NexTech 2021 Congress
October 03, 2021 to October 07, 2021 - Barcelona, Spain

  • UBICOMM 2021, The Fifteenth International Conference on Mobile Ubiquitous Computing, Systems, Services and Technologies
  • ADVCOMP 2021, The Fifteenth International Conference on Advanced Engineering Computing and Applications in Sciences
  • SEMAPRO 2021, The Fifteenth International Conference on Advances in Semantic Processing
  • AMBIENT 2021, The Eleventh International Conference on Ambient Computing, Applications, Services and Technologies
  • EMERGING 2021, The Thirteenth International Conference on Emerging Networks and Systems Intelligence
  • DATA ANALYTICS 2021, The Tenth International Conference on Data Analytics
  • GLOBAL HEALTH 2021, The Tenth International Conference on Global Health Challenges
  • CYBER 2021, The Sixth International Conference on Cyber-Technologies and Cyber-Systems

SoftNet 2021 Congress
October 03, 2021 to October 07, 2021 - Barcelona, Spain

  • ICSEA 2021, The Sixteenth International Conference on Software Engineering Advances
  • ICSNC 2021, The Sixteenth International Conference on Systems and Networks Communications
  • CENTRIC 2021, The Fourteenth International Conference on Advances in Human-oriented and Personalized Mechanisms, Technologies, and Services
  • VALID 2021, The Thirteenth International Conference on Advances in System Testing and Validation Lifecycle
  • SIMUL 2021, The Thirteenth International Conference on Advances in System Simulation
  • SOTICS 2021, The Eleventh International Conference on Social Media Technologies, Communication, and Informatics
  • INNOV 2021, The Tenth International Conference on Communications, Computation, Networks and Technologies
  • HEALTHINFO 2021, The Sixth International Conference on Informatics and Assistive Technologies for Health-Care, Medical Support and Wellbeing

NetWare 2021 Congress
November 14, 2021 to November 18, 2021 - Athens, Greece

  • SENSORCOMM 2021, The Fifteenth International Conference on Sensor Technologies and Applications
  • SENSORDEVICES 2021, The Twelfth International Conference on Sensor Device Technologies and Applications
  • SECURWARE 2021, The Fifteenth International Conference on Emerging Security Information, Systems and Technologies
  • AFIN 2021, The Thirteenth International Conference on Advances in Future Internet
  • CENICS 2021, The Fourteenth International Conference on Advances in Circuits, Electronics and Micro-electronics
  • ICQNM 2021, The Fifteenth International Conference on Quantum, Nano/Bio, and Micro Technologies
  • FASSI 2021, The Seventh International Conference on Fundamentals and Advances in Software Systems Integration
  • GREEN 2021, The Sixth International Conference on Green Communications, Computing and Technologies

TrendNews 2021 Congress
November 14, 2021 to November 18, 2021 - Athens, Greece

  • CORETA 2021, Advances on Core Technologies and Applications
  • DIGITAL 2021, Advances on Societal Digital Transformation

 


ThinkMind // ICIMP 2018, The Thirteenth International Conference on Internet Monitoring and Protection // View article icimp_2018_2_20_30028


A Hybrid Approach for Enhancing Android Sandbox Analysis

Authors:
Ngoc-Tu Chau
Jaehyeon Yoon
Souhwan Jung

Keywords: Android Analysis; Sensitive Information Provider; Anti-Analysis

Abstract:
Dynamic analysis solutions are applied to prevent malicious applications from bypassing Android sandbox using dynamic payload techniques. However, such dynamic analysis methods are vulnerable to malware that use Anti-Analysis and Anti-Emulator techniques. Malicious applications use Anti- Emulation techniques to archive sensitive information that can be used to distinguish between sandbox and real device. Upon identifying sandbox environment, malicious applications may implement several of evasion techniques to avoid from being analyzed. The main problem, however, is that it can be easy for even a novice user to get sensitive information provided by a sandbox with just a little effort. Although there are work-around solutions for solving the problem by directly updating the sensitive information before building the sandbox, they are still containing some limitations in practice. Firstly, it is inconvenient to change the sensitive information after the sandbox or instrumentation module are deployed. Secondly, the updated information can be inconsistent and illogical. To provide a flexible approach for these issues, this paper proposes a dynamic approach that updates the sensitive information based on Sensitive Information Provider server that is located outside the sandbox. The Sensitive Information Provider (SIP) could be a collector that retrieves and processes sensitive information from one or more seeder mobile devices or could be a set of mobile devices. Because of the device-based information, the proposed approach provides a consistence and logic output when it is compared with other solutions. Furthermore, since the proposed solution separates the source of sensitive information from the sandbox, it is possible to update the sensitive information even after the sandbox was deployed. However, the proposed approach sacrifices performance to flexibility and thus it is only suitable to specific environments. The implementation section also analyzes the use-cases which are suitable to apply the proposed solution.

Pages: 30 to 34

Copyright: Copyright (c) IARIA, 2018

Publication date: July 22, 2018

Published in: conference

ISSN: 2308-3980

ISBN: 978-1-61208-652-1

Location: Barcelona, Spain

Dates: from July 22, 2018 to July 26, 2018

SERVICES CONTACT
2010 - 2017 © ThinkMind. All rights reserved.
Read Terms of Service and Privacy Policy.