Dynamic Analysis of Android Malware

Victor van der Veen, Herbert Bos, Christian Rossow · Data Archiving and Networked Services (DANS) · 2013

Expecting a shipment of 1 billion Android devices in 2017, cyber criminals have naturally extended their vicious activities towards Google’s mobile operating system: threat researchers are reporting an alarming increase of detected Android malware from 2012 to 2013. In order to have some control over the estimated 700 new Android applications that are being released every day, there is need for a form of automated analysis to quickly detect and isolate new malware instances. We present the TraceDroid Analysis Platform, a scalable, automated framework for dynamic analysis of Android applications to detect suspicious, possibly malicious apps using a comprehensive method tracing scheme dubbed TraceDroid. We provide means to aid further post-analysis on suspects to allow malware researchers to fully understand their behavior and ultimately label them as malicious or benign. Our framework can therefore aid and direct scarce analysis resources towards applications that have the greatest potential of being malicious. We show that TraceDroid is almost 50% faster than Android’s original profiler implementation while revealing much more detail about the app’s execution. This makes it a perfect tool not only for malware analysts, but also for app developers and reverse engineers. For a random set of 35 both benign and malicious samples, the stimulation engine of our TraceDroid Analysis Platform achieves an average code coverage of 33.6% which is even more than when they are stimulated manually (32.9%).

Read the paper · More papers on PaperTik