scieee Open visual document viewer

Malware Analysis on Android

Puente Arribas, Daniel; Daguerre Garrido, José Ignacio; Costales de Ledesma, Ramón

Abstract

In the XXI century, the world has witnessed the creation, development and proliferation of mobile devices until the massive usage apparent nowadays. The portability, instantaneity and ease of use that these devices offer has encouraged the great majority of the population to have one of them at arm’s length. Thus, these devices have become a coveted target for malicious developers. This is the reason why the security of mobile devices has become a vital topic that must be addressed, since a suitable solution has yet to be found. From this necessity arises the present work, in which we elaborate the beginning of a response that serves as a starting point to promote further development that achieves the desired objective. With Android being the most representative Operating System among mobile devices, we are going to study the analysis of malware on Android and develop a static and dynamic antivirus based on signatures, permissions and logs, since they will prove useful when trying to detect malicious applications.

Full text

Malwa e Analysis on And oid Análisis de Malwa e en And oid Final Deg ee P ojec in Compu e Science Deg ee Facul y o Compu e Science & Enginee ing Uni e sidad Complu ense de Mad id Cou se 2020-2021 Au ho s Daniel Puen e A ibas José Ignacio Dague e Ga ido Ramón Cos ales de Ledesma Ad iso s: Ma cos Sánchez-Élez Ma ín and Inmaculada Pa dines Lence 2 Abs ac In he XXI cen u y, he wo ld has wi nessed he c ea ion, de elopmen and p oli e a ion o mobile de ices un il he massi e usage appa en nowadays. The po abili y, ins an anei y and ease o use ha hese de ices o e has encou aged he g ea majo i y o he popula ion o ha e one o hem a a m’s leng h. Thus, hese de ices ha e become a co e ed a ge o malicious de elope s. This is he eason why he secu i y o mobile de ices has become a i al opic ha mus be add essed, since a sui able solu ion has ye o be ound. F om his necessi y a ises he p esen wo k, in which we elabo a e he beginning o a esponse ha se es as a s a ing poin o p omo e u he de elopmen ha achie es he desi ed objec i e. Wi h And oid being he mos ep esen a i e Ope a ing Sys em among mobile de ices, we a e going o s udy he analysis o malwa e on And oid and de elop a s a ic and dynamic an i i us based on signa u es, pe missions and logs, since hey will p o e use ul when ying o de ec malicious applica ions. Keywo ds (10 max) And oid, Malwa e, Vulne abili y, An i i us, Hash, Log, Pe mission, S a ic Analysis, Dynamic Analysis, Cloud. 3 4 Resumen En el siglo XXI se ha podido ap ecia la apa ición, desa ollo y p oli e ación de los disposi i os mó iles has a llega a la masi icación que iene luga en la ac ualidad. La po abilidad, ins an aneidad y acilidad de uso que o ecen ha hecho que la mayo ía de la población enga uno siemp e al alcance de su mano. Es po ello que se han con e ido en un obje i o codiciado po los desa ollado es de p og amas maliciosos. Así pues, la segu idad de es os disposi i os se ha con e ido en un pun o cla e que debe se abo dado, ya que has a la echa no se ha encon ado una solución ap opiada. De es a necesidad su ge el p esen e abajo, en el que elabo amos el comienzo de una espues a que si e como pun o de pa ida pa a omen a un pos e io desa ollo que alcance el obje i o deseado. Siendo And oid el sis ema ope a i o más ep esen a i o en e los disposi i os mó iles, amos a hace un es udio del análisis del malwa e en And oid y a desa olla un an i i us es á ico y dinámico basado en i mas, pe misos y logs, pues es as e idencias se án de g an ayuda en la labo de de ección de aplicaciones maliciosas. Palab as cla e (máx 10) And oid, Malwa e, Vulne abilidad, An i i us, Hash, Log, Pe miso, Análisis es á ico, Análisis dinámico, Cloud. 5 6 Acknowledgemen s We would like o exp ess ou mos since e g a i ude o bo h ou p ojec ad iso s, Ma cos Sánchez-Élez Ma ín and Inmaculada Pa dines Lence, o hei excellen guidance h oughou he p oduc ion o his p ojec . 7 Index 1. In oduc ion 11 1.1 Mo i a ions 11 1.2 S a e o he A 12 1.3 Objec i es 14 1.4 Wo k planning 14 1.5 Documen O ganiza ion 21 2. And oid 22 2.1 And oid Ope a ing Sys em 22 2.1.1 In oduc ion 22 2.1.2 Applica ions 24 2.1.3 Componen s 27 2.1.4 In en s 28 2.2 And oid’s Vulne abili ies 28 2.2.1 Gene al Vulne abili ies 28 2.2.2 Roo ing 31 2.3 And oid’s Secu i y Sys ems 33 2.3.1 Linux Secu i y 33 2.3.2 Applica ion Sandbox 33 2.3.3 SELinux 34 2.3.4 Sys em’s Secu i y 34 2.3.5 Use ’s Secu i y 35 2.3.6 Apps Secu i y 35 2.4 And oid’s Malwa e 35 2.4.1 Malwa e ends 35 2.4.2 Malwa e ypes, aims and cha ac e is ics 38 2.4.3 T ansmission me hods, de ec ion and p e en ion 42 3. Wo kspace 46 3.1 Tools and samples 46 3.1.1 Tools 46 3.1.1 Samples 48 3.2 Decisions 49 4. Analysis Me hods 51 4.1 C yp og aphic Signa u e Analysis 51 4.2 Heu is ic Log Analysis 53 4.2.1 And oid logs 53 4.2.2 Log handling 55 4.3 Pe mission Analysis 56 5. Analysis Me hods Implemen a ion 59 5.1 C yp og aphic Signa u e Analysis Implemen a ion 59 8 5.2 Heu is ic Log Analysis Implemen a ion 65 5.2.1 Applica ion 65 5.2.2 Se e 79 5.2.3 P oblems o e come 84 5.3 Pe mission Analysis Implemen a ion 85 5.3.1 Da ase o pe missions 85 5.3.2 Classi ica ion o pe missions 89 5.3.3 Pe missions analysis and sco ing 90 5.3.4 Resul s 96 6. And oid Malwa e Analyze App 101 6.1 F agmen Menu 101 6.2 Home F agmen 103 6.3 Apps In o ma ion F agmen 104 6.4 Signa u e Analyze F agmen 109 6.5 Pe mission Analyze F agmen 111 6.6 Log Analyze F agmen 113 6.7 P e ious Resul s F agmen 118 6.8 Se e Se ings F agmen 119 6.9 Abou Us F agmen 122 7. Expe imen al esul s 123 7.1 Applica ions Analyzed 123 7.2 Pe mission Analysis 132 7.3 C yp og aphic Signa u e Analysis 138 7.4 Heu is ic Log Analysis 144 8. Indi idual Wo k 152 8.1 Daniel Puen e A ibas 152 8.2 José Ignacio Dague e Ga ido 153 8.3 Ramón Cos ales de Ledesma 154 9. Conclusions & Fu u e Wo k 155 9.1 O e iew 155 9.2 Applied Knowledge 155 9.3 Imp o emen s 156 9.3.1 Signa u e analyze 156 9.3.2 Log analyze 157 9.3.3 Pe mission analyze 157 9.4 Fu u e Wo k 157 9.4.1 Signa u e analyze 157 9.4.2 Log analyze 157 9.4.3 Pe mission analyze 158 Bibliog aphy 159 9 ii. Upg ade he app o lis he hashes o all he applica ions. Times amp: 21 Oc obe - 4 No embe . De elope : Daniel Puen e. iii. Upg ade he app o lis he pe missions o all he applica ions. Times amp: 21 Oc obe - 4 No embe . De elope : Daniel Puen e. i . De elop he app de ails ac i i y unc ionali y and iew. Times amp: 4 - 30 No embe . De elope : Daniel Puen e. . Upg ade he app o access he logs. Times amp: 25 No embe - 16 Decembe . De elope s: Daniel Puen e and Ramón Cos ales. i. C ea e a mockup local da abase o he app. Times amp: 25 No embe - 16 Decembe . De elope : José Ignacio Dague e. ii. Upg ade he app o connec o he se e . Times amp: 20 Janua y - 8 Feb ua y. De elope s: All he eam. iii. Connec he app o he se e . Times amp: 20 Janua y - 8 Feb ua y. De elope s: All he eam. ix. P in he esul ob ained om he se e . Times amp: 20 Janua y - 8 Feb ua y. De elope s: All he eam. x. Di ide he app unc ionali y in o agmen s. Times amp: 21 - 25 Feb ua y. De elope : Ramón Cos ales. xi. Fix na igabili y. Times amp: 18 Ap il. De elope : Ramón Cos ales. Figu e 4: App planning 4. Se e (see Figu e 5): i. C ea e he se e . Times amp: 20 Janua y - 8 Feb ua y. De elope s: All he eam. ii. C ea e a Spa k S eaming sc ip ha p ocesses he logs. Times amp: 20 Janua y - 8 Feb ua y. De elope s: All he eam. iii. De elop he mul i connec ion. Times amp: 21 Ma ch - 2 Ap il. De elope : Ramón Cos ales. i . Upda e he Spa k S eaming sc ip . Times amp: 25 - 26 Ap il. De elope : Ramón Cos ales. . P ocess, pa se and il e he logs. Times amp: 26 Ap il - 4 May. De elope : Ramón Cos ales. 16 i. Send back he esul s o he app. Times amp: 4 - 8 May. De elope : Ramón Cos ales. ii. Fix bugs. Times amp: 8 - 11 May. De elope : Ramón Cos ales. Figu e 5: Se e planning 5. App [se e se ings agmen ] (see Figu e 6): i. Lis all he connec ions. Times amp: 25 - 26 Feb ua y. De elope : Ramón Cos ales. ii. De elop he add unc ionali y. Times amp: 26 - 28 Feb ua y. De elope : Ramón Cos ales. iii. De elop he dele e unc ionali y. Times amp: 28 Feb ua y - 2 Ma ch. De elope : Ramón Cos ales. i . Sa e and load he connec ions. Times amp: 2 - 5 Ma ch. De elope : Ramón Cos ales. . Pa se he IP and po numbe s. Times amp: 19 - 20 Ap il. De elope : Ramón Cos ales. Figu e 6: Se e se ings planning 6. App [apps in o ma ion agmen ] (see Figu e 7): i. Con e he apps lis ac i i y o a new agmen . Times amp: 25 - 28 Feb ua y. De elope : Daniel Puen e. ii. Con e he app de ails ac i i y o a new agmen . Times amp: 25 - 28 Feb ua y. De elope : Daniel Puen e. 17 iii. De elop he pe missions iew o ganized by ca ego ies. Times amp: 16 - 23 Ma ch. De elope : Daniel Puen e. Figu e 7: Apps in o ma ion planning 7. App [pe missions analyze agmen ] (see Figu e 8): i. Pe missions esea ch. Times amp: 1 - 7 Ma ch. De elope : Daniel Puen e. ii. Elabo a e pe missions and domains da ase . Times amp: 8 - 15 Ma ch. De elope : Daniel Puen e. iii. Design and code pe missions g ading algo i hms. Times amp: 24 Ma ch - 1 Ap il. De elope : Daniel Puen e i . De elop pe mission analyze logic and unc ionali y. Times amp: 5 - 18 Ap il. De elope : Daniel Puen e. . De elop pe missions analyze iew. Times amp: 19 - 30 Ap il. De elope : Daniel Puen e. i. Finish, es , debug and co ec e o s. Times amp: 1 - 12 May. De elope : Daniel Puen e. Figu e 8: Pe mission analyze planning 8. App [signa u e analyze agmen ] (see Figu e 9): i. Upg ade and upload he i s da abase e sion. Times amp: 25 No embe - 20 Feb ua y. De elope : José Ignacio Dague e. ii. De elopmen o he Signa u e Analyze agmen . Times amp: 20 - 27 Feb ua y. De elope : José Ignacio Dague e. iii. C ea ion o an ac i i y wi h he “Check Hash” op ion. Times amp: 28 Feb ua y- 1 Ma ch. De elope : José Ignacio Dague e. 18 i . Connec ion and in e ac ion wi h he da abase h ough he applica ion. Times amp: 1 - 2 Ma ch. De elope : José Ignacio Dague e. . Display all he apps in a checkbox lis . Times amp: 3 - 17 Ma ch. De elope : José Ignacio Dague e. i. Implemen a sea ch box in Signa u e Analyze F agmen . Times amp: 1 - 19 Ap il. De elope : José Ignacio Dague e. ii. Finish Signa u e Analysis agmen . Times amp: 22 Ap il - 1 May. De elope : José Ignacio Dague e. iii. Upg ade Signa u e Analysis agmen wi h an upda able da abase. Times amp: 3 - 6 May. De elope : José Ignacio Dague e. ix. Upload he inal e sion o he da abase. Times amp: 11 May - 12 May. De elope : José Ignacio Dague e. Figu e 9: Signa u e analyze planning 9. App [log analyze agmen ] (see Figu e 10): i. Display all he apps in a checkbox lis . Times amp: 5 - 10 Ma ch. De elope : Ramón Cos ales. ii. P og am he connec ion o he se e . Times amp: 10 - 21 Ma ch. De elope : Ramón Cos ales. iii. Clean he code. Times amp: 2 - 8 Ap il. De elope : Ramón Cos ales. i . De elop he agmen ha shows he log analysis esul . Times amp: 22 - 25 Ap il. De elope : Ramón Cos ales. . Implemen expandable elemen s while showing he esul . Times amp: 11 - 12 May. De elope : Ramón Cos ales. i. Check he pe missions o he apps when showing he esul . Times amp: 12 - 16 May. De elope : Ramón Cos ales. 19 Figu e 10: Log analyze planning 10. App [p e ious esul s agmen ] (see Figu e 11): i. C ea e he P e Resul s da abase. Times amp: 8 - 12 Ap il. De elope : Ramón Cos ales. ii. Lis all he p e ious esul s. Times amp: 12 - 14 Ap il. De elope : Ramón Cos ales. iii. De elop a agmen ha shows he esul o an analysis. Times amp: 14 - 17 Ap il. De elope : Ramón Cos ales. Figu e 11: P e ious esul s planning 11. App [abou us agmen ] (see Figu e 12): i. C ea e he agmen . Times amp: 14 - 17 Ap il. De elope : Ramón Cos ales. Figu e 12: Abou us planning 12. App [home agmen ] (see Figu e 13): i. De elop he agmen . Times amp: 18 Ap il. De elope : Ramón Cos ales. ii. Display elemen s whose hash is ye o be analyzed. Times amp: 20 - 22 Ap il. De elope : Ramón Cos ales. 20 Figu e 13: Home planning 1.5 Documen O ganiza ion This documen is s uc u ed in 9 chap e s. Chap e 1 in oduces he con ex o he p ojec . Chap e 2 desc ibes he And oid ope a ing sys em and e iews i s ulne abili ies and he secu i y sys ems de eloped o his OS; his chap e ends wi h a malwa e o e iew. Chap e 3names all he ools and samples used in he de elopmen o his p ojec and a gues he decisions we ook in each s ep o i s p oduc ion. Chap e 4 explains he heo y behind he analysis me hods we de eloped o he applica ion and Chap e 5 shows hei implemen a ion. Chap e 6 co e s he use ’s in e ac ion wi h he applica ion and i s layou s. Chap e 7 shows he esul s ob ained om analyzing se e al applica ions using he applica ion de eloped h oughou his p ojec . Chap e 8 lis s all he indi idual con ibu ions o each membe o he eam. Finally, Chap e 9 e iews he conclusions d awn om his p ojec and b ains o ms u u e wo k and imp o emen s ha we didn’ ha e he ime o accomplish. 