DROIT: Dynamic Alternation of Dual-Level Tainting for Malware Analysis

Chi-Wei Wang, Shiuhpyng, Winston Shieh · 2015

Taint analysis for Android malware has received much attention due to its power to reveal the information theft behavior. Existing taint techniques track data flow either at Java object level or at deeper instruction level. Object-level tracking is suitable for mal-ware written in Java byte-code, but not for native ones. Instruction-level tracking cap-tures the finest data flow. However, it leads to obscure semantic reconstruction and low performance. In this paper, we present DROIT, a taint tracker which dynamically switches between object-level and instruction-level tracking on demands. DROIT tracks data flow at Java object level in general. When its Dalvik VM exits the byte-code execu-tion, DROIT will automatically switch to instruction-level tracking, and vice versa. The trigger-based DROIT can alternate between the two levels in an efficient manner, and can provide dual-level whole image of the data flow, rather than fragments. Tracking at the dual levels also eases the semantic reconstruction significantly. The experiment with 19 representative Android information-stealing trojans showed that DROIT can track data flow of Java-based malware (e.g., DroidDream, PjApps, and GingerMaster), those com-posed in native code, and those alternating between the two levels (e.g., DroidKungFu), respectively.

Read the paper · More papers on PaperTik