scieee Science in your language
[en] (orig)

Malware Analysis on Android

Abstract

In the XXI century, the world has witnessed the creation, development and proliferation of mobile devices until the massive usage apparent nowadays. The portability, instantaneity and ease of use that these devices offer has encouraged the great majority of the population to have one of them at arm’s length. Thus, these devices have become a coveted target for malicious developers. This is the reason why the security of mobile devices has become a vital topic that must be addressed, since a suitable solution has yet to be found. From this necessity arises the present work, in which we elaborate the beginning of a response that serves as a starting point to promote further development that achieves the desired objective. With Android being the most representative Operating System among mobile devices, we are going to study the analysis of malware on Android and develop a static and dynamic antivirus based on signatures, permissions and logs, since they will prove useful when trying to detect malicious applications.

Read accessible full text

Malware Analysis on Android

Author: Puente Arribas, Daniel; Daguerre Garrido, José Ignacio; Costales de Ledesma, Ramón
Year: 2021
Source: https://docta.ucm.es/bitstreams/b1ca5dba-271f-4154-99ba-a77cd982a27b/download
Malwa e Analysis on And oid
Análisis de Malwa e en And oid
Final Deg ee P ojec in Compu e Science Deg ee
Facul y o Compu e Science & Enginee ing
Uni e sidad Complu ense de Mad id
Cou se 2020-2021
Au ho s
Daniel Puen e A ibas
José Ignacio Dague e Ga ido
Ramón Cos ales de Ledesma
Ad iso s: Ma cos Sánchez-Élez Ma ín and Inmaculada Pa dines Lence
2
Abs ac
In he XXI cen u y, he wo ld has wi nessed he c ea ion, de elopmen and p oli e a ion o
mobile de ices un il he massi e usage appa en nowadays. The po abili y, ins an anei y
and ease o use ha hese de ices o e has encou aged he g ea majo i y o he popula ion
o ha e one o hem a a m’s leng h. Thus, hese de ices ha e become a co e ed a ge o
malicious de elope s. This is he eason why he secu i y o mobile de ices has become a
i al opic ha mus be add essed, since a sui able solu ion has ye o be ound.
F om his necessi y a ises he p esen wo k, in which we elabo a e he beginning o a
esponse ha se es as a s a ing poin o p omo e u he de elopmen ha achie es he
desi ed objec i e.
Wi h And oid being he mos ep esen a i e Ope a ing Sys em among mobile de ices, we
a e going o s udy he analysis o malwa e on And oid and de elop a s a ic and dynamic
an i i us based on signa u es, pe missions and logs, since hey will p o e use ul when ying
o de ec malicious applica ions.
Keywo ds (10 max)
And oid, Malwa e, Vulne abili y, An i i us, Hash, Log, Pe mission, S a ic Analysis, Dynamic
Analysis, Cloud.
3
4
Resumen
En el siglo XXI se ha podido ap ecia la apa ición, desa ollo y p oli e ación de los
disposi i os mó iles has a llega a la masi icación que iene luga en la ac ualidad. La
po abilidad, ins an aneidad y acilidad de uso que o ecen ha hecho que la mayo ía de la
población enga uno siemp e al alcance de su mano. Es po ello que se han con e ido en
un obje i o codiciado po los desa ollado es de p og amas maliciosos. Así pues, la
segu idad de es os disposi i os se ha con e ido en un pun o cla e que debe se abo dado,
ya que has a la echa no se ha encon ado una solución ap opiada.
De es a necesidad su ge el p esen e abajo, en el que elabo amos el comienzo de una
espues a que si e como pun o de pa ida pa a omen a un pos e io desa ollo que
alcance el obje i o deseado.
Siendo And oid el sis ema ope a i o más ep esen a i o en e los disposi i os mó iles,
amos a hace un es udio del análisis del malwa e en And oid y a desa olla un an i i us
es á ico y dinámico basado en i mas, pe misos y logs, pues es as e idencias se án de g an
ayuda en la labo de de ección de aplicaciones maliciosas.