21 2. And oid This chap e in oduces he And oid Ope a ing Sys em [1], desc ibes he key cha ac e is ics o applica ions and enume a es all ypes o componen s and in en s. Also, And oid’s ulne abili ies a e ou lined, he oo ing me hod is explained and And oid’s di e en secu i y measu es a e lis ed. Las ly, an analysis o And oid’s malwa e ypes, cha ac e is ics and ends is pe o med. 2.1 And oid Ope a ing Sys em 2.1.1 In oduc ion And oid is an Ope a ing Sys em ha consis s o a s ack o open sou ce so wa e based on he Linux Ke nel and c ea ed speci ically o mobile de ices. I s a chi ec u e is con o med o six laye s [21]: -The Linux Ke nel: I is he base laye o he And oid Ope a ing Sys em, equi ed o ca ying ou essen ial unc ionali ies such as p ocess managemen , memo y, ne wo k s ack, con olle model and key secu i y ea u es. I is no he s anda d ke nel, bu a speci ic o k ha includes addi ional elemen s, such as Binde o in e -p ocess communica ion, speci ic d i e s, e c. -Ha dwa e Abs ac ion Laye (HAL): allows he Ja a API F amewo k laye o make use o s anda d in e aces ha pe mi he le e age o de ice ha dwa e capabili ies. I consis s o a se o lib a y modules, one o each ha dwa e componen , such as he came a. -And oid Run ime (ART): Each app uns in i s own p ocess and wi h i s own ins ance o he And oid Run ime. I is designed o be able o un mul iple i ual machines on low memo y de ices h ough DEX iles. Be o e And oid 5.0, he Dal ik i ual machine was used. The main di e ence be ween Dal ik and ART is ha he la e compiles he by ecode iles du ing he ins alla ion o he applica ion, so i s key objec i e is o compile he sou ces in DEX code. I has he Co e Lib a y (a pa icula implemen a ion o he Ja a API), basic commands accessible h ough an ADB shell [45], na i e sys em daemons and se ices, and he Ini p ocess. -Na i e C/C++ Lib a ies: They allow applica ions o in e ac a a low le el wi h he ke nel. All And oid lib a ies a e Open Sou ce. Examples: Bionic (C s anda d lib a y on And oid), WebKi (web page ende ing and Ja aSc ip in e p e e ), SQLi e (da abase), OpenSSL (SSL Socke s), e c. -Ja a API F amewo k: E e y pa o he Ope a ing Sys em is accessible h ough an API w i en in Ja a, which is used o de eloping applica ions wi h he objec i e o eusing componen s. I is no exac ly a lib a y, since he e is an in e -p ocess communica ion wi h Binde o limi ing accesses o secu i y easons. Examples: no i ica ion manage , packe manage , window manage e c. 22 -Sys em Apps: These a e he p eins alled apps on he sys em ha o e unc ionali y o bo h he use and o he apps ha may equi e hem. These laye s a e de ailed in Figu e 14. [21] Figu e 14: The And oid so wa e s ack 23 2.1.2 Applica ions APK iles And oid apps a e packaged and dis ibu ed in APK (Applica ion Package) iles ha a e based on Ja a JAR packages. These packages ha e he ollowing s uc u e [22]: -And oidMani es .xml – I is he applica ion's con igu a ion ile. Se e al a ibu es a e de ined in i , such as he unique iden i ie o he applica ion, i ’s componen s («ac i i ies», « ecei e s», «con en p o ide s», e c.) o he pe missions i equi es. -classes.dex – Con ains he applica ion’s compiled code. - esou ces.a sc – I is he ile con aining p ecompiled esou ces. -META-INF – I is he di ec o y ha s o es in o ma ion co esponding o he digi al signa u e o he applica ion; i con ains he ollowing iles: -MANIFEST.MF – I con ains a comple e lis o he APK iles along wi h hei espec i e SHA-1 hash. -CERT.SF – I con ains he SHA-1 hash o e e y 3 lines ha appea in he MANIFEST.MF. -CERT.RSA – s o es he signa u e o he CERT.SF ile and he ce i ica e used o sign he iles. - es – I is he di ec o y ha s o es he esou ces (images, ex iles, XML iles, e c.) used by he applica ion. -lib – I is he di ec o y ha con ains he compiled code o di e en a chi ec u es: a meabi, a meabi- 7a, x86 o mips. -asse s – I con ains non-p ocessed esou ces. Figu e 15 displays he a o emen ioned con en s o APK iles. [23] Figu e 15: APK ile s uc u e 24 As explained in chap e s 4 and 5, APK iles a e o g ea impo ance in ou p ojec , as we make use o hem in all he analysis me hods we ca y ou : - In he C yp og aphic Signa u e Analysis, we use he en i e APK ile o compu e he hash signa u e o he ins alled applica ions. - In he Pe mission Analysis, we ead he pe missions ha applica ions equi e om hei espec i e And oidMani es .xml ile. - In he Heu is ic Log Analysis, as in Pe mission Analysis, we ead he pe missions ha he analyzed applica ions equi e. Pe missions O all he iles ha make up an APK ile, he mos ele an o ou p ojec is he And oidMani es .xml [24], since i con ains he pe missions ha he applica ion equi es. This in o ma ion is i al o wo o he h ee analysis me hods ha we pe o m: he pe mission analysis and he log analysis. And oid es ic s access o speci ic da a and ac ions in o de o p o ec use p i acy. In case an applica ion needs o access any o hose es ic ed componen s, i has o eques he speci ic pe mission needed o accessing hem. These pe missions a e ca ego ized in wo di e en ways: ca ego ized by ype and by g oup. The e a e se e al ypes o pe missions, di ided by he scope o es ic ed da a o ac ions ha he applica ion may pe o m once he pe mission is g an ed [25]: -Ins all- ime pe missions: They gi e he app limi ed access o es ic ed da a, and hey allow i o pe o m es ic ed ac ions ha minimally a ec he sys em and o he apps. The sys em au oma ically g an s he pe missions when he use ins alls he app. -Run ime pe missions: Also known as dange ous pe missions, hey gi e he app addi ional access o es ic ed da a, and hey allow i o pe o m es ic ed ac ions ha mo e subs an ially a ec he sys em and o he apps. The e o e, hey need o be eques ed be o e hey can access he es ic ed da a o pe o m es ic ed ac ions. -Signa u e pe missions: I he app decla es a signa u e pe mission ha ano he app has de ined, and i he wo apps a e signed by he same ce i ica e, hen he sys em g an s he pe mission o he i s app a ins all ime. -No mal pe missions: They allow access o da a and ac ions ha ex end beyond he app's Sandbox. Howe e , he da a and ac ions p esen e y li le isk o he use 's p i acy, and he ope a ion o o he apps. -Special pe missions: They co espond o pa icula app ope a ions. Only he pla o m and OEMs (O iginal Equipmen Manu ac u e s) can de ine special pe missions. The pe missions a e di ided in o g oups by hei unc ionali y [26]. Fo example, and oid.pe mission-g oup.LOCATION g oups he pe missions ha g an access o he de ice loca ion, like he pe mission and oid.pe mission.ACCESS_FINE_LOCATION o he pe mission and oid.pe mission.ACCESS_COARSE_LOCATION. 25 Fo de ices wi hou an unlockable boo loade , oo access can be achie ed by exploi ing a ke nel o sys em ulne abili y. A p i ilege escala ion exploi , ypically packaged in one-click oo ing applica ions, allows an applica ion o un a oo shell o ins all he "su" bina y o modi y sys em se ings. Ano he way is ia a p i ileged ADB (And oid Debug B idge) [45]. The sys em p ope y " o.secu e" o "de aul .p op" de e mines he UID (Use ID) o he p ocess unde which an ADB shell is execu ed. When he alue is 1, he daemon p ocess "adbd", which ini ially uns as oo , changes i s UID be o e c ea ing he ADB shell wi hou oo p i ileges. O he wise, use s can ha e a shell ha can un any p og am as oo . Roo Vulne abili y And oid's pe mission sys em o ces access con ols on secu i y- ela ed esou ces such as senso s, sensi i e da a and impo an communica ion modules. Bu i he phone is oo ed, his pe mission sys em can be a oided. On a oo ed phone, p ocesses can un wi h oo p i ilege and i is possible o access any esou ce wi hou pe mission. Many people oo he de ice o unins all s ock apps, lash hi d-pa y ROMs, use applica ions ha equi e oo pe mission, back up he phone... The p oblem is ha when dealing wi h a oo ed mobile phone, malwa e can access sensi i e da abases (SMS, Con ac s...) and ha dwa e in e aces (came a, mic ophone...) wi hou ha ing he co esponding pe missions be o ehand. In hese cases, he pe mission sys em is no ele an , because i is a oided. Whe eas he e a e applica ions ha o e one-click- oo (by clicking a bu on hey a e able o oo he phone), equally he e exis applica ions ha o e one-click-un oo (i emo es he "su" bina y). Remo ing oo om he phone akes away oo pe missions om po en ial malwa e, so he pe mission sys em becomes ele an again, denying malwa e access o sys em esou ces. Howe e , du ing he ime window in which he de ice is oo ed, i he malwa e has modi ied he packages.xml ile (con aining a lis o pe missions and packages) o apks wi h oo p i ileges, i may ha e escala ed i s pe missions, causing pe mission escala ion a e oo emo al o be a backdoo o he malwa e o abuse esou ces [46]. They could also dele e he ce i ica e es ic ion o sha ing UIDs wi h ano he app; i his is done wi h a p i ileged app, hen p i ileged pe missions o ha app o access o i s da a can be ob ained. Mo eo e , he code could also ha e been modi ied o emo e he pe mission access con ol. The e o e, his ype o malwa e o e s a highe le el o impac , as hey a e able o pe sis a e oo emo al, as well as ha ing a e y high de ec ion e asion a e. 32 2.3 And oid’s Secu i y Sys ems 2.3.1 Linux Secu i y A he ope a ing sys em le el, he And oid pla o m uses Linux ke nel secu i y such as secu e in e -p ocess communica ion (IPC) o enable secu e communica ions be ween applica ions unning in di e en p ocesses [47]. This ensu es ha e en na i e code is es ic ed by he applica ion Sandbox. Thus, he sys em is designed o p e en a malicious applica ion om damaging o he apps, he And oid sys em, o he de ice. The Linux ke nel p o ides And oid wi h se e al key secu e ea u es, including [47]: - A use -based pe missions model. - P ocess isola ion. - Ex ensible mechanism o secu e IPC. - The capabili y o emo e unnecessa y and po en ially insecu e pa s o he ke nel. A undamen al goal o ke nel secu i y is o isola e he esou ces o one use om hose o ano he use , hus [47]: - P e en s one use om eading ano he use 's iles. - Ensu es ha one use does no exhaus he memo y o ano he . - Ensu es ha one use does no d ain ano he use 's CPU esou ces. - Ensu es ha one use does no d ain ano he use 's de ices ( elephony, GPS, Blue oo h...). 2.3.2 Applica ion Sandbox The secu i y o And oid applica ions is en o ced by he applica ion Sandbox [84], which isola es applica ions om each o he and p o ec s apps and he sys em om malicious apps. I achie es his by assigning a unique use ID o each app and unning i in i s own p ocess. The ke nel en o ces secu i y be ween apps and he sys em a he p ocess le el h ough s anda d Linux acili ies such as use and g oup IDs ha a e assigned o di e en apps. By de aul , apps canno in e ac wi h each o he and ha e limi ed access o he OS. As he applica ion Sandbox is loca ed in he ke nel, his secu i y model ex ends o bo h sys em applica ions and na i e code. All so wa e abo e he ke nel, such as ope a ing sys em lib a ies, applica ion amewo ks, applica ion un ime (ART), and all applica ions, a e unning inside an applica ion Sandbox. Gene ally, o e ade he applica ion Sandbox on a p ope ly con igu ed de ice, ke nel secu i y mus be comp omised. Ne e heless, he indi idual p o ec ions ha o ce he applica ion Sandbox a e no in ulne able, so p o ec ion in o dep h is impo an o p e en a single ulne abili y om comp omising he ope a ing sys em o o he apps. Wi h each And oid e sion, p o ec ions ha e been added o p o ec he applica ion Sandbox, such as in 9.0, 33 which o ced all non-p i ileged apps o un in indi idual SELinux Sandboxes, p o iding manda o y pe -app access con ol, o imp o e he sepa a ion o apps, p e en o e w i ing o secu e de aul s, and p e en apps om making hei da a accessible o e e yone. I is no a good idea o make da a accessible o e e yone, as his can be an in o ma ion leak and a popula a ge o malwa e. F om And oid e sion 9 onwa ds his is no allowed. The e o e, o ile sha ing i is used by con en p o ide s o MediaS o e class o hose media iles ha should be accessible o e e yone. 2.3.3 SELinux And oid uses Secu i y-Enhanced Linux (ke nel secu i y module) [48] o apply access con ol policies and se manda o y access con ols on p ocesses. I applies Manda o y Access Con ol (MAC) ins ead o Disc e e Access Con ol (DAC). This implies ha ins ead o he owne o a esou ce con olling he access pe missions a ached o ha esou ce, any access is que ied o a cen al au ho i y. This ensu es ha he so wa e uns only a he lowes p i ilege le el, mi iga ing he e ec s o po en ial a acks. 2.3.4 Sys em’s Secu i y The sys em pa i ion con ains he And oid ke nel, as well as sys em lib a ies, he applica ion un ime (ART), he applica ion amewo k and applica ions [47]. The pa i ion is ead-only. When he de ice is boo ed in sa e mode, hi d-pa y applica ions can be launched manually by he de ice owne , bu a e no launched by de aul . File sys em pe missions ensu e ha a use canno al e o ead ano he use 's iles, unless he de elope explici ly sha es iles wi h o he applica ions [47]. In And oid, each applica ion uns as i s own use . Ve i ied boo ensu es he in eg i y o he de ice's so wa e, s a ing om a ha dwa e oo o us ill he sys em pa i ion [87]. Du ing boo , each s age c yp og aphically e i ies he in eg i y and au hen ici y o he nex s age be o e execu ing i . This makes p i ilege escala ion non-pe sis en , because i de ec s ile sys em modi ica ions and comp omised de ices a e no allowed o boo . And oid p o ides a se o c yp og aphic APIs o use by applica ions [47]. This includes implemen a ions o s anda d and commonly used c yp og aphic p imi i es, such as AES, RSA, DSA and SHA. Addi ionally, hese APIs can be used by high-le el p o ocols, such as SSH and HTTPS. I also has a KeyChain class ha allows applica ions o use sys em c eden ial s o age o p i a e keys and ce i ica e chains. By de aul , only he ke nel and a small subse o co e applica ions can be un wi h oo pe missions. And oid does no p e en a use o applica ion wi h oo pe missions om modi ying he ope a ing sys em, ke nel, o any o he applica ion. In gene al, oo has ull access o all applica ions and hei da a. Use s who change pe missions on an And oid de ice o allow oo access o applica ions inc ease hei exposu e o malicious applica ions and po en ial applica ion c ashes. 34 2.3.5 Use ’s Secu i y And oid suppo s ull ile sys em enc yp ion, so all use da a can be enc yp ed in he ke nel [47]. I also allows ull disk enc yp ion, so ha a single key (p o ec ed by he de ice passwo d) p o ec s he en i e use da a pa i ion; a boo ime he use mus p o ide c eden ials be o e any pa o he disk becomes accessible. I also suppo s ile-based enc yp ion, allowing di e en iles o be enc yp ed wi h di e en keys ha can be unlocked independen ly. Enc yp ing da a wi h a key s o ed in he de ice does no p o ec applica ion da a om use s wi h oo pe missions. Applica ions can add a laye o da a p o ec ion by using enc yp ion wi h a key s o ed ou side he de ice, such as on a se e , o a use passwo d. This p o ides empo a y p o ec ion while he key is no p esen , bu a some poin he key mus be gi en o he applica ion, making i accessible o use s wi h oo pe missions. A mo e obus app oach o p o ec da a om possible access by use s wi h oo pe missions is he use o ha dwa e solu ions. Manu ac u e s can implemen ha dwa e solu ions ha limi access o speci ic con en . And oid also allows o p e-access e i ica ion o he de ice h ough a passwo d gi en by he owne . No only does i p e en access, bu i also p o ec s he c yp og aphic keys o ile sys em enc yp ion. In he case he de ice is los o s olen, he enc yp ion o he en i e ile sys em uses he de ice's passwo d o p o ec he enc yp ion key, so ha modi ying he boo loade o ope a ing sys em is no enough o gain access o he use 's da a. 2.3.6 Apps Secu i y Applica ions can only access a limi ed se o esou ces managed by he OS [49]. Ne e heless, applica ions usually need access o a di e en se o esou ces ou side he Sandbox such as he came a o Blue oo h. This equi es he use o p o ec ed APIs, which a e in ended o be used by applica ions h ough pe missions. Since pe missions a e managed by he OS, in o de o use hese APIs, applica ions mus de ine he pe missions in he mani es and hen he de ice owne ei he accep s o ejec s hem du ing ins alla ion. In case an applica ion ies o access a p o ec ed API no decla ed in he mani es , a secu i y excep ion is aised and e u ned o he applica ion, denying i s access o he eques ed esou ce. 2.4 And oid’s Malwa e 2.4.1 Malwa e ends Malwa e de elopmen o mobile de ices has inc eased conside ably in he las ew yea s. In 2019, he e we e al eady mo e han 27 million malwa e p og ams in he And oid mobile 35 sec o [50]. A g ow h o 690,000 new malwa e p og ams was obse ed, esul ing in an inc easing numbe o bo ne s a ge ing And oid sys ems [50]. Mos in ec ions a e due o malicious apps ob ained om hi d pa ies, which has inc eased by a ound 85% pe yea since 2011 [50]. Figu e 23 below shows he g ow h o malwa e samples on And oid om 2012 o 2018. [40] Figu e 23: New And oid malwa e samples pe yea In 2020, h ea s on And oid de ices a e di ided in o ou di e en ca ego ies [51]: Malwa e, which