The Experts below are selected from a list of 5499 Experts worldwide ranked by ideXlab platform
Yves Le Traon - One of the best experts on this subject based on the ideXlab platform.
-
on locating Malicious code in piggybacked android apps
Journal of Computer Science and Technology, 2017Co-Authors: Tegawende F Bissyande, Jacques Klein, Haipeng Cai, Yves Le TraonAbstract:To devise efficient approaches and tools for detecting Malicious packages in the Android ecosystem, researchers are increasingly required to have a deep understanding of malware. There is thus a need to provide a framework for dissecting malware and locating Malicious Program fragments within app code in order to build a comprehensive dataset of Malicious samples. Towards addressing this need, we propose in this work a tool-based approach called HookRanker, which provides ranked lists of potentially Malicious packages based on the way malware behaviour code is triggered. With experiments on a ground truth of piggybacked apps, we are able to automatically locate the Malicious packages from piggybacked Android apps with an accuracy@5 of 83.6% for such packages that are triggered through method invocations and an accuracy@5 of 82.2% for such packages that are triggered independently.
-
automatically locating Malicious packages in piggybacked android apps
2017 IEEE ACM 4th International Conference on Mobile Software Engineering and Systems (MOBILESoft), 2017Co-Authors: Tegawende F Bissyande, Jacques Klein, Haipeng Cai, Yves Le TraonAbstract:To devise efficient approaches and tools for detecting Malicious packages in the Android ecosystem, researchers are increasingly required to have a deep understanding of malware. There is thus a need to provide a framework for dissecting malware and locating Malicious Program fragments within app code in order to build a comprehensive dataset of Malicious samples. Towards addressing this need, we propose in this work a tool-based approach called HookRanker, which provides ranked lists of potentially Malicious packages based on the way malware behaviour code is triggered. With experiments on a ground truth set of piggybacked apps, we are able to automatically locate the Malicious packages from piggybacked Android apps with an accuracy of 83.6% in verifying the top five reported items.
-
ungrafting Malicious code from piggybacked android apps
2016Co-Authors: Tegawende F Bissyande, Jacques Klein, Yves Le TraonAbstract:To devise e cient approaches and tools for detecting Malicious code in the Android ecosystem, researchers are increasingly required to have deep understanding of malware. There is thus a need to provide a framework for dissecting malware and localizing Malicious Program fragments within app code in order to build a comprehensive dataset of Malicious samples. In this paper we address this need with an approach for listing Malicious packages in an app based on code graph analysis. To that end we focus on piggybacked apps, which are benign apps repackaged with Malicious payload. Our approach classifies each app independently from its potential clones based on machine learning, and detects piggybacked apps with a precision of about 97%. With the built classifier we were also able to find new piggybacked apps in market datasets, outside our ground truth. We also identify Malicious packages with an accuracy@5 of 83% and an accuracy@1 of around 68%. We further demonstrate the importance of collecting Malicious packages by using them to build a performant malware detection system.
Tegawende F Bissyande - One of the best experts on this subject based on the ideXlab platform.
-
on locating Malicious code in piggybacked android apps
Journal of Computer Science and Technology, 2017Co-Authors: Tegawende F Bissyande, Jacques Klein, Haipeng Cai, Yves Le TraonAbstract:To devise efficient approaches and tools for detecting Malicious packages in the Android ecosystem, researchers are increasingly required to have a deep understanding of malware. There is thus a need to provide a framework for dissecting malware and locating Malicious Program fragments within app code in order to build a comprehensive dataset of Malicious samples. Towards addressing this need, we propose in this work a tool-based approach called HookRanker, which provides ranked lists of potentially Malicious packages based on the way malware behaviour code is triggered. With experiments on a ground truth of piggybacked apps, we are able to automatically locate the Malicious packages from piggybacked Android apps with an accuracy@5 of 83.6% for such packages that are triggered through method invocations and an accuracy@5 of 82.2% for such packages that are triggered independently.