Palab as cla e (máx 10)
And oid, Malwa e, Vulne abilidad, An i i us, Hash, Log, Pe miso, Análisis es á ico, Análisis
dinámico, Cloud.
5

6
Acknowledgemen s
We would like o exp ess ou mos since e g a i ude o bo h ou p ojec ad iso s, Ma cos
Sánchez-Élez Ma ín and Inmaculada Pa dines Lence, o hei excellen guidance
h oughou he p oduc ion o his p ojec .
7
Index
1. In oduc ion 11
1.1 Mo i a ions 11
1.2 S a e o he A 12
1.3 Objec i es 14
1.4 Wo k planning 14
1.5 Documen O ganiza ion 21
2. And oid 22
2.1 And oid Ope a ing Sys em 22
2.1.1 In oduc ion 22
2.1.2 Applica ions 24
2.1.3 Componen s 27
2.1.4 In en s 28
2.2 And oid’s Vulne abili ies 28
2.2.1 Gene al Vulne abili ies 28
2.2.2 Roo ing 31
2.3 And oid’s Secu i y Sys ems 33
2.3.1 Linux Secu i y 33
2.3.2 Applica ion Sandbox 33
2.3.3 SELinux 34
2.3.4 Sys em’s Secu i y 34
2.3.5 Use ’s Secu i y 35
2.3.6 Apps Secu i y 35
2.4 And oid’s Malwa e 35
2.4.1 Malwa e ends 35
2.4.2 Malwa e ypes, aims and cha ac e is ics 38
2.4.3 T ansmission me hods, de ec ion and p e en ion 42
3. Wo kspace 46
3.1 Tools and samples 46
3.1.1 Tools 46
3.1.1 Samples 48
3.2 Decisions 49
4. Analysis Me hods 51
4.1 C yp og aphic Signa u e Analysis 51
4.2 Heu is ic Log Analysis 53
4.2.1 And oid logs 53
4.2.2 Log handling 55
4.3 Pe mission Analysis 56
5. Analysis Me hods Implemen a ion 59
5.1 C yp og aphic Signa u e Analysis Implemen a ion 59
8
5.2 Heu is ic Log Analysis Implemen a ion 65
5.2.1 Applica ion 65
5.2.2 Se e 79
5.2.3 P oblems o e come 84
5.3 Pe mission Analysis Implemen a ion 85
5.3.1 Da ase o pe missions 85
5.3.2 Classi ica ion o pe missions 89
5.3.3 Pe missions analysis and sco ing 90
5.3.4 Resul s 96
6. And oid Malwa e Analyze App 101
6.1 F agmen Menu 101
6.2 Home F agmen 103
6.3 Apps In o ma ion F agmen 104
6.4 Signa u e Analyze F agmen 109
6.5 Pe mission Analyze F agmen 111
6.6 Log Analyze F agmen 113
6.7 P e ious Resul s F agmen 118
6.8 Se e Se ings F agmen 119
6.9 Abou Us F agmen 122
7. Expe imen al esul s 123
7.1 Applica ions Analyzed 123
7.2 Pe mission Analysis 132
7.3 C yp og aphic Signa u e Analysis 138
7.4 Heu is ic Log Analysis 144
8. Indi idual Wo k 152
8.1 Daniel Puen e A ibas 152
8.2 José Ignacio Dague e Ga ido 153
8.3 Ramón Cos ales de Ledesma 154
9. Conclusions & Fu u e Wo k 155
9.1 O e iew 155
9.2 Applied Knowledge 155
9.3 Imp o emen s 156
9.3.1 Signa u e analyze 156
9.3.2 Log analyze 157
9.3.3 Pe mission analyze 157
9.4 Fu u e Wo k 157
9.4.1 Signa u e analyze 157
9.4.2 Log analyze 157
9.4.3 Pe mission analyze 158
Bibliog aphy 159
9
ii. Upg ade he app o lis he hashes o all he applica ions. Times amp: 21
Oc obe - 4 No embe . De elope : Daniel Puen e.
iii. Upg ade he app o lis he pe missions o all he applica ions. Times amp: 21
Oc obe - 4 No embe . De elope : Daniel Puen e.
i . De elop he app de ails ac i i y unc ionali y and iew. Times amp: 4 - 30
No embe . De elope : Daniel Puen e.