accoun s o app oxima ely h ee qua e s o he o al; Adwa e, which ep esen s 15.4% o he o al; Riskwa e and PUA (Po en ially Unwan ed Applica ions) being almos negligible a 6% and 4% espec i ely. As shown in Figu e 24, in 2020 malicious ac i i y inc eased by 30% in Ma ch, which coincided wi h COVID-19 c isis [52]. As wo kplace wo k has been o ced o mo e o home, much o he wo kload has shi ed o home, which is o en less p o ec ed han a company's ne wo k. 36 [53] Figu e 24: The And oid h ea ac i i y in Q2 compa ed o Q1 2020 Figu e 25 illus a es he op mobile h ea s de ec ed by Kaspe sky in bo h 2019 and 2020. I shows ha he use o Adwa e has doubled in a single yea . [54] Figu e 25: Dis ibu ion o new mobile h ea s by ype in 2019 and 2020, Kaspe sky 37 Ou o he op en malwa e amilies de ec ed, i e o hem make in usi e use o ads, wi h And oid/Hiddad opping he lis [53]. I is wo h men ioning ha T ojan d oppe s ep esen a hi d o he op en amilies de ec ed in he second qua e o 2020, as shown in Figu e 26. [53] Figu e 26: Top en de ec ed amilies in Q2 2020 2.4.2 Malwa e ypes, aims and cha ac e is ics Common mechanisms: -Pe sis ence: Usually, malwa e samples seek o pe sis on he de ice. One o he mos common mechanisms o achie e pe sis ence is h ough componen hiding. One possible echnique o achie e his objec i e is o disable he ac i i y componen egis e ed in he Launche by he applica ion a he momen o i s ins alla ion, as a esul o which he applica ion's icon disappea s. To u he enable code execu ion, malwa e should implemen a ecei e componen o log sys em e en s and a se ice componen o backg ound execu ion. This allows he malwa e o un in backg ound a sys em e en s, such as s a -up o WiFi ac i a ion, e en hough he icon is no isible. Examples o his can be seen in samples o spywa e, RATs, clicke s o ansomwa e, as hey can deploy hei ull unc ionali y om backg ound execu ion. -Denial o se ice: Malwa e seeks o block access o sc eens om which he applica ion could be emo ed. I does his by using se ices ha , while unning in he backg ound, de ec when he applica ion is ying o be unins alled and o e lay a componen ha p e en s i om doing so. To achie e his, hey usually implemen he GET_TASKS pe mission o ge he applica ion ha is unning in he o eg ound, as well as he BIND_DEVICE_ADMIN pe mission o egis e as De ice Adminis a o . This sec ion lis s he main ca ego ies o malwa e ha can be ound on he And oid ope a ing sys em. Each ca ego y desc ibes i s objec i e and s a egies o iden i ica ion by he analys [55]. 38 Adwa e This is he mos common ype o malwa e on And oid de ices. When aced wi h applica ions wi h ads, i is con o e sial o classi y hem as malwa e, as i is di icul o es ablish a limi a which he use o ads s a s o be abusi e o simply ano he mone iza ion sys em. The main ea u e o his malwa e is he inclusion o API keys in he And oidMani es .xml ile o ob ain he unc ionali y o a ious ads se ices, such as AdMob, Baidu, Adwhi l o Ad-X. These API keys con ain he iden i ie s ha he ads se ices use o iden i y which app is displaying he ads, hus enabling mone a y ewa d. Ano he cha ac e is ic used by mo e agg essi e samples comes om he inclusion o pe missions such as: -SYSTEM_ALERT_WINDOW: I o e lays he cu en window wi h ano he one o you choice. -GET_TASKS: Allows you o see wha o he applica ion is unning. I adwa e de ec s ha a b owse is being used, i can edi ec he use o an ad page. Phishing The aim o his ype o malwa e is o s eal sensi i e use in o ma ion (usually use name and passwo d) by decep ion, p e ending o be a legi ima e applica ion ha hides malwa e. De ec ing phishing is ela i ely easy i i ies o pass i sel o as a legi ima e applica ion. In such a case, by compa ing he digi al ce i ica es, we can check whe he hey a e applica ions p og ammed by he same de elope o whe he we a e dealing wi h a case o impe sona ion, causing i o all in o he ca ego y o phishing. Malwa e o his ype equi es pe missions ha allow i o send s olen in o ma ion, such as access o he In e ne , SMS, e c. This allows us o iden i y his malwa e, especially i i should no equi e hese pe missions gi en he unc ionali y i p omises (a social ne wo king applica ion should no need access o SMS). Also, as hey a e copies o o he applica ions, i is common o he e o be disc epancies wi h he o iginal o unc ional e o s. Spywa e This ca ego y co e s all ypes o applica ions which seek o s eal in o ma ion om a de ice, such as phone numbe , email accoun , con ac s, loca ion, ins alled applica ions, calls, messages, mic ophone access, de ice ID, ope a ing sys em, MAC add ess, e c. In i s code, i he e is no ob usca ion, he e p obably a e s ings ela ed o in o ma ion hey a e looking o , such as email, loca ion, model, phone, SMS, e c. Du ing execu ion, da a is equen ly ei he sen o a se e , pos ed on a o um o sen by SMS, which in ol es ne wo k a ic. Da a may be sen plain o enc yp ed, making i di icul o iden i y. 39 The pe missions equi ed by he spywa e depend on he in o ma ion ha needs o be ex ac ed, o example: -ACCESS_WIFI_STATE: I sea ches o ne wo k in o ma ion om he de ice. -READ_CONTACTS: Access con ac s. -ACCESS_COARSE_LOCATION oACCESS_FINE_LOCATION: Pa a accede a la localización. -READ_SMS o el RECEIVE_SMS: Access messages. -PROCESS_OUTGOING_CALLS y el READ_PHONE_STATE: Phone calls. RAT RAT s ands o Remo e Access Tool o , i i is hidden inside ano he applica ion, Remo e Access T ojan. The aim o his ype o malwa e is o gain emo e con ol o a de ice. These ac ions can be: accessing web pages, ins alling applica ions, sending SMS, sending use in o ma ion, changing de ice con igu a ions, e c. As con ol is emo e, he applica ion mus communica e wi h a C&C (Command & Con ol) se e . Commonly, hese se e s gi e he malwa e de elope he oppo uni y o dis ibu e commands o speci ic de ices. I is o his eason ha he ul ima e goal o his ype o malwa e is he c ea ion o bo ne s ha allow hem o launch dis ibu ed a acks o black ha SEO (Sea ch Engine Op imiza ion) echniques ( hey a e used o imp o e he posi ioning o a websi e in he sea ch engine esul s lis ). This malwa e no mally equi es as many pe missions as possible, allowing o a wide ange o ac ions. Keylogge s This ype o malwa e collec s keys okes ha ha e been p essed by he use and sends hem o an ex e nal se e . Some con o e sy also a ises wi h applica ions wi h his unc ionali y, as he e a e keyboa d applica ions ha collec keys okes and s a is ics o imp o e hei se ices, aising a dilemma as o whe he hey should be conside ed malwa e o no . Such applica ions usually ha e he ollowing pe missions: -BIND_INPUT_METHOD: Mus be equi ed by an Inpu Me hodSe ice, o ensu e ha only he sys em can bind o i . -ACCESS_NETWORK_STATE: Allows applica ions o access in o ma ion abou ne wo ks. -INTERNET 40 Tapjacking Malwa e o his ype is designed o ick he use in o p essing on he sc een, pe o ming a di e en unc ion han he one he use hinks she/he is pe o ming. The wo mos ypical implemen a ion echniques a e based on Toas and WindowManage . Toas is a sys em o displaying ex messages in pop-up o ma . Clicks on i a e non- unc ional, so hey a ec wha e e is unde nea h he pop-up. These messages can be designed using XML, so hey can be made o look simila o a dialogue wi h bu ons. This would allow he malwa e de elope o design a pop-up which guides he use 's aps o whe e she/he wan s hem o go. I is common o such applica ions o equi e he GET_TASKS pe mission o know which applica ion is open and hus which applica ion he use 's aps on he Toas a e wo king on. Clicke s The pu pose o his kind o malwa e is o load web pages and click on links o imp o e he anking o ha page (black ha SEO), in ads wi h he aim o c ea ing a la ge numbe o hi s ha gene a e a inancial bene i o he de elope , o edi ec a ic im o download o he malwa e. I is common o many o he click-accoun ing sys ems on websi es o be Ja aSc ip code. Clicke s mus he e o e ha e he abili y o load HTML code and in e p e Ja aSc ip . Some decla e he SYSTEM_ALERT_WINDOW pe mission. Ransomwa e I s aim is o inhibi access o de ice esou ces, ypically o demand a inancial paymen . On compu e s i is usually implemen ed by enc yp ing iles; None heless, on And oid his me hod is less common due o he applica ion Sandbox, which limi s he esou ces ha each applica ion can access, e en i a de ice is oo ed , he ansomwa e could escala e p i ileges and gain access o all iles. The e o e, he mos common in And oid a e ac i i y blocke s, which equi e pe missions o iden i y he applica ion ha is in he o eg ound and o e lap wi h i , causing he use o be unable o use hei de ice. These applica ions usually equi e he ollowing pe missions: -RECEIVE_BOOT_COMPLETED: Launch ansomwa e as soon as he de ice boo s up. -USER_PRESENT oSCREEN_ON: De ec i he use is in e ac ing wi h he de ice. -WRITE_SETTINGS: Modi y se ings on he de ice. - BIND_DEVICE_ADMIN: Allows Sys emUI o eques hi d pa y con ols. 41 And oid Vi ual Machine An And oid emula o was equi ed in o de o es he analyze wi h eal malwa e. The machine has been con igu ed wi h he i ualiza ion en i onmen VMwa e, and he e sion o he ope a ing sys em is And oid 8. PackageManage and PackageIn o In o de o handle he me ada a in o ma ion ha he ins alled applica ions con ains, he analyze uses he classes PackageManage and PackageIn o. The PackageManage is a class o e ie ing a ious kinds o in o ma ion ela ed o he applica ion packages ha a e cu en ly ins alled on he de ice [78]. The PackageIn o is a class ha con ains o e all in o ma ion abou he con en s o a package. This co esponds o all he in o ma ion collec ed om And oidMani es .xml [77]. Gi hub Desk op Gi hub Desk op is an applica ion ha enables use s o in e ac wi h Gi Hub using a GUI ins ead o he command line o a web b owse [64]. We used his ool o manage he e sions o he applica ion and o seamlessly me ge each con ibu ion o all he pa icipan s o he eam, allowing a pa allel de elopmen . 3.1.1 Samples In addi ion o he ools necessa y o de elop he wo k p esen ed he e, we ha e had o look o samples o malicious applica ions o pe missions misin o ma ion o es he ool. Malicious Apps Hashes Despi e e o s o acqui e a da abase con aining he digi al signa u es (hash unc ion) enc yp ed in di e en enc yp ion algo i hms (SHA, MD5, e c.) o all exis ing malwa e, we could only ind a lis o MD5 hashes o malwa e samples [76]. Nowadays mos common enc yp ion algo i hms o digi al signa u es o applica ions a e SHA1, SHA2, and MD5. The e o e, we ied o ob ain a da ase which con ains one o hese algo i hms. I is wo h men ioning ha he mos secu e op ion is he use o SHA256 algo i hm o highe as i causes less collisions, so we ha e he e o e adap ed he C yp og aphic Signa u e Analysis so ha i emains unc ional when using a di e en hashing algo i hm. 48 Pe missions Da ase The pe missions da ase is mos ly used by he pe mission analysis bu i is also used in o he aspec s o he applica ion. This sample has been made om a ious sou ces, speci ically om he pe missions API e e ence page o he And oid De elope s O icial Si e [79] and om he And oid Pe missions si e [80] so as o ge a da ase as comple e as possible. Wha is s o ed in his da ase a e he pe mission cons an s, he le el o dange , a desc ip ion o he pe missions and he g oup hey belong o. Domains Da ase The Domains da ase is also used by he pe mission analysis. This sample has been made om he And oid Pe missions si e [42] whe e all he pe missions a e assigned o a speci ic g oup. In his da ase i is s o ed he pe mission g oups, an alias o he domain and a desc ip ion o he g oup. 3.2 Decisions In his sec ion we p esen a summa y o he design decisions ha we ha e made h oughou he de elopmen p ocess o his wo k and ha a ec he inal o m o he de eloped ool. - We decided o implemen a log analysis o And oid because we wan ed o ha e a dynamic analysis o add some unc ionali y o e he wo o he me hods o analysis. Also, since we did no ind much in o ma ion abou i , we wan ed o y and c ea e some hing ela i ely new. - We op o implemen a pe mission analyze because i can gi e he use plen y o in o ma ion abou wha he applica ion is ying o achie e. Also, by gi ing a sco e we belie e we can show isually and e ec i ely i i is ac ually a bene olen applica ion. Finally, we hink ha i can aise he use ’s awa eness ega ding pe mission g an ing and encou age hem o check he pe missions o he applica ions being ins alled on hei de ice. - We chose o implemen a signa u e analyze since i he e is a collision ound wi h i s signa u e, i is almos ce ain ha i is malwa e, implying ha his analysis me hod gi es an almos absolu e ce ain y o he use . - We decided o implemen a Se e Se ings F agmen because e e y ime he EC2 ins ance is launched, a new IP is se o he ins ance. I we had no de eloped his agmen , each ime we launched he ins ance we would ha e needed o w i e he new IP in he applica ion code, build he APK and ins all i on ou mobile phones. Also, his agmen allows he use o c ea e hei own se e and only ha e o wo y abou adding he IP wi hou changing any code. - We chose o p ocess he logs on he cloud because doing i locally would ha e implied ha he applica ion would p obably lag o c ash due o he amoun o p ocessing powe needed. I also implies ha he ba e y usage is educed, since less powe is needed. Finally, his allows he use o se up hei own se e o p ocessing he logs. 49 - We also concluded ha we would only analyze he applica ions ins alled by he use and no he s ock applica ions since hese applica ions a e de eloped by ele an companies which a e globally us ed. Also, since he use canno unins all hem, i would only mean ha he analyses would ake mo e ime and hey would no gain any hing. - We decided o implemen he upg ading and adjus men o he applica ion code in case o a da abase eplacemen , because in case o being able o acqui e a da a se wi h enc yp ion algo i hms be e han MD5 o e en con aining se e al ypes o algo i hms applied o a single applica ion. - We decided o de elop ou app o a leas And oid 8.x (O eo) e sions, as hey mo ed om an Ins all- ime pe missions policy o a Run ime pe missions policy. In addi ion, we make su e we a e up o da e wi h e sion 11, which can be conside ed he mos up o da e e sion, as e sion 12 is s ill in es ing. Finally, we decided o wo k wi h his e sion because, in he pe mission analysis, he app e ie es he ca ego y o he ins alled apps. This ac ion can only be pe o med wi h a 26 API le el which co esponds o And oid 8. 50 4. Analysis Me hods This chap e in oduces he heo y equi ed o unde s anding he h ee analysis me hods we ha e pe o med in he applica ion, which a e he C yp og aphic Signa u e Analysis, he Heu is ic Log Analysis and he Pe mission Analysis. 