-
automatically locating Malicious packages in piggybacked android apps
2017 IEEE ACM 4th International Conference on Mobile Software Engineering and Systems (MOBILESoft), 2017Co-Authors: Tegawende F Bissyande, Jacques Klein, Haipeng Cai, Yves Le TraonAbstract:To devise efficient approaches and tools for detecting Malicious packages in the Android ecosystem, researchers are increasingly required to have a deep understanding of malware. There is thus a need to provide a framework for dissecting malware and locating Malicious Program fragments within app code in order to build a comprehensive dataset of Malicious samples. Towards addressing this need, we propose in this work a tool-based approach called HookRanker, which provides ranked lists of potentially Malicious packages based on the way malware behaviour code is triggered. With experiments on a ground truth set of piggybacked apps, we are able to automatically locate the Malicious packages from piggybacked Android apps with an accuracy of 83.6% in verifying the top five reported items.
-
ungrafting Malicious code from piggybacked android apps
2016Co-Authors: Tegawende F Bissyande, Jacques Klein, Yves Le TraonAbstract:To devise e cient approaches and tools for detecting Malicious code in the Android ecosystem, researchers are increasingly required to have deep understanding of malware. There is thus a need to provide a framework for dissecting malware and localizing Malicious Program fragments within app code in order to build a comprehensive dataset of Malicious samples. In this paper we address this need with an approach for listing Malicious packages in an app based on code graph analysis. To that end we focus on piggybacked apps, which are benign apps repackaged with Malicious payload. Our approach classifies each app independently from its potential clones based on machine learning, and detects piggybacked apps with a precision of about 97%. With the built classifier we were also able to find new piggybacked apps in market datasets, outside our ground truth. We also identify Malicious packages with an accuracy@5 of 83% and an accuracy@1 of around 68%. We further demonstrate the importance of collecting Malicious packages by using them to build a performant malware detection system.
Randal E. Bryant - One of the best experts on this subject based on the ideXlab platform.
-
Semantics-aware malware detection
Proceedings - IEEE Symposium on Security and Privacy, 2005Co-Authors: Mihai Christodorescu, Somesh Jha, Sanjit A. Seshia, Dawn Song, Randal E. BryantAbstract:A malware detector is a system that attempts to determine whether a\nProgram has Malicious intent. In order to evade detection, malware\nwriters (hackers) frequently use obfuscation to morph malware. Malware\ndetectors that use a pattern-matching approach (such as commercial virus\nscanners) are susceptible to obfuscations used by hackers. The\nfundamental deficiency in the pattern-matching approach to malware\ndetection is that it is purely syntactic and ignores the semantics of\ninstructions. In this paper we present a malware-detection algorithm\nthat addresses this deficiency by incorporating instruction semantics to\ndetect Malicious Program traits. Experimental evaluation demonstrates\nthat our malware-detection algorithm can detect variants of malware with\na relatively low run-time overhead Moreover, our semantics-aware malware\ndetection algorithm is resilient to common obfuscations used by hackers.
Mohammad Mehedi Hassan - One of the best experts on this subject based on the ideXlab platform.