. Upg ade he app o access he logs. Times amp: 25 No embe - 16
Decembe . De elope s: Daniel Puen e and Ramón Cos ales.
i. C ea e a mockup local da abase o he app. Times amp: 25 No embe - 16
Decembe . De elope : José Ignacio Dague e.
ii. Upg ade he app o connec o he se e . Times amp: 20 Janua y - 8
Feb ua y. De elope s: All he eam.
iii. Connec he app o he se e . Times amp: 20 Janua y - 8 Feb ua y.
De elope s: All he eam.
ix. P in he esul ob ained om he se e . Times amp: 20 Janua y - 8 Feb ua y.
De elope s: All he eam.
x. Di ide he app unc ionali y in o agmen s. Times amp: 21 - 25 Feb ua y.
De elope : Ramón Cos ales.
xi. Fix na igabili y. Times amp: 18 Ap il. De elope : Ramón Cos ales.
Figu e 4: App planning
4. Se e (see Figu e 5):
i. C ea e he se e . Times amp: 20 Janua y - 8 Feb ua y. De elope s: All he
eam.
ii. C ea e a Spa k S eaming sc ip ha p ocesses he logs. Times amp: 20
Janua y - 8 Feb ua y. De elope s: All he eam.
iii. De elop he mul i connec ion. Times amp: 21 Ma ch - 2 Ap il. De elope :
Ramón Cos ales.
i . Upda e he Spa k S eaming sc ip . Times amp: 25 - 26 Ap il. De elope :
Ramón Cos ales.
. P ocess, pa se and il e he logs. Times amp: 26 Ap il - 4 May. De elope :
Ramón Cos ales.
16

i. Send back he esul s o he app. Times amp: 4 - 8 May. De elope : Ramón
Cos ales.
ii. Fix bugs. Times amp: 8 - 11 May. De elope : Ramón Cos ales.
Figu e 5: Se e planning
5. App [se e se ings agmen ] (see Figu e 6):
i. Lis all he connec ions. Times amp: 25 - 26 Feb ua y. De elope : Ramón
Cos ales.
ii. De elop he add unc ionali y. Times amp: 26 - 28 Feb ua y. De elope :
Ramón Cos ales.
iii. De elop he dele e unc ionali y. Times amp: 28 Feb ua y - 2 Ma ch.
De elope : Ramón Cos ales.
i . Sa e and load he connec ions. Times amp: 2 - 5 Ma ch. De elope : Ramón
Cos ales.
. Pa se he IP and po numbe s. Times amp: 19 - 20 Ap il. De elope : Ramón
Cos ales.
Figu e 6: Se e se ings planning
6. App [apps in o ma ion agmen ] (see Figu e 7):
i. Con e he apps lis ac i i y o a new agmen . Times amp: 25 - 28 Feb ua y.
De elope : Daniel Puen e.
ii. Con e he app de ails ac i i y o a new agmen . Times amp: 25 - 28
Feb ua y. De elope : Daniel Puen e.
17
iii. De elop he pe missions iew o ganized by ca ego ies. Times amp: 16 - 23
Ma ch. De elope : Daniel Puen e.
Figu e 7: Apps in o ma ion planning
7. App [pe missions analyze agmen ] (see Figu e 8):
i. Pe missions esea ch. Times amp: 1 - 7 Ma ch. De elope : Daniel Puen e.
ii. Elabo a e pe missions and domains da ase . Times amp: 8 - 15 Ma ch.