4.1 C yp og aphic Signa u e Analysis This sec ion ocuses on he concep s o c yp og aphic signa u es and hei subsequen analysis o de ec malwa e. In he li e a u e on his subjec , inge p in s calcula ed wi h a hashing algo i hm a e o en e e ed o as signa u es. The e a e cu en ly o he me hods o malwa e de ec ion, bu he use o signa u es o hash unc ions by compa ing wi h he esul s o p e iously de ec ed and analyzed malwa e is s ill he mos unc ional echnique o an i i us o secu i y sys ems. Google Play S o e equi es ha each APK mus be signed wi h wo digi al ce i ica es: an App signing key (used o sign APKs ha a e ins alled on a use 's de ice) and an Upload key (used o sign he app bundle o APK be o e you upload i o app signing wi h Google Play). As pa o And oid secu i y, he signing key ne e changes du ing he li e ime o an applica ion, so i no only ensu es ha And oid applica ions a e us wo hy, bu also e i ies ha he applica ion has been p o ided by a us ed sou ce [65]. I a hi d pa y manages o ake an App signing key wi hou he knowledge o pe mission o an app de elope , i could sign and dis ibu e he app ha maliciously eplaces he au hen ic applica ion o co up s i . Mo eo e , i could also sign and dis ibu e apps unde you iden i y ha a ack o he apps o he sys em i sel , o co up o s eal use da a. The ce i ica e inge p in is a sho and unique ep esen a ion o a ce i ica e ha is o en eques ed by API p o ide s alongside he package name o egis e an app o use hei se ice. The MD5, SHA-1 and SHA-256 inge p in s o he upload and app signing ce i ica es can be ound on he app signing page o he Play Console. When you a e ying o publish an applica ion you mus ha e p e iously signed i by you sel p o iding he SHA-1 o you signing ce i ica e o you upload i o he Play Console, and Play App Signing akes ca e o he es . Google Play S o e checks ha he package name and ce i ica e ma ch wi h he applica ion and i hey do no ma ch i is no o e ed o use s bu i i is an upda e o an exis ing applica ion in he s o e i will conside i as a new applica ion and will no o e i o use s as an upda e [66]. The analysis o c yp og aphic signa u es is based on da abase que ies, which s o e he in o ma ion ob ained om p e iously epo ed o analyzed malicious iles o applica ions. This in o ma ion con ains he summa y unc ions o he malicious iles which a e used o uniquely and unambiguously iden i y each ile hos ed in he da abase. C yp og aphic signa u es a e a ma hema ical algo i hm (hash unc ion) ha maps a da a se , ega dless o i s size, o a bi -a ay o a ixed size. They a e essen ial o malwa e de ec ion 51 since in case o e en he sligh es modi ica ion o he da a o code, he bi -a ay changes ex ensi ely. They a e also de e minis ic so ha a malicious ile always gene a es he same bi a ay when applying he same hash unc ion and i he hash unc ion chosen has a weak collision, i would be impossible o ind one malicious ile and ano he alid ile con aining he same hash. The e a e di e en ypes o algo i hms used o hash unc ion gene a ion, bu he mos common a e SHA2 (256, 384 o 512 bi s), SHA1 (160 bi s) and MD5 (128 bi s). The no o ious di e ence be ween he p e iously men ioned algo i hms ocuses on he leng h o he gene a ed hash s ing, he longe he leng h o he s ing he lowe he p obabili y o a collision. We can see in Figu e 28 an analysis o an And oid applica ion pe o med by he online ool Vi usTo al [81], which makes use o a da abase managemen sys em ha s o es signa u es. I ocuses on pe o ming ile que ies emo ely using a hash unc ion (SHA256) in o de o check i he iles a e malicious. [81] Figu e 28: Vi usTo al - Analysis o an And oid apk 52 4.2 Heu is ic Log Analysis Log iles a e compu e -gene a ed ex iles ha a e au oma ically p oduced whene e a speci ic e en akes place in a speci ic en i onmen , such as an ope a ing sys em, applica ion, se e , e c. They con ain in o ma ion abou usage, ac i i ies and ope a ions. This in o ma ion is use ul o oubleshoo ing and debugging he en i onmen , since hey keep a eco d o e e y hing ha has happened in a ex ual o ma . They ypically ha e he LOG ile ex ension. Each ope a ing sys em has di e en me hods o s a ing o s opping logs eco ding, since bo h he en i onmen and he speci ic e en s ha igge hem a e di e en . The e o e, each OS is uniquely con igu ed o gene a e log iles in esponse o speci ic e en s. In he case o Linux, i di ides log iles in o ou ca ego ies: Applica ion logs, E en logs, Se ice logs and Sys em logs [67]. 4.2.1 And oid logs And oid Logging Sys em consis s o di e en ci cula bu e s, which p o ide logging o di e en pa s o he sys em. These log bu e s a e [68]: - adio: This bu e con ains adio/ elephony ela ed messages. -e en s: This bu e s o es bina y sys em e en messages. -main: This is he de aul log bu e , which does no con ain sys em and c ash log messages (i con ains he applica ions logs). This is he only bu e a ailable o apps. -sys em: This bu e con ains he sys em logs. -c ash: This bu e s o es logs ela ed o c ashes. -ke nel: This bu e s o es ke nel ela ed logs. -secu i y: This is he secu i y log bu e . -s a s: This bu e co esponds o s a is ics logs. Each message in he log consis s o a ag indica ing he pa o he sys em o applica ion ha he message came om, a imes amp, he message log le el and he log message i sel . The log le el is a cha ac e ha encodes he p io i y o he log en y (i is And oid’s e minology o se e i y le el). He e we lis all he possible alues i can ake, o de ed om lowes o highes p io i y [68]: -V: Ve bose (lowes p io i y) -D: Debug -I: In o -W: Wa ning -E: E o -F: Fa al -S: Silen (highes p io i y, on which no hing is e e p in ed) The Log class (and oid.u il.Log [69]) is an API ha allows use s o c ea e log en ies based on hei log le el. I con ains se e al public me hods o logging in each p io i y. Fo 53 example, o Ve bose p io i y he use can use he me hod Log. (), o Wa ning p io i y he use can use Log.w(), e c. Typically, hese me hods ake wo a gumen s: he log’s ag ( o example, i could be he name o he ac i i y ha c ea es he log) and i s message. The API hen c ea es he log en y wi h he passed alues and adds he imes amp, he iden i ie o he issuing p ocess and h ead and o he in o ma ion. On he o he hand, he Logca command-line ool is used o eading logs. The use can un logca h ough an adb shell using he ollowing syn ax: [adb] logca [<op ion>] ... [< il e -spec>] … This command has a wide a ie y o op ions; hese a e he mos ele an [70]: --b <bu e >: Speci ies he log bu e ha is going o be ead. --c: Clea s he en i e bu e . --d: Dump he log con en s. -- < o ma >: Se s he ou pu o ma o log messages. The de aul is h ead ime o ma . The e a e se e al ou pu o ma s ha modi y he ou pu so ha hey display ce ain me ada a ields. The ollowing lis co esponds o he suppo ed ou pu o ma s [70]: -b ie : Display p io i y, ag, and PID o he issuing p ocess. -long: Display all me ada a ields. -p ocess: Display PID only. - aw: Display he aw log message wi h no o he me ada a ields. - ag: Display he p io i y and ag only. - h ead: A legacy o ma ha shows p io i y, PID, and TID o he h ead issuing he message. - h ead ime (de aul ): Display he da e, in oca ion ime, p io i y, ag, PID, and TID o he h ead issuing he message. - ime: Display he da e, in oca ion ime, p io i y, ag, and PID o he p ocess issuing he message. Now we show some examples o he mos ele an o ma s: - The de aul ou pu o ma has he ollowing s uc u e: Da e Time PID TID P io i y Tag: Message 05-16 20:04:58.151 6992 7560 i came a : open came a: 1, package name: com.wha sapp - The b ie ou pu o ma has he ollowing s uc u e: P io i y/Tag( PID): Message I/Ac i i yManage ( 585): S a ing ac i i y: In en { ac ion=and oid.in en .ac ion...} - The long ou pu o ma has he ollowing s uc u e: 54 [ Da e Time PID: TID P io i y/Tag ] Message [ 05-28 18:30:53.542 3716: 3733 I/com.wha sapp ] Backg ound young concu en copying GC eed 25395(1669KB) AllocSpace objec s, 0(0B) LOS objec s, 24% ee, 6753KB/8917KB, paused 262us o al 112.240ms 4.2.2 Log handling Log iles eco d a la ge amoun o in o ma ion ha con eys e e y hing ha is happening in he sys em. This makes log iles an impo an elemen o conside i we wan o analyze wha applica ions a e unning on he sys em and y o igu e ou wha ac ions hey a e ca ying ou . The e o e, log analysis is a sc u iny me hod widely used in he indus y o malwa e de ec ion. The mos ypical use cases o log analysis a e [71]: -Compliance wi h secu i y policies, audi s o egula ions. - Sys em oubleshoo ing. -Fo ensics. - Secu i y inciden esponse. - Unde s anding online use beha iou . -Pe o mance imp o emen . Depending on he use case, he beha iou o log analysis di e s acco ding o he con ex o he log iles. A e all, bo h he da a and objec i e behind a ne wo k log analysis a e no he same as a sys em log analysis. Hence, log analysis mus in e p e messages wi hin he con ex o he applica ion o sys em. None heless, hey usually ha e some p ocedu es in common [71]: -No maliza ion: Con e ing log messages om di e en sou ces in o a uni o m o ma . -Pa e n ecogni ion: Selec ing incoming log messages and compa ing hem wi h a p e iously es ablished da ase o il e o handle he logs in di e en ways. -Classi ica ion and agging: O de ing and classi ying log messages in o di e en ca ego ies based on speci ic keywo ds, da es, e c o la e usage. -Co ela ion analysis: Collec ing messages om di e en sys ems and inding all he messages belonging o one single e en . -A i icial Igno ance: Disca ding log en ies which a e known o be unin e es ing. The no maliza ion and classi ica ion p ocedu es ensu e an ease o use while handling he log messages. Secondly, he pa e n ecogni ion and co ela ion analysis p ocedu es g an he analys he in o ma ion necessa y o d aw use ul conclusions om he log en ies. Las ly, he a i icial igno ance p ocedu e ensu es he ce ain y o he esul s as well as a be e pe o mance. Log analysis is a ype o dynamic analysis, since i examines he beha iou o a sys em, ne wo k o applica ions while hey a e in execu ion. This implies i is a ime and esou ces consuming p ocess, since huge amoun s o in o ma ion a e gene a ed each second and 55 e e y log mus be checked. Ne e heless, i s g ea es ad an age is ha i allows he adminis a o o disco e how he analyzed elemen is in e ac ing wi h he sys em, which helps disco e mal unc ion o damages. The e a e ools cen ed in And oid log analysis o moni o sys em use. As an example, Sola Winds Loggly [72] has se e al unc ionali ies ha allow he use o pe o m an analysis o he logs o his de ice: i agg ega es all o he And oid logs on he cloud so ha he use can moni o and analyze hem by means o sea ch que ies and simpli ied cha s and dashboa ds. Ano he example is And oidLogViewe [73], which displays he logs o he use ’s And oid de ice and allows him o sea ch in hem using egula exp essions, il e hem by ag, PID, p io i y, e c and mo e. 4.3 Pe mission Analysis And oid app pe missions a e conside ed o be a il e ha helps o p ese e use p i acy by p o ec ing access o es ic ed in o ma ion, such as he use 's sys em s a us and con ac in o ma ion, and o es ic ed ac ions, such as connec ing o a linked de ice o eco ding audio. They lie in he And oidMani es .xml ile [24] and he e a e di e en classes depending on hei pu pose and es ic ion scope ha hey g an . This sec ion co e s he impo ance o And oid pe missions om a malwa e analysis app oach and p o ides a de ailed explana ion o how hey a e assessed and classi ied. Al hough he p e ious analysis and all he in o ma ion decla ed in he And oidMani es ile mus be conside ed as ele an , an And oid pe missions assessmen is undoub edly one o he sec ions o which mo e a en ion should be paid as a s a ing poin when analyzing malwa e on And oid. All sys em unc ionali y ha he applica ion wan s o access ha e o be decla ed wi hin he And oidMani es .xml ile unde he ollowing ags s uc u e: <mani es > <uses-pe mission /> <pe mission /> <pe mission-g oup /> … </mani es > Since in his wo k he pe mission analysis is pe o med on he <uses-pe mission /> ag, nex , we e iew wha i s objec i e is. <uses-pe mission> ag This ag indica es wha pe missions an applica ion equi es, e e ing o ha dwa e and so wa e componen s ha a e on he de ice and ha he applica ion can make use o . F om a malwa e analysis pe spec i e, he key is o ind some kind o unusual beha iou s and o he indica o s. The e o e, in a s udy o decla ed pe missions i is impo an o ba e in mind he ollowing asks [74] as a guide: 56 - Iden i y hose applica ions ha eques a la ge amoun o pe missions. These kinds o applica ions gene ally demand addi ional pe missions wi hou ac ually equi ing hem, which is a sign o unusual beha iou and migh be a hin o a malwa e en y. - Iden i y he unc ions ha he applica ion in ends o pe o m h ough he decla ed pe missions. - Iden i y he pe missions ha i does no make sense o decla e acco ding o he supposed na u e o he applica ion. Fo example, an applica ion whose supposed unc ionali y is o allow he use o change he wallpape desk op backg ound, bu which, h ough i s pe missions, eques s sending o SMS messages. - Iden i y he pe missions ha he applica ion does no decla e, bu i would be expec ed o decla e acco ding o he supposed na u e o he applica ion. Fo example, a pho og aphy applica ion ha does no equi e access o he came a. - Iden i y he pe missions ha he applica ion decla es and, acco ding o i s classi ica ion, look o hose which a e conside ed o be in asi e and po en ially dange ous. Fo example, pe missions ha dele e packages, moun /unmoun ilesys ems, ead logs, e c. On he o he hand, i he applica ion ins alla ion p ocess is analyzed, some peculia i ies should be obse ed depending on he ype o ins alla ion ha is ca ied ou : - In case o ins alling h ough he Google Play S o e, he pe missions a e shown o he use g ouped by ca ego ies o eques hei consen . A his poin i is impo an o no e a peculia i y ha occu s when upda ing applica ions ha a e al eady ins alled on he de ice, since he e may be h ea s ha make use o i : ○ I a pe mission om a ca ego y ha has no been p e iously app o ed is added, a con i ma ion dialog is shown o he use in o de o app o e he new g oup o pe missions. ○ I a pe mission om a ca ego y ha has been p e iously app o ed is added, no con i ma ion is eques ed om he use . So he e migh be he possibili y ha an applica ion ha ini ially eques ed a ce ain ca ego y, a e an upda e, inco po a es a new pe mission ha belongs o he same ca ego y wi hou asking he use o any con i ma ion. Fo example, an app ha ini ially eques s he Messaging ca ego y because i uses he and oid.pe mission.READ_SMS pe mission, a e an upda e, i inco po a es he and oid.pe mission.WRITE_SMS pe mission wi hou asking he use o app o al. - In case o ins alling an APK h ough al e na i e ma ke s such as Amazon AppS o e o Ap oide (in any o he cases i is necessa y o ha e allowed he ins alla ion om 57 -Ins alledAppsAdap e : I is a iew adap e which con ols how he Recycle iew shows he iew. I also maps all applica ion’s in o ma ion om he xml ile o unc ions in he adap e . The e is implemen ed a lis ene which w aps he en i e i em and i he checkbox is clicked, i is se o he opposi e o wha i was, so ha wi h he use o no i yDa aSe Changed() me hod, he lis o apps is e eshed wi h i s espec i e checkbox om Recycle View. -Signa u eAnalyze F agmen : I is he main class whe e all bu on’s unc ionali ies a e de ined wi h hei own lis ene and mapped o XML componen s based on he g aphical iew. Un o una ely, MD5 has been c yp og aphically b oken and conside ed insecu e. Fo his eason, i