A Brief Introduction
Obfuscation techniques modify an app’s source (or machine) code in order to make it more difficult to analyze. This is typically applied to protect intellectual property in benign apps, or to hinder the process of extracting actionable information in the case of malware. Since malware analysis often requires considerable resource investment, detecting the particular obfuscation technique used may contribute to apply the right analysis tools; thus, leading to some savings. In this paper, we propose AndrODet, a mechanism to detect three popular types of obfuscation in Android applications, namely identifier renaming, string encryption, and control flow obfuscation. AndrODet leverages online learning techniques, thus being suitable for resource-limited environments that need to operate in a continuous manner.
- An adaptive online learning system to detect three common types of obfuscation in Android applications
- A comparison between online learning and batch learning systems to detect prevalent Android obfuscations
- Statistical results for different considered features on the biggest collection of obfuscated apps
You can download AndrODet from my GitHub profile in here.