2021•arXiv (Cornell University)Open access

Exploring the Use of Static and Dynamic Analysis to Improve the\n Performance of the Mining Sandbox Approach for Android Malware Identification

Francisco Handrick da Costa, Ismael Medeiros, Thales Menezes, João Victor da Silva, Ingrid Lorraine da Silva, Rodrigo Bonifácio, Krishna Narasimhan, Márcio Ribeiro

Open full text 0 citations

Abstract

The Android mining sandbox approach consists in running dynamic analysis\ntools on a benign version of an Android app and recording every call to\nsensitive APIs. Later, one can use this information to (a) prevent calls to\nother sensitive APIs (those not previously recorded) or (b) run the dynamic\nanalysis tools again in a different version of the app -- in order to identify\npossible malicious behavior. Although the use of dynamic analysis for mining\nAndroid sandboxes has been empirically investigated before, little is known\nabout the potential benefits of combining static analysis with the mining\nsandbox approach for identifying malicious behavior. As such, in this paper we\npresent the results of two empirical studies: The first is a non-exact\nreplication of a previous research work from Bao et al., which compares the\nperformance of test case generation tools for mining Android sandboxes. The\nsecond is a new experiment to investigate the implications of using taint\nanalysis algorithms to complement the mining sandbox approach in the task to\nidentify malicious behavior. Our study brings several findings. For instance,\nthe first study reveals that a static analysis component of DroidFax (a tool\nused for instrumenting Android apps in the Bao et al. study) contributes\nsubstantially to the performance of the dynamic analysis tools explored in the\nprevious work. The results of the second study show that taint analysis is also\npractical to complement the mining sandboxes approach, improve the performance\nof the later strategy in at most 28.57%.\n

Open-access reader

About this research paper

What this paper is about

The Android mining sandbox approach consists in running dynamic analysis\ntools on a benign version of an Android app and recording every call to\nsensitive APIs. Later, one can use this information to (a) prevent calls to\nother sensitive APIs (those not previously recorded) or (b) run the dynamic\nanalysis tools again in a different version of the app -- in order to identify\npossible malicious behavior. Although the use of dynamic analysis for mining\nAndroid sandboxes has been empirically investigated before, little is known\nabout the potential benefits of combining static analysis with the mining\nsandbox approach for identifying malicious behavior. As such, in this paper we\npresent the results of two empirical studies: The first is a non-exact\nreplication of a previous research work from Bao et al., which compares the\nperformance of test case generation tools for mining Android sandboxes. The\nsecond is a new experiment to investigate the implications of using taint\nanalysis algorithms to complement the mining sandbox approach in the task to\nidentify malicious behavior. Our study brings several findings. For instance,\nthe first study reveals that a static analysis component of DroidFax (a tool\nused for instrumenting Android apps in the Bao et al. study) contributes\nsubstantially to the performance of the dynamic analysis tools explored in the\nprevious work. The results of the second study show that taint analysis is also\npractical to complement the mining sandboxes approach, improve the performance\nof the later strategy in at most 28.57%.\n

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The Android mining sandbox approach consists in running dynamic analysis\ntools on a benign version of an Android app and recording every call to\nsensitive APIs. Later, one can use this information to (a) prevent calls to\nother sensitive APIs (those not previously recorded) or (b) run the dynamic\nanalysis tools again in a different version of the app -- in order to identify\npossible malicious behavior. Although the use of dynamic analysis for mining\nAndroid sandboxes has been empirically investigated before, little is known\nabout the potential benefits of combining static analysis with the mining\nsandbox approach for identifying malicious behavior. As such, in this paper we\npresent the results of two empirical studies: The first is a non-exact\nreplication of a previous research work from Bao et al., which compares the\nperformance of test case generation tools for mining Android sandboxes. The\nsecond is a new experiment to investigate the implications of using taint\nanalysis algorithms to complement the mining sandbox approach in the task to\nidentify malicious behavior. Our study brings several findings. For instance,\nthe first study reveals that a static analysis component of DroidFax (a tool\nused for instrumenting Android apps in the Bao et al. study) contributes\nsubstantially to the performance of the dynamic analysis tools explored in the\nprevious work. The results of the second study show that taint analysis is also\npractical to complement the mining sandboxes approach, improve the performance\nof the later strategy in at most 28.57%.\n

Key concepts: Sandbox (software development), Android malware, Android (operating system), Static analysis, Computer science, Malware, System call, Malware analysis

Related papers

Back to paper searchBrowse research topicsOriginal source
Exploring the Use of Static and Dynamic Analysis to Improve the\n Performance of the Mining Sandbox Approach for Android Malware Identification — Research Paper | ScholarLens