Open Access Open Access  Restricted Access Subscription Access

Hybrid Dynamic Analysis for Android Malware Protected by Anti-Analysis Techniques with DOOLDA

Sunjun Lee,
Yonggu Shin,
Minseong Choi,
Haehyun Cho,
Jeong Hyun Yi,

Abstract


A lot of the recently reported malware is equipped with the anti-analysis techniques (e.g., anti-emulation, anti-debugging, etc.) for preventing from being the analyzed, which can delay detection and make malware alive for a longer period. Therefore, it is of the great importance of developing automated approaches to defeat such anti-analysis techniques so that we can handle and effectively mitigate numerous malware. In this paper, by analyzing 1,535 malicious applications, we found that 18.31% of them equipped with anti-analysis techniques. Next, we propose a novel, dynamic analyzer, named DOOLDA, for automatically invalidating anti-analysis techniques through dynamic instrumentation. DOOLDA monitors executions of Android applications’ entire code layers (i.e., bytecode and native code). Based on monitoring results, DOOLDA finds the code related to anti-analysis techniques and invalidates the anti-analysis techniques by instrumenting it. To demonstrate the effectiveness of DOOLDA, we show that it can invalidate all known anti-analysis techniques. Also, we compare DOOLDA with other dynamic analyzers.

Keywords


Malware analysis, Dynamic analysis, Mobile security

Citation Format:
Sunjun Lee, Yonggu Shin, Minseong Choi, Haehyun Cho, Jeong Hyun Yi, "Hybrid Dynamic Analysis for Android Malware Protected by Anti-Analysis Techniques with DOOLDA," Journal of Internet Technology, vol. 25, no. 2 , pp. 195-213, Mar. 2024.

Full Text:

PDF

Refbacks

  • There are currently no refbacks.





Published by Executive Committee, Taiwan Academic Network, Ministry of Education, Taipei, Taiwan, R.O.C
JIT Editorial Office, Office of Library and Information Services, National Dong Hwa University
No. 1, Sec. 2, Da Hsueh Rd., Shoufeng, Hualien 974301, Taiwan, R.O.C.
Tel: +886-3-931-7314  E-mail: jit.editorial@gmail.com