is always ecommended o s o e c yp og aphic signa u es using a di e en hashing algo i hm, so we decided o implemen a me hod (Figu e 35) in which i examines he i s line o a da abase added and i checks which hashing algo i hm is used by i s cha ac e leng h. This makes ou app capable o upda ing he da abase managemen in case he e is a hash da abase subs i u ion. Figu e 35: Me hod o ecognise which algo i hm is used in he da abase P oblems o e come The i s e sion o he da abase p esen ed a p oblem which was he epe i ion o he uples when ini ialising ou da abase, so o sol e i we p oceeded o modi y hash, d_g p and idpe m columns o ype UNIQUE. Rega ding he de elopmen o he c yp og aphic signa u e analyze , se e al modi ica ions we e made un il we eached he inal e sion. A e managing o display he lis o applica ions ins alled on he And oid de ice along wi h a checkbox, we decided o implemen he SELECT ALL op ion o make i s aigh o wa d o he use o make a ull selec ion o apps. In addi ion, i was decided o add a Sea chbox as i was di icul o ind a speci ic app among all he ins alled ones. Being awa e o he ac ha he Malwa e Lis able was no secu e enough in e ms o he hashing algo i hm used, we s uc u ed he c yp og aphic signa u e analyse so ha i can be unc ional wi h any da abase con aining a di e en hashing algo i hm. 64 5.2 Heu is ic Log Analysis Implemen a ion In he discussions ca ied ou by he membe s o he eam o he design o he malwa e de ec ion ool, we came o he conclusion ha a heu is ic analysis o he log iles was necessa y. The easons behind ou decision o implemen his analysis a e he ollowing: - To ale he use o all he applica ions ha a e cu en ly unning on he de ice, since some o hem may be unning in he backg ound wi hou he use ’s knowledge. - To le he use know wha a ge elemen s (came a, SMS, s o age, e c) each unning applica ion is ying o access. - To le he use es ablish speci ic keywo ds ha will be moni o ed. The esul shows all he applica ions ha sha ed a log en y wi h ha speci ic keywo d. - To check i he applica ions ha accessed ce ain a ge elemen s had he pe missions necessa y o do so. O all he p ocedu es commonly used in log analysis, we use he ollowing: -Classi ica ion and agging: We classi y he logs by package name and keywo d. -Co ela ion analysis: We g oup all he logs o each applica ion and co ela e all he logs o a speci ic applica ion by he a ge elemen s accessed. -A i icial Igno ance: We only use hose logs ha con ain some hing ela ed o applica ions, since he e a e plen y o sys em logs ha a e no in e es ing o malwa e de ec ion pu poses. We ha e de eloped his analysis di iding i s unc ionali y in o wo pa s: -Applica ion: I connec s he And oid mobile de ice o he se e , ex ac s i s log en ies, sends hem o he se e along wi h he package names o all he use apps ins alled on he de ice and some il e s se by he use . A e he analysis is s opped, i e ie es he esul om he se e and s o es ha esul in he P e ious Resul s da abase loca ed in he And oid de ice. Finally, i displays he conclusion isually, a e p ocessing he esul . -Se e : Whene e an incoming connec ion om any mobile de ice a i es, i p ocesses he logs ecei ed based on he il e s es ablished by he use and, a e s o ing all he logs, i summa izes he en ies o in e es . Once he s op signal is ecei ed, i e ie es he esul s ob ained and sends hem back o he applica ion ins alled in he mobile de ice h ough he connec ion. 5.2.1 Applica ion Se up Reading logs is no some hing ha a egula applica ion should do. Fo his eason, he pe mission needed o accessing hem, called and oid.pe mission.READ_LOGS, is a o bidden pe mission, which means ha i canno be g an ed by he use like no mal pe missions. One way o g an ing his ype o pe missions o applica ions is by oo ing he de ice, which is ex emely isky. Ins ead, he use can use ADB (And oid Debug B idge) [45] o open a shell ha communica es wi h he de ice. 65 Fi s o all, he use mus be able o access he de elope op ions o he And oid de ice: - This is achie ed by clicking 7 imes he build numbe , ke nel e sion o o he alue inside he in o ma ion abou he phone (depends on he de ice). - Inside he de elope op ions he use mus allow he USB debugging. - The use needs o ha e ins alled ADB h ough pla o m- ools [82] on he compu e o which he phone is going o be plugged. - A e plugging he phone o he compu e and accep ing o connec o said compu e , he use mus en e he di ec o y o pla o m- ools h ough a e minal (CMD in Windows). Using he command adb de ices we can check i he de ice is being de ec ed. I i is, he use mus execu e he command adb shell pm g an com.example.and oidmalwa eanalyze and oid.pe mission.READ_LOGS, which g an s And oidMalwa eAnalyze he READ_LOGS pe mission. Classes de eloped As Figu e 36 shows, h ee di ec o ies we e de eloped o con ain he unc ionali y o he Log Analysis: -se e Se ings: Handles he IP and Po numbe s used o connec o he se e . -logAnalyze : All he unc ionali y o he analysis is con ained inside his di ec o y, excep sa ing he esul ob ained om he se e and displaying i . -p e Resul s: Con ains he P e Resul sDB, which is he da abase used o s o e he esul s o bo h he signa u e and log analyses. I also con ains he unc ionali y needed o displaying said esul s. Figu e 36: O ganiza ion o he Se e Se ings, Log Analyze and P e ious Resul s classes 66 Nex , we explain each class ha composes he Se e Se ings: -Se e Se ingsF agmen : This F agmen is used o handle he add esses (IP:Po ) ha he Log Analyze will use o connec o he use . All he al eady s o ed add esses a e shown h ough a Lis View.These add esses can be selec ed by he use , simply by p essing hem. The add ess selec ed by he use is he one ha is going o be used o he connec ion. This F agmen also displays one bu on o adding add esses and one o dele ing he selec ed add ess. The add esses a e s o ed inside Sha edP e e ences. When he use adds a new add ess, bo h IP and Po numbe s a e pa sed. The pa sing me hod is shown in Figu e 37. Figu e 37: Se e Se ingsF agmen - Add ess pa sing Nex , we explain each class ha composes he Log Analyze : -LogAnalyze F agmen : This F agmen is he en ypoin o he log analysis. I is used o displaying wo bu ons. Bo h bu ons edi ec o he LogAnalyze F agmen Applica ions, passing a boolean pa ame e , which ells he class i he applica ions o be lis ed ha e o be use applica ions (ins alled by he use ) o sys em applica ions (s ock-apps, sys em se ices). The use will ha e o choose be ween one o hem. -LogAnalyze F agmen Applica ions: This F agmen is he on end o he analyze . I i s c ea es a Recycle View and se s i s Adap e wi h a new class, called 67 LogAppsAdap e . Then, i also ini ializes he LogAnalyze Connec . In his F agmen , he use can ype some keywo ds ha will be moni o ed while analyzing he logs. When he analysis is s a ed, he LogAnalyze Connec is execu ed. When he analysis is s opped, i sa es in he P e Resul sDB he esul ob ained and calls he class ShowLogResul o display he esul . This class also has an ale message sys em ha , based on an in ege , displays a Snackba wi h in o ma ion ega ding he s a us o he analysis (Figu e 38). Figu e 38: LogAnalyze F agmen Applica ions - s a us -LogAppsAdap e : This class ex ends Recycle View.Adap e . I is esponsible o con olling he checkbox lis o applica ions. I i s e ie es all he applica ions ins alled on he de ice, bo h use and sys em apps (Figu e 39). The package name, applica ion name and icon o all he applica ions a e s o ed in wo A ayLis s o PackageIn oS uc classes, which we de eloped o s o e ypical alues o applica ions (Figu e 40). One o he a ays con ains he use apps and he o he he sys em apps. Depending on whe he he use chose o lis use o sys em applica ions, he co esponding a ay is used in he checkbox lis . Fo each applica ion, his Adap e shows i s icon and applica ion name and a checkbox; i no applica ion name is ound, he package name is p in ed. 68 Figu e 39: LogAppsAdap e - ge ins alled apps Figu e 40: LogAppsAdap e - PackageIn oS uc -LogAnalyze Connec : This class ex ends AsyncTask [86]. I is esponsible o ex ac ing he logs, sending hem o he se e and e ie ing he esul om he se e . I i s loads he selec ed add ess ha was s o ed in Sha edP e e ences in he Se e Se ingsF agmen . When his AsyncTask is execu ed, he AsyncTask me hod doInBackg ound() is called. This me hod i s connec s o he se e using he loaded add ess (Figu e 41). Once connec ed o he se e , he logs a e sen h ough he connec ion (Figu e 42). When he use p esses he bu on o s op he analysis, he esul is e ie ed h ough he connec ion (Figu e 43). Finally, when doInBackg ound() inishes, he AsyncTask me hod onPos Execu e() sends he esul back o LogAnalyze F agmen Applica ions. Figu e 41: LogAnalyze Connec - New connec ion 69 Figu e 42: LogAnalyze Connec - Ex ac and send logs Figu e 43: LogAnalyze Connec - Re ie e esul - LogResul : This class is esponsible o con e ing he esul om ex in o an a ay o LogIn e ac ions classes (Figu e 44), which we de eloped o s o e in o ma ion needed o display he esul . I also has a unc ion ha educes he size o he esul , as he da a e ie ed om he se e may ha e some applica ion esul s spli o e mo e han one line, allowing i o be educed o a single line. This way, he da abase sa es some space. Figu e 44: LogResul - A ibu es 70 Nex , we explain each class ha composes he P e ious Resul s: -P e Resul sDB: This class ac s as a da abase o he esul s ob ained om he log and signa u e analysis me hods. This da abase con ains a able called p e Resul s, which is o med by he columns shown in Table 4. The da e ime o he comple ion o he analysis is s o ed o know when he analysis was pe o med. The analysis_ ype ow di e en ia es be ween he signa u e and log me hods. The apps_analysed alue is used o know wha elemen s we e analyzed and he analysis_ esul s o es he esul ob ained om he analysis. The wo main me hods o his da abase a e inse ToDB() (inse s a new esul in o he able) and eadAllF omDB() ( e ie es all he esul s pe o med). P e Resul s Column name Type Schema _id INTEGER PRIMARY KEY AUTOINCREMENT da e TEXT Da e and ime when he analysis was inished analysis_ ype TEXT Desc ibes he analysis ype (log o signa u e) apps_analysed TEXT Lis o he keywo ds and package names o he applica ions analyzed analysis_ esul TEXT Resul o he analysis Table 4: P e ious Resul Table s uc u e -P e Resul sF agmen : his F agmen is he en ypoin o he P e ious Resul s. I i s ge s all he esul s s o ed in he da abase h ough he me hod eadAllF omDB() and displays hem in a Recycle VIew whose Adap e is an ins ance o P e Resul sAdap e . I he use selec s one o he elemen s o he lis , she/he will be edi ec ed o ShowResul i i is a signa u e analysis esul o ShowLogResul i i is a log analysis esul . I no analysis has been pe o med, he message "No analysis pe o med ye " is displayed. -P e Resul sAdap e : This class ex ends Recycle View.Adap e . Fo each elemen , i displays he da e when he analysis was pe o med and he analysis ype (signa u e o log). -ShowResul : This F agmen displays he esul ob ained om a signa u e analysis. Ini ially, his class calls i s me hod ge Ins alledApps() (see Figu e 45). Fi s o all, his me hod checks i no applica ions ha e been analyzed. I ue, hen he lis o apps analyzed will display “None”. I a leas one applica ion has been analyzed, i ge s he applica ion name, package name and applica ion iconn o he analyzed 71 applica ions. This p ocess is simila o he one used in LogAppsAdap e . These applica ions a e hen displayed using he P e Resul sRecycle View class, wi h he Elemen sAdap e . A e wa ds, a Tex View displays he esul . Figu e 45: ShowResul - ge Ins alledApps -P e Resul sRecycle View: This class ex ends Recycle View. I was de eloped o es ablish a dynamic size o he lis , since he lis had o ha e he necessa y heigh o w ap i s con en s, bu also maximum heigh , so ha i did no ake up oo much space. As seen in Figu e 46, his was accomplished by o e iding he onMeasu e() me hod and se ing a heigh o 750 a mos . Figu e 46: P e Resul sRecycle View - onMeasu e -Elemen sAdap e : This class ex ends Recycle View.Adap e . I displays all he applica ions o elemen s analyzed ( he keywo ds speci ied in LogAnalyze F agmen Applica ions). 72 -ShowLogResul : This F agmen is used o show he esul s o a log analysis. I i s ly c ea es an ins ance o LogResul and calls i s me hod ge Lis (), which con e s he esul om ex o an a ay o LogIn e ac ions. A e wa ds, he me hod ge Ins alledApps() o ShowLogResul is called (see Figu es 47 and 48). The unc ionali y o his me hod is qui e simila o he also named ge Ins alledApps() me hod o ShowResul . Fi s , i no elemen s we e analyzed, an A ayLis is c ea ed wi h only one elemen ha will be displayed as “E e y hing”, since no choosing any elemen o analyze implies analyzing all he use applica ions. I a leas one elemen was analyzed, he A ayLis is se wi h he applica ion name, package name and applica ion icon o he analyzed apps. Then, i a e ses all he elemen s and sub elemen s p esen in he esul , adding he applica ion name, package name and applica ion icon o he applica ions and he name o keywo ds and a ge elemen s o wo A ayLis s o LogIn e ac ions. The elemen s o he esul can ei he be applica ions (which implies ha hei sub elemen s a e he a ge elemen s hey ha e accessed) o keywo ds se by he use (which implies ha hei sub elemen s a e he applica ions ha ha e accessed ha keywo d). Ha ing he h ee A ayLis s, i s he elemen s analyzed (apps and keywo ds) a e displayed h ough a P e Resul sRecycle View, wi h he Elemen sAdap e . Then, a lis o all he applica ions ha we e unning du ing he analysis is shown in a Recycle View, wi h he LogElemen sAdap e o he elemen s (applica ions) and LogSubElemen sAdap e o he sub elemen s ( a ge elemen s) since he applica ions ha ha e accessed a leas one a ge elemen can be expanded. Nex , a lis o he keywo ds speci ied by he use and ha we e ound du ing he analysis is shown in a Recycle View, wi h he LogElemen sAdap e o he elemen s (keywo ds) and LogSubElemen sAdap e o he sub elemen s (applica ions) since he keywo ds ha ha e been accessed by one applica ion can be expanded. Finally, he se Pe missionsLis () me hod checks i he applica ions ha ha e accessed a a ge elemen had he pe missions necessa y o do so (see Figu e 49) (we decided i would be be e o check whe he he apps ha e a pe mission wi hin a speci ic pe mission g oup ins ead o compa ing all possible pe missions, because he pe missions needed a e well summa ized by hei pe mission g oup; he only excep ion is NFC, since i is a e y speci ic pe mission inside he pe mission g oup Ne wo k, which is ex emely b oad). This is achie ed by e i ying all he pe missions g an ed o hose applica ions (see Figu e 50) and con as ing i one o hose pe missions allows he app o access he speci ic a ge elemen . Fo his pu pose a lis wi h he a ge elemen s and hei co esponding necessa y pe missions () has been c ea ed o check i he applica ions ha e hem g an ed; he alues a e displayed in Table 5. The esul o checking he pe missions is shown in a Recycle View, wi h he LogElemen sAdap e o he elemen s (apps / keywo ds) and LogSubElemen sAdap e o he sub elemen s ( a ge elemen s / apps) since he applica ions ha ha e accessed a leas one a ge elemen can be expanded. A symbol a he igh o each elemen shows i he necessa y pe mission is g an ed (g een check) o no ( ed c oss). 