{"title":"DynaDroid: dynamic binary instrumentation based app behavior monitoring framework","authors":"Bharat Buddhdev, R. Bhan, M. Gaur, V. Laxmi","doi":"10.1145/2799979.2800036","DOIUrl":null,"url":null,"abstract":"Android OS market share has made it a feverish target of malicious attacks. Dynamic Binary Instrumentation (DBI) based tools are gaining prominence for behavioral program inspection, feature identification and virtual machine binary code translation. DBI has an advantage of being transparent, i.e. the application under inspection is never modified. In this paper we describe DynaDroid, DBI framework developed to build behavior based binary instrumentation methodology to effectively monitor Android Package (APK) behavior. Unlike the existing behavior monitoring approaches, the proposed DynaDroid reconstructs the Dalvik level and Java level semantics at a time. The proposed dynamic behavior approach can provide base for analyzing the native calls, Dalvik instructions and also generate profile for Java based API activity. We plan to build effective instrumentation framework to detect real malware with lightweight overhead.","PeriodicalId":293190,"journal":{"name":"Proceedings of the 8th International Conference on Security of Information and Networks","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-09-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 8th International Conference on Security of Information and Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2799979.2800036","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Android OS market share has made it a feverish target of malicious attacks. Dynamic Binary Instrumentation (DBI) based tools are gaining prominence for behavioral program inspection, feature identification and virtual machine binary code translation. DBI has an advantage of being transparent, i.e. the application under inspection is never modified. In this paper we describe DynaDroid, DBI framework developed to build behavior based binary instrumentation methodology to effectively monitor Android Package (APK) behavior. Unlike the existing behavior monitoring approaches, the proposed DynaDroid reconstructs the Dalvik level and Java level semantics at a time. The proposed dynamic behavior approach can provide base for analyzing the native calls, Dalvik instructions and also generate profile for Java based API activity. We plan to build effective instrumentation framework to detect real malware with lightweight overhead.