updroid: updated android malware and its familial...

17
UpDroid: Updated Android Malware and Its Familial Classification Kursat Aktas, Assoc. Prof. Sevil Sen WISE Lab. Hacettepe University

Upload: others

Post on 27-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

UpDroid: Updated Android Malware and

Its Familial Classification

Kursat Aktas, Assoc. Prof. Sevil Sen

WISE Lab.Hacettepe University

Page 2: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification
Page 3: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Mobile Security

📫 New mobile variants.

- Android is among the most targeted platforms by attackers.

- Mobile devices are usually protected by static analysis-based solutions. - Vulnerable to new attacks.- Vulnerable to new variants of existing attacks.

Page 4: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Updating

o One of the most effective evasion strategies.

Update attackso Does not contain any malicious code at the

installation phase.o Add its malicious code at runtime.

Page 5: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

UpDroid: Updated Android Malware

Page 6: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Collecting AppsKoodous oRecently submitted applications oNot detected by other analysists oContaining at least on loading activityoCollected 11490 apps

ApkpureoMost popular apps from each categoryoCollected 6299 apps

Page 7: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Analysis of Apps

Each app is run for 15 minutes.DroidBox outputs are collected.

Three filtering mechanism1. loading + data leakage2. loading + malicious network connection3. native code loading signature + data leakage or malicious network connection

Page 8: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Dataset Validationsending potential candidate update attacks to VirusTotal.

oDetected more than 10 Avs.oIts dominant label belonging to an updated attack family.o82.66% of candidates confirmed as updated attacks.o7.1% of all connected samples missed our filtering mechanisms.

Page 9: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

UpDroid Overview

21 malware families, 2479 malware samples

Page 10: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Family Classification

o Mobile malware variants are on the rise.o Commercial AVs are not reliable.

o Minimize the number of samples to be analysed.

o Help to decrease the analysis time.

Page 11: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Static + Dynamic features

Page 12: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification
Page 13: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Family Classification Results

Page 14: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Static Analysis-Based Approaches

Page 15: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Confusion Matrix for the Last5Y dataset

Page 16: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Conclusion

A new dataset, UpDroid is introduced.

Page 17: UpDroid: Updated Android Malware and Its Familial ...aselcuk.etu.edu.tr/SiberGuvenlikGunu-2019.12.23/KursatAktas.pdf · 21 malware families, 2479 malware samples. Family Classification

Acknowledgement

This study is supported by TUBITAK (the project 115E150).

THE SCIENTIFIC AND TECHNOLOGICAL RESEARCH COUNCIL OF TURKEY