73 sudo cu l -O h p://d3kbcqa49mib13.cloud on .ne /spa k-2.2.0-bin-hadoop2.7. gz sudo a x ./spa k-2.2.0-bin-hadoop2.7. gz sudo mkdi /us /local/spa k sudo cp - spa k-2.2.0-bin-hadoop2.7/* /us /local/spa k Add /us /local/spa k/bin o he PATH: expo PATH="$PATH:/us /local/spa k/bin" Include he in e nal hos name and IP o /e c/hos s. Fo example: 127.0.0.1 localhos 172.30.4.210 ip-172-30-4-210 Finally, download he wo necessa y sc ip s ha we ha e de eloped o he se e : -se e .c: Manages incoming connec ions, pa ses incoming logs, sends hem o he analyze .py sc ip and, when he use has s opped he analysis, i gi es he esul back o he use . -analyze .py: Spa k S eaming sc ip ha s o es, spli s and educes he logs. To execu e he sc ip s, open wo e minals. In he i s one execu e: gcc -Wall -g se e .c -o se e ./se e In he o he one execu e: spa k-submi analyze .py Nex , he unc ionali y o bo h sc ip s (se e .c and analyze .py) is going o be explained in de ail. Se e .c The se e .c sc ip pe o ms h ee unc ions desc ibed below: 1. Connec ion managemen Fi s , he sc ip wai s un il i can connec wi h analyze .py ia TCP. The socke es ablished o his connec ion is iden i ied by he add ess localhos and he po 9999. Once he connec ion wi h he sc ip has been es ablished, he se e begins o accep clien connec ions. We ha e p og ammed his sc ip o always be in execu ion, allowing all clien s o connec o he se e whene e hey need. Fo his eason, he se e has been de eloped as a concu en se e wi h an accep -and- o k pa e n. We can see his pa e n in Figu e 52, bu a e he me hod accep () e u ns, he se e o ks. 80 [85] Figu e 52: Elemen a y TCP Socke When he connec ion has been es ablished, he unc ion ecei eDa a() is called. 2. Log managemen The logs a e managed inside he me hod ecei eDa a().This me hod i s ecei es he keywo ds and applica ions ha a e used as il e s and he package name o all he use applica ions o he clien ’s de ice. Then, he p ocess loops un il he clien sends a speci ic signal ha ins uc s he se e ha he use has inished sending logs. Fo ease o use, we decided o lowe case all he logs ecei ed. Now, he se e checks i he logs con ain any o he package names om among all he use applica ions on he clien de ice, which we e ecei ed a he s a o his me hod. I one is ound, we conside ha log o be o in e es , since we only wan o moni o he beha iou o he use applica ions. Since we wan o show he use wha applica ions a e unning, we send he logs ela ed o he a ge elemen s o be moni o ed o he analyze .py sc ip , conca ena ing a he beginning o he log he IP o he de ice o he clien and he package name o he applica ion ound wi hin he log. 81 We decided ha he e a e se e al a ge elemen s ha equi e special a en ion in e ms o possible malicious beha io . These a ge elemen s a e: - loca ion - gps - came a - mic ophone - sound - eco de - elephony - blue oo h - wi i - ne wo k - messaging - mms - sms - sdca d - s o age - con ac s - n c - mail - accoun Now, h ee checks a e pe o med: -The keywo ds and applica ions il e s a e emp y: we check i he e a e any a ge elemen s in he log. I he e is one ound, we send i o analyze .py, conca ena ing he clien ’s de ice IP, he package name o he applica ion ound inside he log and ha a ge elemen . -The keywo ds il e is no emp y: we check i he e a e any keywo ds o he keywo ds il e in he log. I he e is one ound, we send i o analyze .py, conca ena ing he clien ’s de ice IP, he keywo d and he package name o he applica ion ound inside he log. -The applica ions il e is no emp y: we check i he applica ion is in he speci ied applica ions il e . I i is, we check i he e a e any a ge elemen s in he log. I he e is one ound, we send i o analyze .py, conca ena ing he clien ’s de ice IP, he package name o he applica ion ound inside he log and ha a ge elemen . 3. Ge ing he esul Since spa k s eaming s o es e e y hing in se e al pa i ions, we c ea ed he unc ion ge Resul s(), which opens e e y ile inside e e y subdi ec o y ound in he Resul di ec o y. Then, we send o he clien all he esul s ha con ain his IP and dele e hose esul s. Analyze .py 82 We ha e p og ammed his sc ip o always be in execu ion, allowing all clien s o connec o he se e whene e hey need. Figu e 53 shows he code o his sc ip . Figu e 53: analyse .py Fi s , he sc ip wai s un il i can connec wi h he se e .c ia TCP. The socke es ablished o his connec ion is iden i ied by he add ess localhos and he po 9999. Once he connec ion wi h he sc ip has been es ablished, he se e begins o accep clien connec ions. I is a Spa k S eaming sc ip , which implies ha i is cons an ly ge ing in o ma ion. Fi s , i sa es he logs ecei ed in he And oidLogs di ec o y. Then, i pa ses hose logs and educes hem wi h he ollowing o ma ((IP, package name, a ge elemen ), numbe o g ouped logs). Finally, i sa es hose educ ions in he Resul di ec o y. Figu e 54 shows a snippe o he sc ip in execu ion. Figu e 54: analyze .py unning 83 5.2.3 P oblems o e come -The IP and Po numbe s o he se e we e ini ially ha d-coded. The p oblem o his app oach is ha he IP o he EC2 ins ance changes each ime he ins ance is launched, which implies ha he applica ion had o be modi ied, compiled and ins alled whene e he cloud ins ance was launched. Fo his eason, we decided o implemen a Tex View whe e he use could w i e he IP and Po . We hen ealized ha e e y ime he applica ion was launched, he use had o inpu he IP and Po , which was a e y exhaus ing ask. Finally, we op ed o de elop he Se e Se ings class o s o ing he IP and Po s. Wi h his class, he use has o inpu hem only once. - A i s , all ypes o applica ions we e p in ed (use and sys em apps). This made i oo di icul o he use o choose a speci ic applica ion, so we decided o di ide hem in o wo di e en agmen s. We also decided o keep he sys em applica ions because i can be e y in e es ing when pe o ming a log analysis o analyze by Came a, Blue oo h, e c. - In And oid, an applica ion canno connec o a socke in he UI Th ead (main h ead o execu ion o he applica ion). This mean ha he connec ion o he se e had o be execu ed in ano he h ead. We decided o achie e his by using he AsyncTask class o i s simplici y in p og amming and he ac ha i s compu a ion uns in a backg ound h ead and i s esul is pos ed o he UI h ead. - When sending da a o he se e , we ealized ha ec () call did no always ead all he da a sen . Mo e speci ically, i he size o he da a was oo big, only a ac ion o ha da a was ecei ed. We a i s hough ha i could be due o he size o he bu e whe e he da a was being s o ed, bu we la e ealized ha we shouldn' expec o ecei e he da a in he same numbe o ead calls as he e we e w i e calls. Fo ha eason, we used e mina ion cha ac e s, o speci y he end o he da a being sen . We used ‘#’ o he use app package names, ‘ n’ o he logs and ‘Q’ o signaling he end o he communica ion. - A i s we pe o med he log il e ing in he applica ion. A p oblem a ose, which was ha some de ices could no handle such a la ge amoun o p ocessing. Fo ha eason, we decided o mo e he log il e ing o he se e . This also allowed us o s o e all he logs in he se e be o e doing any il e ing. - One o he bigges challenges we aced was how o ex ac use ul in o ma ion om he logs. The main p oblem wi h logs is ha hey sha e a sha ed o ma , bu he message i sel does no ha e a common o m, so each message is di e en . We i s hough ha i would be in e es ing o know which applica ions c ea ed a log en y wi h a le el abo e Wa ning, because ha could e eal applica ions wi h bugs in he code o applica ions ha access speci ic p o ec ed i ems. In he end, we decided ha he bes way was o check o speci ic pa e ns inside hose messages, and ha ’s how we came up wi h he idea o he a ge elemen s. 84 - We also aced some issues e u ning he esul om LogAnalyze Connec o LogAnalyze F agmen Applica ions, as i uns on a di e en h ead. We managed his by c ea ing a delega e unc ion in he UI h ead and passing i o LogAnalyze Connec . This unc ion ac s as an asynch onous esponse ha is called wi hin AsyncTask’s onPos Execu e() me hod, which is called when all p ocessing has al eady been done. 5.3 Pe mission Analysis Implemen a ion Ano he aspec ha mus be conside ed in he de elopmen o a malwa e analysis ool is he s udy o he ele ance o he pe missions eques ed by each applica ion. Pe missions play a e y impo an ole when analyzing malwa e as hey help suppo use p i acy by p o ec ing access o es ic ed da a and es ic ed ac ions om malicious pu poses [55]. This sec ion goes h ough he mo i a ions behind pe o ming his assessmen and explains all he de ails and s eps ollowed du ing he implemen a ion o he pe mission analysis. The pe missions de e mine wha is allowed o be done by an app. In o de o pe o m a mo e comp ehensi e and elabo a e malwa e s udy, he eam has concluded ha a pe mission analysis would make a solid suppo ing ea u e o ou And oid Malwa e Analyze App. To ca y ou an analysis o his s yle, he main hing is o emain neu al and always ely on objec i e ac s o achie e he mos accu a e esul possible in he pe mission assessmen . The ac o ul illing hese condi ions de e mines he igo and p ecision o he analysis. The basis and wha we a e ying o e alua e in his analysis a e he pe missions eques ed by he applica ion, which can be ound inside he And oidMani es .xml ile [24] unde he <uses-pe mission /> ag [88]. The ollowing sec ions desc ibe how hese pe missions ha e been handled and analyzed. 5.3.1 Da ase o pe missions Be o e s a ing wi h he analysis i is essen ial o c ea e a da ase ha collec s all he exis ing pe missions and in o ma ion abou hem. The aim o ha ing his lis is o know he ins alled apps pe missions and o classi y hem acco ding o he domain ha hey belong o and hei le el o dange . Fo his wo k, he eam conside s ha he bes implemen a ion o he pe mission da ase is o ha e a da abase o med by wo ables, one wi h he pe missions in o ma ion and ano he wi h he g oups in o ma ion (see Figu e 55). 85 Figu e 55: Pe missions Da ase Rela ional Model The able Pe missions (Table 6) con ains all he ele an in o ma ion ega ding And oid pe missions. As i conce ns he iden i ica ion o his able, he Pe missions ID ield is he cons an alue o he pe mission which is s o ed in he <uses-pe missions/> ag o he And oidManid es .xml. The aim o he sco e ield is o g ade he pe missions acco ding o how exposed he in o ma ion is as well as he scope o es ic ed ac ions you can pe o m when he sys em g an s you ha pe mission. The alues aken by he sco es ange om 0 o 6 and hey a e explained in he 5.3.2 sec ion. Table 6: F agmen o he able Pe missions The able Domains (Table 7) con ains all he ele an in o ma ion ega ding he di e en g oups which he pe missions belong o. This able jus s o es he iden i ica ion o he g oup and an alias and a desc ip ion o acili a e he unde s anding o he domain o he use and show him a a high le el wha unc ionali ies o he de ice a e used by he app. 86 Table 7: F agmen o he able Domains In o de o ge a pe missions da ase as comple e as possible, he eam elies on he pe missions API e e ence page [79] om he And oid o De elope s o icial si e. This page p o ides de elope s wi h a ull lis o pe missions ecognized by And oid. In Figu e 56 all he in o ma ion used in he pe missions da ase is highligh ed. 87 [79] Figu e 56: And oid De elope s, API Re e ence Page 1 - Pe mission ID, 2 - Pe mission Sco e, 3 - Pe mission Desc ip ion, 4 - Pe mission Alias, 5 - API le el (no used) As addi ional in o ma ion, he eam has also used he da ase o pe missions o m he sou ce and oidpe missions.com [80] which comple es he lis p o ided by And oid De elope s. Fu he mo e, his si e ela es he pe missions wi h hei domain and gi es an explana ion. In Figu e 57 all he in o ma ion used in he domains da ase is highligh ed. 88 [80] Figu e 57: and oidpe missions.com 1 - Domain ID, 2 - Domain Alias, 3 - Domain Desc ip ion, 4 - Pe mission ID, 5 - Pe mission Desc ip ion 5.3.2 Classi ica ion o pe missions E en hough And oid al eady classi ies i s pe missions acco ding o he scope o es ic ed da a and ac ions ha an app can access and pe o m when he sys em g an s ha pe mission [9], he eam decides o adop a mo e de ailed way o labelling he pe missions. In Table 8 i can be seen his adap a ion. The column Sco e is he alue s o ed in he da abase ha alloca es he pe mission scope and he column Pe mission Class is he pe mission classi ica ion acco ding o And oid. Table 8: Explana o y able o he di e en le els assigned o he pe missions 89 pe missions is 10 imes he a e age numbe o pe missions acco ding o he ca ego y. This way, o an applica ion o ca ego y Games (ideal = 5), depending on he numbe o pe missions, he Quan i a i e Sco e is highe o lowe : 5. So he lis o apps The nex and inal s ep o he pe mission analyze is o so in o a lis he ins alled apps acco ding o hei Final Sco e. This sco e is compu ed as he lowes alue be ween he Quan i a i e and Quali a i e sco es. 5.3.4 Resul s Once he analysis o pe missions is done, he esul s a e shown o he use . These esul s consis on: - The a e age o he Final Sco es (Figu e 61). Figu e 61: Pe mission Analysis Resul s iew 96 - Lis o he ins alled applica ions ha eques o bidden pe missions (Figu e 62 and Figu e 63). Figu e 62: Apps ha eques special pe missions [91] Figu e 63: Ap oide eques s “Ins all Packages, which is a special pe mission - Lis o ins alled applica ions ha eques dange ous pe missions (Figu e 64 and 65). Figu e 64: Apps ha eques dange ous pe missions 97 Figu e 65: Adobe Scan eques s se e al dange ous pe missions - Lis o ins alled applica ions ha eques dep eca ed pe missions (Figu e 66 and 67). Figu e 66: Apps ha eques dep eca ed pe missions Figu e 67: Ins ag am eques s wo dep eca ed pe missions: “Unins all_Sho cu ” (see Figu e 68) and “Use_Finge p in ” (see Figu e 69) 98 [98] Figu e 68: Unins all Sho cu is a dep eca ed pe mission [92] Figu e 69: Use Finge p in is a dep eca ed pe mission - Lis o ins alled applica ions ha eques unknown pe missions (Figu e 70 and 71). Figu e 70: Apps ha eques unknown pe missions Figu e 71: Ins ag am eques s an unknown pe mission: “Billing” 99 - Lis o ins alled applica ions so ed by Final Sco e (Figu e 72). Figu e 72: Apps so ed by Final Sco e 100 6. And oid Malwa e Analyze App This chap e shows he s uc u e o he applica ion de eloped as a esul o he wo k ca ied ou in his p ojec . This chap e p o ides a de ailed explana ion o each layou o he applica ion and he in e ac ion o he use wi h i . Th ough his chap e we will e e o he applica ion de eloped as AMA, (And oid Malwa e Analyze ). We ha e also designed a logo as shown in Figu e 73. Figu e 73: Applica ion Logo 6.1 F agmen Menu The AMA applica ion has been s uc u ed h ough he use o F agmen s. And oid F agmen s ep esen a eusable po ion o he app's UI ha de ines and manages i s own layou and a e a ached o an Ac i i y. As shown in Figu e 74 and 75, AMA consis s o 8 main agmen s, accessible by a agmen menu, which can be e ealed by clicking on he op le h ee ba icon. The main agmen s a e: -Home: En y poin o he applica ion. Shows some s a ing in o ma ion o he analysis pe o med. -Apps In o ma ion: Lis s all he applica ions ins alled on he de ice and when one o hem is selec ed displays in o ma ion abou i . -Signa u e Analyze : F agmen in cha ge o ca ying ou he signa u e analysis. -Pe mission Analyze : F agmen in cha ge o ca ying ou he pe mission analysis. -Log Analyze : F agmen in cha ge o ca ying ou he log analysis. -P e ious Resul s: Displays he esul s o p e iously pe o med analysis. -Se e Se ings: Handles he IPs used o es ablish he connec ion o he se e . -Abou Us: Shows some in o ma ion abou he p ojec and he h ee analyses. 