arXiv (Cornell University) · 2014 · 12 citations · 0 references
Popularity and complexity of malicious mobile applications are rising, making\ntheir analysis difficult and labor intensive. Mobile application analysis is\nindeed inherently different from desktop application analysis: In the latter,\nthe interaction of the user (i.e., victim) is crucial for the malware to\ncorrectly expose all its malicious behaviors.\n We propose a novel approach to analyze (malicious) mobile applications. The\ngoal is to exercise the user interface (UI) of an Android application to\neffectively trigger malicious behaviors, automatically. Our key intuition is to\nrecord and reproduce the UI interactions of a potential victim of the malware,\nso as to stimulate the relevant behaviors during dynamic analysis. To make our\napproach scale, we automatically re-execute the recorded UI interactions on\napps that are similar to the original ones. These characteristics make our\nsystem orthogonal and complementary to current dynamic analysis and\nUI-exercising approaches.\n We developed our approach and experimentally shown that our stimulation\nallows to reach a higher code coverage than automatic UI exercisers, so to\nunveil interesting malicious behaviors that are not exposed when using other\napproaches.\n Our approach is also suitable for crowdsourcing scenarios, which would push\nfurther the collection of new stimulation traces. This can potentially change\nthe way we conduct dynamic analysis of (mobile) applications, from fully\nautomatic only, to user-centric and collaborative too.\n