Proceedings Article10.1109/DSN.2016.56
Repackage-Proofing Android Apps
Lannan Luo,Yu Fu,Dinghao Wu,Sencun Zhu,Peng Liu +4 more
- 01 Jun 2016
- pp 550-561
38
TL;DR: A technique is proposed that builds a reliable and stealthy repackage-proofing capability into Android apps and injects a failure in the form of delayed malfunctions, making it difficult to trace back once repackaging is detected.
read more
Abstract: App repackaging has become a severe threat to theAndroid ecosystem. While various protection techniques, such aswatermarking and repackaging detection, have been proposed, adefense that stops repackaged apps from working on user devices, i.e., repackage-proofing, is missing. We propose a technique thatbuilds a reliable and stealthy repackage-proofing capability intoAndroid apps. A large number of detection nodes are insertedinto the original app without incurring much overhead, each iswoven into the surrounding code to blur itself. Once repackagingis detected, a response node injects a failure in the form ofdelayed malfunctions, making it difficult to trace back. Theresponse nodes and detection nodes form high-degree connectionsand communicate through stealthy communication channels, suchthat upon detection several of the many response nodes areselected stochastically to take actions, which further obfuscatesand enhances the protection. We have built a prototype. Theevaluation shows that the technique is effective and efficient.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Semantics-Based Obfuscation-Resilient Binary Code Similarity Comparison with Applications to Software and Algorithm Plagiarism Detection
TL;DR: The experimental results show that the proposed binary-oriented, obfuscation-resilient binary code similarity comparison method can be applied to software plagiarism and algorithm detection, and is effective and practical to analyze real-world software.
149
A survey of android application and malware hardening
TL;DR: A taxonomy of Android malware hardening techniques available in the literature can be found in this paper, where the authors present an overview of Android and its state of the art security services.
61
Resilient decentralized Android application repackaging detection using logic bombs
Qiang Zeng,Lannan Luo,Zhiyun Qian,Xiaojiang Du,Zhoujun Li +4 more
- 24 Feb 2018
TL;DR: A prototype, named BombDroid, is implemented that builds the repackaging detection into apps through bytecode instrumentation, and the evaluation shows that the technique is effective, efficient, and resilient to various adversary analysis including symbol execution, multi-path exploration, and program slicing.
30
Leveraging Information Asymmetry to Transform Android Apps into Self-Defending Code Against Repackaging Attacks
Kai Chen,Yingjun Zhang,Peng Liu +2 more
TL;DR: To the best of the knowledge, this is the first work that lets repackaged apps automatically malfunction while having none effect on a benign app's function, and a smartphone anti-repackaging system prototype is built.
24
A Taxonomy of Software Integrity Protection Techniques
Mohsen Ahmadvand,Alexander Pretschner,Florian Kelbert +2 more
- 01 Jan 2019
TL;DR: A taxonomy of integrity protection techniques for man-at-the-end (MATE) attacks is presented in this paper, which includes system, defense, and attack perspectives.
22
References
•Proceedings Article
Brahmastra: driving apps to test the security of third-party components
Ravi Bhoraskar,Seungyeop Han,Jinseong Jeon,Tanzirul Azim,Shuo Chen,Jaeyeon Jung,Suman Nath,Rui Wang,David Wetherall +8 more
- 20 Aug 2014
TL;DR: An app automation tool called Brahmastra is presented for helping app stores and security researchers to test third-party components in mobile apps at runtime and uses static analysis to construct a page transition graph and discover execution paths to invoke third- party code.
AppInk: watermarking android apps for repackaging deterrence
Wu Zhou,Xinwen Zhang,Xuxian Jiang +2 more
- 08 May 2013
TL;DR: This work proposes and develops a watermarking mechanism for Android apps, which takes the source code of an app as input to automatically generate a new app with a transparently-embedded watermark and the associated manifest app, and introduces small performance overhead.
115
Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform
Andrew Henderson,Aravind Prakash,Lok Kwong Yan,Xunchao Hu,Xujiewen Wang,Rundong Zhou,Heng Yin +6 more
- 21 Jul 2014
TL;DR: DECAF is presented, a virtual machine based, multi-target, whole-system dynamic binary analysis framework built on top of QEMU, which provides Just-In-Time Virtual Machine Introspection combined with a novel TCG instruction-level tainting at bit granularity, backed by a plugin based, simple-to-use event driven programming interface.
103
Value-based program characterization and its application to software plagiarism detection
Yoon-Chan Jhi,Xinran Wang,Xiaoqi Jia,Sencun Zhu,Peng Liu,Dinghao Wu +5 more
- 21 May 2011
TL;DR: This work introduces a novel approach to dynamic characterization of executable programs based on an observation that some critical runtime values are hard to be replaced or eliminated by semantics-preserving transformation techniques and how to apply this runtime property to help solve problems in software plagiarism detection.
A Framework for Evaluating Mobile App Repackaging Detection Algorithms
Heqing Huang,Sencun Zhu,Peng Liu,Dinghao Wu +3 more
- 17 Jun 2013
TL;DR: This work proposes a framework to evaluate the obfuscation resilience of repackaging detection algorithms comprehensively, and applies this framework to conduct a comprehensive case study on AndroGuard, an Android repackaged detector proposed in Black-hat 2011.