101 Figu e 74: And oid p ojec o ganisa ion Figu e 75: F agmen menu 102 6.2 Home F agmen The Home F agmen , shown in Figu e 76, is he isual en y poin o he applica ion. I accesses he P e Resul s da abase o in o m he use abou he las analysis pe o med, displaying he analysis ype as well as he da e and ime. I no analysis is pe o med, he ex “None” is displayed. Below his in o ma ion, he applica ion shows o he use all he apps whose hash has no been analyzed ye . We ha e implemen ed his unc ionali y because we ha e hough i would be highly ecommended o encou age he use o analyze all he applica ions ins alled on his de ice. I all he apps had been analyzed, he ex “None” is displayed. Figu e 76: Home F agmen 103 6.3 Apps In o ma ion F agmen The Apps In o ma ion F agmen (Figu e 77) shows he use a lis o he ins alled applica ions. By clicking on a speci ic app, he use ge s he di e en in o ma ion ha he package p o ides, he applica ion sco es, he eques ed pe missions and a lis o he domains ha he app has access o. Figu e 77: App In o ma ion F agmen The applica ion sco es a e he quan i y and quali y esul s o he assessmen pe o med by he pe mission analyze . The o e all sco e o he applica ion is he lowes alue o bo h sco es, Adobe Scan would ha e an o e all sco e o 3.82 whe eas Among Us would ha e an 8.75 (Figu e 78). As seen p e iously his is based on he pe missions eques ed by he applica ions. O he ele an in o ma ion ha he package p o ides is he package name, he pa h and he ca ego iza ion o he app. Nex , he agmen shows all he domains o he app, ha is, all he pe mission g oups ha he applica ion eques s. They a e displayed in he o m o an expandable lis ha , when clicked, he pe missions ha belong o ha g oup appea . I also displays o he use a b ie desc ip ion o ha domain (see Figu e 79). 104 Figu e 78: App De ails F agmen (Sco es and Package In o ma ion) Figu e 79: Apps De ails F agmen (Domains ha Adobe Scan has access o) 105 Finally, a he bo om, he e is a lis ha con ains he ins alled applica ions so ed by inal sco e (Figu e 90). I he use decides o click in one o he apps, he applica ion is edi ec ed o he Pe mission Lis F agmen (Figu e 80). Figu e 88: Pe missions Analyze F agmen Figu e 89: Pe missions Analyze F agmen Figu e 90: Top and Bo om o he applica ions lis so ed by sco es 112 6.6 Log Analyze F agmen Fi s ly, he Log Analyze F agmen le s he use decide i he apps she/he wan s o analyze a e use applica ions (applica ions ins alled by him, such as Wha sapp, Ins ag am, And oidMalwa eAnalyze , e c) o unc ionali ies (p e-ins alled apps, such as Came a, Gmail, e c) as shown in Figu e 91. Figu e 91: Log Analyze F agmen Depending on he decision he use has made, he lis o applica ions ha a e displayed changes acco dingly, as shown in Figu e 92. I he connec ion o he se e has been co ec ly se and selec ed in he Se e Se ings F agmen (see sec ion 6.8), an ale message as he one in Figu e 92 is displayed, elling he use o selec he apps o moni o . 113 Figu e 92: Log Analyze F agmen - Applica ions Howe e , i no add ess has been co ec ly se up in he Se e Se ings F agmen , he ale shows an e o message elling he use o add a connec ion in he Se e Se ings sec ion (Figu e 93). Figu e 93: Log Analyze F agmen - No connec ions 114 As Figu e 94 displays, a e he p e ious s ep he use can selec he applica ions ha wan s o analyze. I none is selec ed, all o hem a e analyzed, which will consume mo e ime compa ed o selec ing some applica ions. The use can also inpu some keywo ds sepa a ed by commas, which a e used la e on du ing he analysis (see sec ion 5.2.2 o mo e in o ma ion). When he use wan s o s a he analysis, she/he needs o p ess he S a Analysis bu on. Du ing his ime, he connec ion is es ablished and he applica ion begins o send logs o he se e (Figu e 94). Figu e 94: Log Analyze F agmen - Analysis S a ed The use is able o see i some hing goes w ong h ough he ale messages ha appea on he sc een (Figu e 95). Since he de ice is now being analyzed, he use can in e ac wi h he applica ion she/he wan s o analyze, so ha AMA ge s i s logs. As i is a be a e sion, we ecommend accessing he And oidMalwa eAnalyze once in a while, because i can some imes ge s uck i i is kep in he backg ound o oo long. 115 Figu e 95: Log Analyze F agmen - Connec ion E o A e some ime, he use can p ess he S op Analysis bu on o s op he connec ion and e ie e he esul s. As shown in Figu e 96, he esul i s in oduces he analyzed elemen s. Then i shows he apps analyzed, which can be expanded o show he a ge elemen s hey accessed. Some o hem may no be expandable i no a ge elemen was ecognized. The numbe displayed indica es how many imes ha elemen appea ed in a log en y. A e ha , he keywo ds analyzed a e shown, which can also be expanded o display which applica ion accessed hem. Las ly, he use can see i he applica ions ha e he pe missions needed o access hose a ge elemen s. 116 Figu e 96: Log Analyze F agmen - Show Resul 117 6.7 P e ious Resul s F agmen This agmen displays all he log and signa u e analyses ha ha e been made p e iously. This is a simple way o keep ack o wha is happening on you mobile phone wi h he applica ions ins alled. In addi ion, analysis o e ime o his da a could indica e unwan ed ope a ion o ins alled apps; o example, an app accessing an i em oo much e en hough he use is no awa e o ha ing ha app in use (a leas in he o eg ound). Howe e , we ha e decided ha he pe mission analysis should no be sa ed, since i would ake up a lo o space due o he amoun o in o ma ion and because i is mo e in e es ing o calcula e i each ime. In sec ion 5.2.1 he con en s o he P e Resul s able a e shown (Table 4). As shown in Figu e 97, each elemen o he lis o analyses shows he ype o analysis and he day and ime. They a e o de ed by bo h he da e and ime, in descending o de . Figu e 97: P e ious Resul s F agmen I one o he esul s is selec ed, he speci ic da a is displayed. Figu e 98 displays he esul s o he signa u e analysis and log analysis ha ha e been selec ed. 118 Figu e 98: P e ious Resul Selec ed 6.8 Se e Se ings F agmen In his agmen communica ion wi h he se e is con igu ed. The use can se he IP and Po numbe s ha a e going o be used in he Log Analyze o connec ing o he se e . They a e s o ed using Sha edP e e ences. The use can selec each o he sa ed connec ions, which is he one used when connec ing o he se e . As shown in Figu e 99, he e a e wo bu ons: he Add bu on and he Dele e bu on. I he Add bu on is p essed, a popup appea s, asking he use o inpu he IP and Po numbe in he o ma IP:Po (Figu e 100). I he use p esses he Cancel bu on, he ope a ion is disca ded. 119 Figu e 99: Se e Se ings F agmen Figu e 100: Se e Se ings F agmen - Add IP:Po I he use p esses he Add bu on, he use ’s inpu is pa sed. In case some hing is w ong wi h he IP o Po numbe s (i.e. i i is no a numbe , one o he by es o he IP is in e io o 0 o supe io o 255, e c) he connec ion is no added and an ale message ells he use wha wen w ong, as shown in Figu e 101. I he Dele e bu on is p essed, he selec ed add ess is dele ed. Once i has been emo ed, an ale message no i ies he use o he dele ion (Figu e 102). 120 Figu e 101: Se e Se ings F agmen - W ong Inpu Ale Figu e 102: Se e Se ings F agmen - Dele e add ess 121 Figu e 108: Pe mission manage - TikTok -Figu e 109 displays he in o ma ion ob ained om he Apps In o ma ion F agmen o And oidMalwa eAnalyze . I can be seen ha he ca ego y in which his applica ion alls in o is Social & Communica ion, which is co ec o he app's unc ionali ies. The package name o he applica ion is com.zhiliaoapp.musically, which seems o be qui e suspicious since he cu en name is TikTok. Howe e , i migh be legi ima e because Musically is he o me name o he app. 128 Figu e 109: Apps In o ma ion - TikTok -Dicciona io de la Lengua Española (DLE) - DLE is he o icial applica ion ha he Real Academia Española (RAE) and he Asociación de Academias de la Lengua Española (ASALE) made a ailable o consul he Spanish Dic iona y. - I s main unc ionali y is he sea ch o he meaning o speci ic wo ds in he dic iona y, being able o apply di e en il e s. I also has some links ha allow he use o ob ain in o ma ion abou he app and he en i ies behind i s de elopmen . -Figu e 110 shows he pe missions equi ed by he app and whe he hey ha e been g an ed o denied. In his case, i has no equi ed any. 129 Figu e 110: Pe mission manage - DLE -Figu e 111 displays he in o ma ion ob ained om he Apps In o ma ion F agmen o And oidMalwa eAnalyze . I can be seen ha he ca ego y in which his applica ion alls in o is P oduc i i y, which is co ec o he app's unc ionali ies. Also, he package name o he applica ion is es. ae.dle, which seems o be legi ima e. 130 Figu e 111: Apps In o ma ion - DLE - Nasip Kisme degilmis - I is a supposed TV emo e con ol ha ac ually does no wo k as a emo e con ol, bu as a Clicke . -Figu e 112 displays he in o ma ion ob ained om he Apps In o ma ion F agmen o And oidMalwa eAnalyze . I can be seen ha he ca ego y in which his applica ion alls in o is Unde ined, which is al eady suspicious. Also, he package name o he applica ion is com.ndsonken ucki.kuma, which also seems suspicious. 131 Figu e 112: Apps In o ma ion - Nasip Kisme degilmis - Sma ca dSe ice - I is a malwa e ha ob ains he phone numbe , MAC add ess, de ice usage and eco ds SMS and oice con e sa ions. 7.2 Pe mission Analysis In his sec ion, he pe mission analyze will examine he apps men ioned in he p e ious sec ion. Based on he esul , he pe missions eques ed will be discussed o see i hei use is legi ima e o i i con adic s i s alleged unc ionali y. -Ins ag am -Figu e 113 shows he o e all sco e ob ained by analyzing he app wi h he pe mission analyze . As seen, i sco ed a 4.75 ou o 10, which is a low sco e. This is due, as we will la e see, o i s huge numbe o pe missions and he high a io o dange ous pe missions. Figu e 113: O e all Sco e - Ins ag am - Accessing he esul o he analysis, shown in Figu e 114, i can be seen ha he applica ion eques s se e al ypes o pe missions. Speci ically, his app eques s 15 dange ous pe missions, 2 dep eca ed, 14 no mal and 11 132 unknown, which gi es i a a ing o 5.8 ou o 10 in quali y. In e ms o quan i y, i eques s 42 pe missions in o al, hence i has a 4.75. O all o hem, he mos no able pe missions a e hose ela ed o he Came a, Accoun s, Con ac s, Loca ion, Mic ophone, Phone, S o age and Billing, which make sense wi hin all he unc ionali ies ha he app o e s. All in all, i can be app ecia ed ha his applica ion eques s a g ea numbe o pe missions, which could be dange ous in case he applica ion we e malicious. In his case, his applica ion is he legi ima e one, and hose pe missions a e needed o pe o m se e al o he unc ionali ies o he app. Figu e 114: Pe mission Analyze - Ins ag am -Wha sApp -Figu e 115 shows he o e all sco e ob ained by analyzing he app wi h he pe mission analyze . As seen, i sco ed a 2.5 ou o 10, which is a e y low sco e. This is due, as we will la e see, o i s la ge numbe o pe missions and he poo balance o pe mission ypes acco ding o he secu i y le els. Figu e 115: O e all Sco e - Wha sapp 133 - Accessing he esul o he analysis, shown in Figu e 116, i can be seen ha he applica ion eques s se e al ypes o pe missions. Speci ically, his app eques s 22 dange ous pe missions, 3 dep eca ed, 1 signa u e, 20 no mal and 14 unknown, which gi es i a a ing o 5.73 ou o 10 in quali y. In e ms o quan i y, i eques s 60 pe missions in o al, hence i has a 2.5. O all o hem, he mos no able pe missions a e hose ela ed o he Came a, Accoun s, Con ac s, Loca ion, Mic ophone, Phone, SMS, Read Call Log, NFC, Biome ic, S o age and Billing, which make sense wi hin all he unc ionali ies ha he app o e s. All in all, i can be app ecia ed ha his applica ion eques s a g ea numbe o pe missions, which could be dange ous in case he applica ion we e malicious. In his case, his applica ion is he legi ima e one, and hose pe missions a e needed o pe o m se e al o he unc ionali ies o he app. Figu e 116: Pe mission Analyze - Wha sApp -TikTok -Figu e 117 shows he o e all sco e ob ained by analyzing he app wi h he pe mission analyze . As seen, i sco ed a 2.25 ou o 10, which is a e y low sco e. This is due, as we will la e see, o i s huge numbe o pe missions and he high a io o unknown and dange ous pe missions. 134 Figu e 117: O e all Sco e - TikTok - Accessing he esul o he analysis, shown in Figu e 118, i can be seen ha he applica ion eques s se e al ypes o pe missions. Speci ically, his app eques s 9 dange ous pe missions, 2 dep eca ed, 12 no mal and 39 unknown, which gi es i a a ing o 5.08 ou o 10 in quali y. In e ms o quan i y, i eques s 62 pe missions in o al, hence i has a 2.25. O all o hem, he mos no able pe missions a e hose ela ed o he Came a, Audio, Con ac s, Mic ophone, Phone, S o age and Billing, which make sense wi hin all he unc ionali ies ha he app o e s. Wha is qui e a e is he g ea amoun o unknown pe missions ha appa en ly eques o ead/w i e he sys em se ings. Apa om ha , i can be app ecia ed ha his applica ion eques s a g ea numbe o pe missions, which could be dange ous in case he applica ion we e malicious. In his case, his applica ion is he legi ima e one, and hose pe missions a e needed o pe o m se e al o he unc ionali ies o he app. Figu e 118: Pe mission Analyze - TikTok -Dicciona io de la Lengua Española (DLE) -Figu e 119 shows he o e all sco e ob ained by analyzing he app wi h he pe mission analyze . As seen, i sco ed a 9.6 ou o 10, which is a e y high 135 sco e. This is due, as we will la e see, o i s impeccable quali y and quan i y o pe missions. Figu e 119: O e all Sco e - DLE - Accessing he esul o he analysis, shown in Figu e 120, i can be seen ha he applica ion only eques s no mal pe missions, which gi es i a a ing o 10 ou o 10 in quali y. In e ms o quan i y, i only eques s wo pe missions, hence i has a 9.6. Wi hin he unc ionali ies o he applica ion, i makes sense ha i uses he In e ne and Fo eg ound Se ice pe missions. All in all, i can be app ecia ed ha his applica ion is highly eliable, as i is a om wha could be conside ed a dange ous o suspicious applica ion. Figu e 120: Pe mission Analyze - DLE -Nasip Kisme degilmis -Figu e 121 shows he o e all sco e ob ained by analyzing he app wi h he pe mission analyze . As seen, i sco ed a 8.8 ou o 10, which is a e y high sco e. This is due, as we will la e see, o he good quali y and quan i y o pe missions. 