De elope : Daniel Puen e.
iii. Design and code pe missions g ading algo i hms. Times amp: 24 Ma ch - 1
Ap il. De elope : Daniel Puen e
i . De elop pe mission analyze logic and unc ionali y. Times amp: 5 - 18 Ap il.
De elope : Daniel Puen e.
. De elop pe missions analyze iew. Times amp: 19 - 30 Ap il. De elope :
Daniel Puen e.
i. Finish, es , debug and co ec e o s. Times amp: 1 - 12 May. De elope :
Daniel Puen e.
Figu e 8: Pe mission analyze planning
8. App [signa u e analyze agmen ] (see Figu e 9):
i. Upg ade and upload he i s da abase e sion. Times amp: 25 No embe -
20 Feb ua y. De elope : José Ignacio Dague e.
ii. De elopmen o he Signa u e Analyze agmen . Times amp: 20 - 27
Feb ua y. De elope : José Ignacio Dague e.
iii. C ea ion o an ac i i y wi h he “Check Hash” op ion. Times amp: 28 Feb ua y-
1 Ma ch. De elope : José Ignacio Dague e.
18
i . Connec ion and in e ac ion wi h he da abase h ough he applica ion.
Times amp: 1 - 2 Ma ch. De elope : José Ignacio Dague e.
. Display all he apps in a checkbox lis . Times amp: 3 - 17 Ma ch. De elope :
José Ignacio Dague e.
i. Implemen a sea ch box in Signa u e Analyze F agmen . Times amp: 1 - 19
Ap il. De elope : José Ignacio Dague e.
ii. Finish Signa u e Analysis agmen . Times amp: 22 Ap il - 1 May. De elope :
José Ignacio Dague e.
iii. Upg ade Signa u e Analysis agmen wi h an upda able da abase.
Times amp: 3 - 6 May. De elope : José Ignacio Dague e.
ix. Upload he inal e sion o he da abase. Times amp: 11 May - 12 May.
De elope : José Ignacio Dague e.
Figu e 9: Signa u e analyze planning
9. App [log analyze agmen ] (see Figu e 10):
i. Display all he apps in a checkbox lis . Times amp: 5 - 10 Ma ch. De elope :
Ramón Cos ales.
ii. P og am he connec ion o he se e . Times amp: 10 - 21 Ma ch. De elope :
Ramón Cos ales.
iii. Clean he code. Times amp: 2 - 8 Ap il. De elope : Ramón Cos ales.
i . De elop he agmen ha shows he log analysis esul . Times amp: 22 - 25
Ap il. De elope : Ramón Cos ales.
. Implemen expandable elemen s while showing he esul . Times amp: 11 - 12
May. De elope : Ramón Cos ales.
i. Check he pe missions o he apps when showing he esul . Times amp: 12 -
16 May. De elope : Ramón Cos ales.
19
Figu e 10: Log analyze planning
10. App [p e ious esul s agmen ] (see Figu e 11):
i. C ea e he P e Resul s da abase. Times amp: 8 - 12 Ap il. De elope : Ramón
Cos ales.
ii. Lis all he p e ious esul s. Times amp: 12 - 14 Ap il. De elope : Ramón
Cos ales.
iii. De elop a agmen ha shows he esul o an analysis. Times amp: 14 - 17
Ap il. De elope : Ramón Cos ales.
Figu e 11: P e ious esul s planning
11. App [abou us agmen ] (see Figu e 12):
i. C ea e he agmen . Times amp: 14 - 17 Ap il. De elope : Ramón Cos ales.
Figu e 12: Abou us planning
12. App [home agmen ] (see Figu e 13):
i. De elop he agmen . Times amp: 18 Ap il. De elope : Ramón Cos ales.
ii. Display elemen s whose hash is ye o be analyzed. Times amp: 20 - 22 Ap il.
De elope : Ramón Cos ales.
20
Figu e 13: Home planning
1.5 Documen O ganiza ion
This documen is s uc u ed in 9 chap e s. Chap e 1 in oduces he con ex o he p ojec .
