DroidScope: seamlessly reconstructing the OS and Dalvik semantic views for dynamic Android malware analysis

Lok Kwong Yan, Heng Yin

2012 · 612 citations · 30 references

Concepts

TL;DR

Android’s widespread use and open market make it a prime target for malware, requiring rapid insight into malicious behavior. This paper introduces DroidScope, an Android analysis platform that extends virtualization-based malware analysis. DroidScope reconstructs OS- and Dalvik-level semantics simultaneously, exposing hardware, OS, and VM APIs and enabling custom tools for native/Dalvik tracing, API profiling, and taint-based leakage detection. The platform’s tools effectively analyze real-world malware with modest performance overhead.

Abstract

The prevalence of mobile platforms, the large market share of Android, plus the openness of the Android Market makes it a hot target for malware attacks. Once a malware sample has been identified, it is critical to quickly reveal its malicious intent and inner workings. In this paper we present DroidScope, an Android analysis platform that continues the tradition of virtualization-based malware analysis. Unlike current desktop malware analysis platforms, DroidScope reconstructs both the OS-level and Java-level semantics simultaneously and seamlessly. To facilitate custom analysis, DroidScope exports three tiered APIs that mirror the three levels of an Android device: hardware, OS and Dalvik Virtual Machine. On top of DroidScope, we further developed several analysis tools to collect detailed native and Dalvik instruction traces, profile API-level activity, and track information leakage through both the Java and native components using taint analysis. These tools have proven to be effective in analyzing real world malware samples and incur reasonably low performance overheads.

References

30