136 Figu e 121: O e all Sco e - Nasip Kisme degilmis - Accessing he esul o he analysis, shown in Figu e 122, i can be seen ha he applica ion only eques s no mal and signa u e pe missions, which gi es i a a ing o 10 ou o 10 in quali y. In e ms o quan i y, i only eques s six pe missions, hence i has a 8.8. Wi hin he unc ionali ies o he applica ion, i should eques di e en pe missions, which is suspicious. All in all, i can be app ecia ed ha his applica ion does no eques dange ous pe missions, bu i is suspicious ha i does no eques he pe missions i should need o keep up wi h i s unc ionali y. Figu e 122: Pe mission Analyze - DLE -Sma ca dSe ice -Figu e 123 shows he o e all sco e ob ained by analyzing he app wi h he pe mission analyze . As seen, i sco ed a 4.13 ou o 10, which is a e y low sco e. This is due, as we will la e see, o he huge numbe o dange ous pe missions i eques s. Figu e 123: O e all Sco e - Sma ca dSe ice 137 Figu e 136: Signa u e Analyze - Sma ca dSe ice 7.4 Heu is ic Log Analysis In his sec ion, he log analyze will analyze he apps men ioned in sec ion 7.1. The esul will hen be discussed. -Ins ag am - While he log analyze was collec ing he logs, we accessed Ins ag am and in e ac ed a bi wi h he main page, looking a ecen pos s and some s o ies. We hen ied o ake a pho o, o which i asked o pe mission o access he came a which we decided no o g an . A e ha , we accessed Di ec s and ied o send an audio o a con ac , o which i asked o pe mission o access he mic ophone which we decided no o g an . Finally, we saw some o he pos s and Reels ha appea ed in he Explo e ab and accessed a speci ic accoun a e sea ching o i in he sea ch ba . - A e we we e done, we s opped he analysis and he esul s we e ob ained (Figu e 137). I can be seen ha du ing he execu ion o he analysis, ou applica ions we e unning: Ins ag am, And oidMalwa eAnalyze , Wha sApp and S icke s. Wha sApp p obably had some se ice unning in he backg ound, so i is no su p ising o see ha i gene a ed some logs. As o he S icke s app, pe haps i would be in e es ing o he use o analyze i sepa a ely since i should no be unning, bu ha is no he scope o his 144 analysis. Fou a ge elemen s ha e been de ec ed du ing he execu ion o Ins ag am: Came a, Messaging, Mic ophone and In e ne . Since he e a e a low numbe o logs ela ed o each a ge elemen , he use should no wo y, as hey a e p obably alse posi i es o , ha ing been asked o g an pe missions o he came a and mic ophone, i may ha e gene a ed some logs ela ed o hem. Fo his eason, inding ha he app has no access o he came a and mic ophone should no be ala ming. Figu e 137: Log Analyze - DLE - Reading he logs ha we e s o ed on he se e , we saw ha Came a was igge ed when he came a ac i i y was loaded: “06-15 17:07:55.469 1375 8410 windowmanage : adding window{a67672 u0 khcd.4zp. eel_compose _came a} o window{620175e u0 com.ins ag am.and oid/com.ins ag am.mainac i i y.mainac i i y}”. Rega ding he Mic ophone, he logs we e gene a ed when we we e p omp ed o g an he pe mission: “06-15 17:08:03.273 31338 31338 g an pe missionsac i i y: logged bu ons p esen ed and clicked pe missiong oupname=and oid.pe mission-g oup.mic ophone uid=10278 package=com.ins ag am.and oid p esen edbu ons=25 clickedbu on=8” 145 - F om his analysis we can conclude ha his applica ion pe o ms he p omised unc ionali ies and does no a emp o do any hing ou side o i s supposed beha iou . -Wha sApp - While he log analyze was collec ing he logs, we accessed a Wha sApp con e sa ion o ake a pho o and send i . We also ac i a ed he mic ophone and sen a documen s o ed in he de ice. Finally, we made a ideo call wi h ano he con ac . - A e we we e done, we s opped he analysis and he esul s we e ob ained (Figu e 138). I can be seen ha du ing he execu ion o he analysis, h ee applica ions we e unning: Wha sApp, And oidMalwa eAnalyze and Ins ag am. Ins ag am p obably had some se ice unning in he backg ound, so i is no su p ising o see ha i gene a ed some logs. Fi e a ge elemen s ha e been de ec ed du ing he execu ion o Ins ag am: Came a, Mic ophone, Messaging, SDca d and In e ne . As he numbe o logs ega ding he mic ophone and came a, hei numbe s a e high enough o be su e ha hose ha e been accessed. Figu e 138: Log Analyze - Wha sApp - Reading he logs ha we e s o ed on he se e , we saw ha he Came a logs we e gene a ed when he came a was opened and when he came a ac i i y 146 was called. As an example, we show his log: “06-15 19:33:12.549 14324 15103 i came a : open came a: 1, package name: com.wha sapp”. Rega ding he SDca d, he logs we e gene a ed when we sea ched he locally s o ed documen s o send one o hem: “06-15 19:33:12.444 14324 14324 w com.wha sapp: ype=1400 audi (0.0:10590): a c: g an ed { ge a } o pid=14324 name="/" de ="sdca d s" ino=11048 scon ex =u: :un us ed_app:s0:c147,c256,c512,c768 con ex =u:objec _ :sdca d s:s0 class= ilesys em”. - F om his analysis we can conclude ha his applica ion pe o ms he p omised unc ionali ies and does no a emp o do any hing ou side o i s supposed beha iou . -TikTok - While he log analyze was collec ing he logs, we accessed TikTok and in e ac ed a bi wi h he main page, looking a ecen pos s. We hen eco ded a ideo, o which i asked o pe mission o access he came a which we decided o g an . - A e we we e done, we s opped he analysis and he esul s we e ob ained (Figu e 139). I can be seen ha du ing he execu ion o he analysis, jus i e applica ions we e unning: TikTok, And oidMalwa eAnalyze , Zi y, Wible and Ins ag am. Rega ding Ins ag am, i p obably had some se ice unning in he backg ound, so i is no su p ising o see ha i gene a ed some logs. As o Zi y and Wible apps, pe haps i would be in e es ing o he use o analyze i sepa a ely since i should no be unning, bu ha is no he scope o his analysis. Fou a ge elemen s ha e been de ec ed du ing he execu ion o TikTok: Came a, Messaging, Loca ion and SDCa d. As i conce ns he Came a, i makes sense o ind logs because du ing he analysis i has been used. Rega ding he es o he logs, since he e a e a low numbe o logs ela ed o each a ge elemen , he use should no wo y as hey a e p obably alse posi i es. Fo his eason, inding ha he app has no access o he loca ion should no be ala ming. 147 Figu e 139: Log Analyze - TikTok - Reading he logs ha we e s o ed on he se e , we saw ha Came a was igge ed when he came a was opened: “06-15 19:14:15.738 31375 32062 i came amanage : open came a: 1, package name: com.zhiliaoapp.musically”. - As ega ds he SDca d, he logs we e: “06-15 19:14:57.411 31375 31375 w escoioboundex: ype=1400 audi (0.0:7330975): a c: g an ed { ead open } o pid=31375 pa h="/s o age/emula ed/0/and oid/da a/com.zhiliaoapp.mu sically/cache/pic u e/ esco_cache/ 2.ols100.1/35/eq_mss q_qyzox xqya kx5b5wjw.cn " de ="sdca d s" ino=254257 scon ex =u: :un us ed_app:s0:c99,c257,c512,c768 con ex =u:objec _ :sdca d s:s0 class= ile” - As o he Loca ion, he logs ound we e “06-15 19:14:12.993 2089 2467 i pg_ash : unp_gps:com.zhiliaoapp.musically uid:10355 esul : ue”. - Finally, ega ding o he SDCa d, he logs ound we e “06-15 19:14:12.991 2009 5099 d assis an se ice-1030200: handlemessage app swi ch 148 ompackage:com.huawei.and oid.launche , opackage:com.zhiliaoapp.musically”. - F om his analysis we can conclude ha his applica ion pe o ms he p omised unc ionali ies and does no a emp o do any hing ou side o i s supposed beha iou . -Dicciona io de la Lengua Española (DLE) - While he log analyze was collec ing he logs, we accessed he DLE applica ion and did a couple o sea ches o he meanings o di e en wo ds. We also accessed wo o he links in he applica ion, which edi ec o he de aul b owse o display in o ma ion om he RAE and he app. - A e we we e done, we s opped he analysis and he esul s we e ob ained (Figu e 140). I can be seen ha du ing he execu ion o he analysis, h ee applica ions we e unning: DLE, And oidMalwa eAnalyze and Fi e ox Focus. Fi e ox Focus appea s because he DLE applica ion links edi ec ed he use o he de aul b owse , which in he case o he de ice on which we es ed he analysis, was Fi e ox Focus. Two a ge elemen s ha e been de ec ed du ing he execu ion o he DLE applica ion: Messaging and S o age. Since he e a e a low numbe o logs ela ed o each a ge elemen , he use should no wo y, as hey a e p obably alse posi i es. Fo his eason, inding ha he app has no access o he s o age should no be ala ming. 149 Figu e 140: Log Analyze - DLE - Reading he logs ha we e s o ed on he se e , we ealized ha Messaging was igge ed because when swi ching om he DLE applica ion o Fi e ox Focus and back, se e al logs like “06-13 17:40:41.598 1975 4130 d assis an se ice-1030200: handlemessage app swi ch ompackage:com.huawei.and oid.launche , opackage:es. ae.dle” we e gene a ed, which is de ec ed as Messaging by a alse posi i e. S o age has been de ec ed because wo logs we e c ea ed in his o m “06-13 17:40:31.424 13742 13760 i hwapicachemange ex: apicache pa h=/s o age/emula ed/0 s a e=moun ed key=es. ae.dle#10122#”. - F om his analysis we can conclude ha his applica ion pe o ms he p omised unc ionali ies and does no a emp o do any hing ou side o i s supposed beha iou . -Nasip Kisme degilmis and Sma ca dSe ice - Due o hei malicious na u e, i is necessa y o pe o m an analysis o hese wo applica ions in a secu e en i onmen such as a i ual machine. When ying o pe o m he analysis, we ealized ha he applica ions c ashed each ime hey we e opened, p obably because hey we e p og ammed o wo k in 150 an olde And oid e sion. Fo his eason, we we e unable o pe o m he log analysis o hese applica ions. 151 8. Indi idual Wo k This chap e summa ises he con ibu ions o each pa icipan in his p ojec , lis ing e e y hing lea ned in he p ocess o ca ying i ou . The wo k has been ca ied ou join ly and ai ly, di iding he wo k in o each o he poin s ha make i up. These a e he c yp og aphic signa u es analysis, he analysis o logs and he analysis o pe missions. 8.1 Daniel Puen e A ibas My wo k has had mo e weigh in he analysis o pe missions. The beginning o my wo k consis ed o a global s udy o he me ada a con ained wi hin he PackageIn o objec . In his way, I lea ned abou i s uses and cha ac e is ics o unde s and how o ob ain he da a and say which ields we e he mos use ul and ele an o de elop ou analysis. Nex , I began he de elopmen o he Apps In o ma ion agmen and my i s app oach o he logical and isual de elopmen o he applica ion consis ed in showing he lis o all he ins alled applica ions, as well as he ele an in o ma ion o each one. Once his was done, I con inued wi h he de elopmen o he agmen ha shows he de ails and in o ma ion o each applica ion. Du ing his s age, I s a ed o wo k wi h he eques ed pe missions and I saw he need o c ea e a iew dedica ed o he pe missions in o de o classi y hem acco ding o he scope o es ic ed da a ha he apps can access, and he scope o es ic ed ac ions ha apps can pe o m when he sys em g an s hem pe mission. This way, be o e ge ing in o he pe missions analysis, I did a deep esea ch abou And oid pe missions and lea ned how o decla e pe missions, whe e o decla e hem, how o access hem and how o classi y hem acco ding o he domain which hey belong o and acco ding o he le el o access hey eques o he de ice. Subsequen ly, I buil a da ase composed o pe missions and pe mission g oups ou o a ious sou ces wi h he objec i e o using i la e in pe missions analysis. The in e es ing hing abou his da ase is ha i u ned ou o be e y comple e and e y use ul when i comes o co ec ly classi ying he pe missions. A e all he in o ma ion had been collec ed, he da ase in o ma ion was added as ables o he applica ion's SQLi e da abase. Once I ob ained he necessa y knowledge abou And oid pe missions and ha ing c ea ed a da ase ha s o es hem, I began o de elop he Pe mission Analyze agmen . To do his, I came up wi h wo algo i hms ha assign wo di e en a ings in o de o e alua e applica ions based on he pe missions hey eques . Ac ually, hese wo a ings p o ide wo e y in e es ing iews on applica ions; a quan i a i e iew and ano he deepe and quali a i e iew. A e I ha e inished designing he logical and unc ional pa o he pe missions analyze , I implemen ed i in he applica ion and I con inued de eloping he GUI o he analyze . 152 Rega ding his documen , I w o e he pe mission analyze sec ions o chap e s 4, 5, 6 and 9. We also di ided chap e 3, sec ion 1.4 and he abs ac equally. I also w o e my co esponding sec ion o chap e 8 and sec ions 1.1 and 1.3. Las ly, I was in cha ge o co ec ly ci ing he bibliog aphy. To conclude, my main con ibu ions in his p ojec ocus on he analysis o applica ions me ada a, he esea ch o And oid pe missions and in ela ion o he ex ac ion o in o ma ion om he apps and he analysis o pe missions, elabo a ing he unc ional and logic design as well as hei use in e ace design and i s co esponding implemen a ion. 8.2 José Ignacio Dague e Ga ido I c ea ed he local da abase wi h i s wo ables o malwa e signa u es and exis ing And oid pe missions, which is essen ial o pe o m he s a ic analysis. I was in cha ge o c ea ing an EC2 ins ance o AWS o be able o moni o he logs sen om an And oid de ice in o de o elimina e he cos o doing i locally. I was also in cha ge o es ablishing a connec ion be ween his ins ance and a TCP se e , which connec ed emo ely wi h he applica ion de eloped in And oid S udio. On he o he hand, I ha e pa icipa ed in he implemen a ion o he C yp og aphic Signa u e Analysis agmen s, being one o he h ee undamen al pilla s ha make up he whole applica ion. Rega ding his documen , I w o e he signa u e analyze sec ions o chap e s 4, 5, 6 and 9. We also di ided chap e 3, sec ion 1.4 and he abs ac equally. I also w o e my co esponding sec ion o chap e 8 and sec ion 1.2. Alongside Ramón, we w o e chap e 2. I ha e been able o unde s and no only he in e nal s uc u e o And oid applica ions bu also how Linux is composed and he secu i y se ices and s uc u e ha And oid p o ides. Despi e he lack o knowledge o he And oid S udio ool due o i s complex s uc u e and use, hanks o his p ojec I ha e been able o deal wi h his ool and clea ly unde s and i s usabili y, as well as disco e ing he bene i s and implemen a ions ha can be applied o he de elopmen o And oid applica ions. As And oid S udio is p og ammed in Ja a, I ha e been able o s eng hen my Ja a p og amming skills and become mo e luen . I ha e also lea ned how o make connec ions be ween AWS ins ances and mobile de ices h ough a TCP se e using socke s. I ha e ound Spa k S eaming eally exci ing, which is esponsible o p ocessing da a in eal ime, in ou case he logs o an And oid de ice. I is going o be help ul o implemen applica ions ha o e g ea e e iciency and pe o mance. I is undoub edly he case ha we li e in an age when people a e unawa e o he secu i y and s uc u e o hei mobile de ice and he isks in ol ed. Wha I ha e lea n is ha being knowledgeable abou how applica ion pe missions wo k gi es you a ce ain basic unde s anding o how o deal wi h malwa e. 153