Chap e 2 desc ibes he And oid ope a ing sys em and e iews i s ulne abili ies and he
secu i y sys ems de eloped o his OS; his chap e ends wi h a malwa e o e iew. Chap e
3names all he ools and samples used in he de elopmen o his p ojec and a gues he
decisions we ook in each s ep o i s p oduc ion. Chap e 4 explains he heo y behind he
analysis me hods we de eloped o he applica ion and Chap e 5 shows hei
implemen a ion. Chap e 6 co e s he use ’s in e ac ion wi h he applica ion and i s layou s.
Chap e 7 shows he esul s ob ained om analyzing se e al applica ions using he
applica ion de eloped h oughou his p ojec . Chap e 8 lis s all he indi idual con ibu ions
o each membe o he eam. Finally, Chap e 9 e iews he conclusions d awn om his
p ojec and b ains o ms u u e wo k and imp o emen s ha we didn’ ha e he ime o
accomplish.
21

2. And oid
This chap e in oduces he And oid Ope a ing Sys em [1], desc ibes he key cha ac e is ics
o applica ions and enume a es all ypes o componen s and in en s. Also, And oid’s
ulne abili ies a e ou lined, he oo ing me hod is explained and And oid’s di e en secu i y
measu es a e lis ed. Las ly, an analysis o And oid’s malwa e ypes, cha ac e is ics and
ends is pe o med.
2.1 And oid Ope a ing Sys em
2.1.1 In oduc ion
And oid is an Ope a ing Sys em ha consis s o a s ack o open sou ce so wa e based on
he Linux Ke nel and c ea ed speci ically o mobile de ices. I s a chi ec u e is con o med o
six laye s [21]:
-The Linux Ke nel: I is he base laye o he And oid Ope a ing Sys em, equi ed o
ca ying ou essen ial unc ionali ies such as p ocess managemen , memo y, ne wo k
s ack, con olle model and key secu i y ea u es. I is no he s anda d ke nel, bu a
speci ic o k ha includes addi ional elemen s, such as Binde o in e -p ocess
communica ion, speci ic d i e s, e c.
-Ha dwa e Abs ac ion Laye (HAL): allows he Ja a API F amewo k laye o make
use o s anda d in e aces ha pe mi he le e age o de ice ha dwa e capabili ies. I
consis s o a se o lib a y modules, one o each ha dwa e componen , such as he
came a.
-And oid Run ime (ART): Each app uns in i s own p ocess and wi h i s own
ins ance o he And oid Run ime. I is designed o be able o un mul iple i ual
machines on low memo y de ices h ough DEX iles. Be o e And oid 5.0, he Dal ik
i ual machine was used. The main di e ence be ween Dal ik and ART is ha he
la e compiles he by ecode iles du ing he ins alla ion o he applica ion, so i s key
objec i e is o compile he sou ces in DEX code. I has he Co e Lib a y (a pa icula
implemen a ion o he Ja a API), basic commands accessible h ough an ADB shell
[45], na i e sys em daemons and se ices, and he Ini p ocess.
-Na i e C/C++ Lib a ies: They allow applica ions o in e ac a a low le el wi h he
ke nel. All And oid lib a ies a e Open Sou ce. Examples: Bionic (C s anda d lib a y
on And oid), WebKi (web page ende ing and Ja aSc ip in e p e e ), SQLi e
(da abase), OpenSSL (SSL Socke s), e c.
-Ja a API F amewo k: E e y pa o he Ope a ing Sys em is accessible h ough an
API w i en in Ja a, which is used o de eloping applica ions wi h he objec i e o
eusing componen s. I is no exac ly a lib a y, since he e is an in e -p ocess
communica ion wi h Binde o limi ing accesses o secu i y easons. Examples:
no i ica ion manage , packe manage , window manage e c.
22
-Sys em Apps: These a e he p eins alled apps on he sys em ha o e unc ionali y
o bo h he use and o he apps ha may equi e hem.
