Back to Search
Start Over
GroDDViewer: Dynamic Dual View of Android Malware
- Source :
- GraMSec 2020-7th Seventh International Workshop on Graphical Models for Security, GraMSec 2020-7th Seventh International Workshop on Graphical Models for Security, Jun 2020, Virtual Conference, France. pp.127-139, ⟨10.1007/978-3-030-62230-5_7⟩, Graphical Models for Security ISBN: 9783030622299, GraMSec@CSF
- Publication Year :
- 2020
- Publisher :
- HAL CCSD, 2020.
-
Abstract
- International audience; Understanding an Android malware is a difficult task that requires strong skills in reverse engineering. Few tools exist except the well know IDA and Ghidra tools that are more focused on the analysis of binaries. In the Android world, understanding a malware requires to analyze the bytecode of the application, possibly obfuscated or hidden in a benign application that has been modified. At execution time, the malware can download new payloads, compromise the smartphone, and install new apps. We believe that a security analyst would appreciate to visualize and replay an execution of an Android malware. In particular, an analysis that bridges the gap between the bytecode and the events occurring during the execution would help to understand the malware behavior. In this article, we propose GroDDViewer the first tool offering a dual view of the execution of an Android malware. The first view represents the execution at operating system level through the representation of all information flow between files, processes and sockets. The second view represents what happened in the code of the application, during its execution. The benefit of this visualization tool is illustrated on a ransomware sample. In future, we plan to evaluate the tool with a panel of users on a benchmark of malware samples.
- Subjects :
- Reverse engineering
021110 strategic, defence & security studies
MESH: Malware, Visualization
business.industry
Computer science
malware
0211 other engineering and technologies
02 engineering and technology
Operating system level
computer.software_genre
01 natural sciences
Visualization
010309 optics
Bytecode
[INFO.INFO-CR]Computer Science [cs]/Cryptography and Security [cs.CR]
Android malware
0103 physical sciences
Ransomware
Malware
Android (operating system)
Software engineering
business
computer
visualization
Subjects
Details
- Language :
- English
- ISBN :
- 978-3-030-62229-9
- ISBNs :
- 9783030622299
- Database :
- OpenAIRE
- Journal :
- GraMSec 2020-7th Seventh International Workshop on Graphical Models for Security, GraMSec 2020-7th Seventh International Workshop on Graphical Models for Security, Jun 2020, Virtual Conference, France. pp.127-139, ⟨10.1007/978-3-030-62230-5_7⟩, Graphical Models for Security ISBN: 9783030622299, GraMSec@CSF
- Accession number :
- edsair.doi.dedup.....23f964a069d44c091a75b0278f72d76d