-
a system call refinement based enhanced minimum redundancy maximum relevance method for ransomware early detection
Journal of Network and Computer Applications, 2020Co-Authors: Yahye Abukar Ahmed, Baris Kocer, Shamsul Huda, Bander Ali Saleh Alrimy, Mohammad Mehedi HassanAbstract:Abstract Ransomware is a special type of Malicious software that encrypts the user's assets and makes it unavailable to the users until a ransom is paid to the ransomware author. Such attacks have become one of the most widespread malware that poses serious threat to both individuals and business organizations. Against this destructive Malicious Program, the dynamic analysis approach is the most popular approach for detecting such an attack. The majority of dynamic analysis relies on the system calls, as these provide an interface for Programs to request service from the operating system. However, the redundancy and the irrelevant system calls that the ransomware authors inject in the actual execution flow of suspicious binaries generate a high noisy behavioural sequence that adversely impacts in the detection performance of anti-ransomware tools. To this end, we proposed a non-signature-based detection approach based on the effective windows API call sequences using supervised machine learning techniques. To achieve this objective, we propose an Enhanced Maximum-Relevance and Minimum-Redundancy (EmRmR) filter method to remove the noisy features and select the most relevant subset of features to characterize the real behaviour of the ransomware. Unlike the original mRmR, the EmRmR avoids unnecessary computations intrinsic in the original mRmR algorithms with a small number of evaluations. In addition, this work has introduced a refinement process to reduce the size of the Program's call traces by removing those windows API calls that do not have a strong indication for describing the critical behaviour of the ransomware. After accomplishing extensive experimental evaluations, and comparing with existing behavioural-based detection approaches, the proposed method has shown to be effective for discriminating the behaviour of ransomware, and indicates a high detection accuracy with few false-positive rates.
Thorsten Holz - One of the best experts on this subject based on the ideXlab platform.
-
Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C++ Applications
2015 IEEE Symposium on Security and Privacy, 2015Co-Authors: Felix Schuster, Ahmad-reza Sadeghi, Lucas Davi, Thomas Tendyck, Christopher Liebchen, Thorsten HolzAbstract:Code reuse attacks such as return-oriented Programming (ROP) have become prevalent techniques to exploit memory corruption vulnerabilities in software Programs. A variety of corresponding defenses has been proposed, of which some have already been successfully bypassed -- and the arms race continues. In this paper, we perform a systematic assessment of recently proposed CFI solutions and other defenses against code reuse attacks in the context of C++. We demonstrate that many of these defenses that do not consider object-oriented C++ semantics precisely can be generically bypassed in practice. Our novel attack technique, denoted as counterfeit object-oriented Programming (COOP), induces Malicious Program behavior by only invoking chains of existing C++ virtual functions in a Program through corresponding existing call sites. COOP is Turing complete in realistic attack scenarios and we show its viability by developing sophisticated, real-world exploits for Internet Explorer 10 on Windows and Fire fox 36 on Linux. Moreover, we show that even recently proposed defenses (CPS, T-VIP, vfGuard, and VTint) that specifically target C++ are vulnerable to COOP. We observe that constructing defenses resilient to COOP that do not require access to source code seems to be challenging. We believe that our investigation and results are helpful contributions to the design and implementation of future defenses against control flow hijacking attacks.
-
counterfeit object oriented Programming on the difficulty of preventing code reuse attacks in c applications
IEEE Symposium on Security and Privacy, 2015Co-Authors: Felix Schuster, Ahmad-reza Sadeghi, Lucas Davi, Thomas Tendyck, Christopher Liebchen, Thorsten HolzAbstract:Code reuse attacks such as return-oriented Programming (ROP) have become prevalent techniques to exploit memory corruption vulnerabilities in software Programs. A variety of corresponding defenses has been proposed, of which some have already been successfully bypassed -- and the arms race continues. In this paper, we perform a systematic assessment of recently proposed CFI solutions and other defenses against code reuse attacks in the context of C++. We demonstrate that many of these defenses that do not consider object-oriented C++ semantics precisely can be generically bypassed in practice. Our novel attack technique, denoted as counterfeit object-oriented Programming (COOP), induces Malicious Program behavior by only invoking chains of existing C++ virtual functions in a Program through corresponding existing call sites. COOP is Turing complete in realistic attack scenarios and we show its viability by developing sophisticated, real-world exploits for Internet Explorer 10 on Windows and Fire fox 36 on Linux. Moreover, we show that even recently proposed defenses (CPS, T-VIP, vfGuard, and VTint) that specifically target C++ are vulnerable to COOP. We observe that constructing defenses resilient to COOP that do not require access to source code seems to be challenging. We believe that our investigation and results are helpful contributions to the design and implementation of future defenses against control flow hijacking attacks.