These laye s a e de ailed in Figu e 14.
[21] Figu e 14: The And oid so wa e s ack
23
2.1.2 Applica ions
APK iles
And oid apps a e packaged and dis ibu ed in APK (Applica ion Package) iles ha a e
based on Ja a JAR packages. These packages ha e he ollowing s uc u e [22]:
-And oidMani es .xml – I is he applica ion's con igu a ion ile. Se e al a ibu es a e
de ined in i , such as he unique iden i ie o he applica ion, i ’s componen s
(«ac i i ies», « ecei e s», «con en p o ide s», e c.) o he pe missions i equi es.
-classes.dex – Con ains he applica ion’s compiled code.
- esou ces.a sc – I is he ile con aining p ecompiled esou ces.
-META-INF – I is he di ec o y ha s o es in o ma ion co esponding o he digi al
signa u e o he applica ion; i con ains he ollowing iles:
-MANIFEST.MF – I con ains a comple e lis o he APK iles along wi h hei
espec i e SHA-1 hash.
-CERT.SF – I con ains he SHA-1 hash o e e y 3 lines ha appea in he
MANIFEST.MF.
-CERT.RSA – s o es he signa u e o he CERT.SF ile and he ce i ica e used
o sign he iles.
- es – I is he di ec o y ha s o es he esou ces (images, ex iles, XML iles, e c.)
used by he applica ion.
-lib – I is he di ec o y ha con ains he compiled code o di e en a chi ec u es:
a meabi, a meabi- 7a, x86 o mips.
-asse s – I con ains non-p ocessed esou ces.
Figu e 15 displays he a o emen ioned con en s o APK iles.
[23] Figu e 15: APK ile s uc u e
24
As explained in chap e s 4 and 5, APK iles a e o g ea impo ance in ou p ojec , as we
make use o hem in all he analysis me hods we ca y ou :
- In he C yp og aphic Signa u e Analysis, we use he en i e APK ile o compu e he
hash signa u e o he ins alled applica ions.
- In he Pe mission Analysis, we ead he pe missions ha applica ions equi e om
hei espec i e And oidMani es .xml ile.
- In he Heu is ic Log Analysis, as in Pe mission Analysis, we ead he pe missions
ha he analyzed applica ions equi e.
Pe missions
O all he iles ha make up an APK ile, he mos ele an o ou p ojec is he
And oidMani es .xml [24], since i con ains he pe missions ha he applica ion equi es. This
in o ma ion is i al o wo o he h ee analysis me hods ha we pe o m: he pe mission
analysis and he log analysis.
And oid es ic s access o speci ic da a and ac ions in o de o p o ec use p i acy. In case
an applica ion needs o access any o hose es ic ed componen s, i has o eques he
speci ic pe mission needed o accessing hem. These pe missions a e ca ego ized in wo
di e en ways: ca ego ized by ype and by g oup.
The e a e se e al ypes o pe missions, di ided by he scope o es ic ed da a o ac ions
ha he applica ion may pe o m once he pe mission is g an ed [25]:
-Ins all- ime pe missions: They gi e he app limi ed access o es ic ed da a, and
hey allow i o pe o m es ic ed ac ions ha minimally a ec he sys em and o he
apps. The sys em au oma ically g an s he pe missions when he use ins alls he
app.
-Run ime pe missions: Also known as dange ous pe missions, hey gi e he app
addi ional access o es ic ed da a, and hey allow i o pe o m es ic ed ac ions ha
mo e subs an ially a ec he sys em and o he apps. The e o e, hey need o be
eques ed be o e hey can access he es ic ed da a o pe o m es ic ed ac ions.
-Signa u e pe missions: I he app decla es a signa u e pe mission ha ano he app
has de ined, and i he wo apps a e signed by he same ce i ica e, hen he sys em
g an s he pe mission o he i s app a ins all ime.
-No mal pe missions: They allow access o da a and ac ions ha ex end beyond he
app's Sandbox. Howe e , he da a and ac ions p esen e y li le isk o he use 's
p i acy, and he ope a ion o o he apps.
