing and lookup.

Methodology : Prototyping and Evaluation 118,318 apps were collected over 2 months from GooglePlay (49.8%) and 14 alternate markets. Due to overlap in markets, this came to 104,874 distinct apps RiskRanker analyzed apps on a local 5 node cluster, with each node having 8 cores and 8GB of memory On this system, RiskRanker could process 3500 apps per hour Collected apps were processed in 30 hours.

Results Verification experiments From this collection, RiskRanker identified: 718 malicious apps from 29 malware families Of these, 322 were zero‐day from 11 new families First order risk analysis revealed 220 malware samples from 25 families Second order risk analysis found 499 samples from 6 families Summary of results in Table 2

Results Verification experiments

Results Verification experiments False Negative Measurements The authors demonstrated the effectiveness of RiskRanker in finding new (zero‐day) threats.  They then downloaded a set of known malware from a public contagion repository (exists for research?)  After removing duplicates, the set consisted of 133 apps from 31 families. RiskRanker identified 121 of the 133 malevolent apps.  Analysis determined that the detection failures were out of scope of the detection modules of RiskRanker.

Results Verification experiments Malware Distribution Breakdown: Malware could be detected in all of the markets (GooglePlay included)  At one market, 220 apps, or 3% of their offerings were infected. 4 alternative markets offered at least 90 malware apps.  Google only had 2 out of 52,208 apps infected. This may be due to adoption of GoogleBouncer (its approach to cleansing their market is unknown)

Discussions/Conclusions/Future Work The authors found that their RiskRanker system detected previously unknown malware from various stores. The system, even in a limited prototype stage, was very effective They discuss some weaknesses: obfuscation complicates path analysis  a malware author could write their own crypto routine, so the known call used for detection is skipped.  Can hide malicious code as a large array of innocent looking bytes.

References Wiki ( Trend Micro Warns of Increased Android Malware, Stephanie Mlot, For malware growth figure and broken android art. RiskRanker: Scalable and Accurate Zero‐day Android Malware Detection, Michael Grace †, Yajin Zhou †, Qiang Zhang, Shihong Zou, Xuxian Jiang † †North Carolina State University NQ Mobile Security Research Center {mcgrace, yajin zhou, {zhangqiang, A Survey of Mobile Malware in the Wild, Adrienne Porter Felt, Matthew Finifter, Erika Chin, Steven Hanna, and David Wagner University of California, Berkeley

Thank You