-Special pe missions: They co espond o pa icula app ope a ions. Only he
pla o m and OEMs (O iginal Equipmen Manu ac u e s) can de ine special
pe missions.
The pe missions a e di ided in o g oups by hei unc ionali y [26]. Fo example,
and oid.pe mission-g oup.LOCATION g oups he pe missions ha g an access o he
de ice loca ion, like he pe mission and oid.pe mission.ACCESS_FINE_LOCATION o he
pe mission and oid.pe mission.ACCESS_COARSE_LOCATION.
25
Fo de ices wi hou an unlockable boo loade , oo access can be achie ed by exploi ing a
ke nel o sys em ulne abili y. A p i ilege escala ion exploi , ypically packaged in one-click
oo ing applica ions, allows an applica ion o un a oo shell o ins all he "su" bina y o
modi y sys em se ings.
Ano he way is ia a p i ileged ADB (And oid Debug B idge) [45]. The sys em p ope y
" o.secu e" o "de aul .p op" de e mines he UID (Use ID) o he p ocess unde which an
ADB shell is execu ed. When he alue is 1, he daemon p ocess "adbd", which ini ially uns
as oo , changes i s UID be o e c ea ing he ADB shell wi hou oo p i ileges. O he wise,
use s can ha e a shell ha can un any p og am as oo .
Roo Vulne abili y
And oid's pe mission sys em o ces access con ols on secu i y- ela ed esou ces such as
senso s, sensi i e da a and impo an communica ion modules. Bu i he phone is oo ed,
his pe mission sys em can be a oided. On a oo ed phone, p ocesses can un wi h oo
p i ilege and i is possible o access any esou ce wi hou pe mission. Many people oo he
de ice o unins all s ock apps, lash hi d-pa y ROMs, use applica ions ha equi e oo
pe mission, back up he phone...
The p oblem is ha when dealing wi h a oo ed mobile phone, malwa e can access sensi i e
da abases (SMS, Con ac s...) and ha dwa e in e aces (came a, mic ophone...) wi hou
ha ing he co esponding pe missions be o ehand. In hese cases, he pe mission sys em is
no ele an , because i is a oided.
Whe eas he e a e applica ions ha o e one-click- oo (by clicking a bu on hey a e able o
oo he phone), equally he e exis applica ions ha o e one-click-un oo (i emo es he
"su" bina y). Remo ing oo om he phone akes away oo pe missions om po en ial
malwa e, so he pe mission sys em becomes ele an again, denying malwa e access o
sys em esou ces. Howe e , du ing he ime window in which he de ice is oo ed, i he
malwa e has modi ied he packages.xml ile (con aining a lis o pe missions and packages)
o apks wi h oo p i ileges, i may ha e escala ed i s pe missions, causing pe mission
escala ion a e oo emo al o be a backdoo o he malwa e o abuse esou ces [46].
They could also dele e he ce i ica e es ic ion o sha ing UIDs wi h ano he app; i his is
done wi h a p i ileged app, hen p i ileged pe missions o ha app o access o i s da a can
be ob ained. Mo eo e , he code could also ha e been modi ied o emo e he pe mission
access con ol.
The e o e, his ype o malwa e o e s a highe le el o impac , as hey a e able o pe sis
a e oo emo al, as well as ha ing a e y high de ec ion e asion a e.
32

2.3 And oid’s Secu i y Sys ems
2.3.1 Linux Secu i y
A he ope a ing sys em le el, he And oid pla o m uses Linux ke nel secu i y such as
secu e in e -p ocess communica ion (IPC) o enable secu e communica ions be ween
applica ions unning in di e en p ocesses [47]. This ensu es ha e en na i e code is
es ic ed by he applica ion Sandbox. Thus, he sys em is designed o p e en a malicious
applica ion om damaging o he apps, he And oid sys em, o he de ice.
The Linux ke nel p o ides And oid wi h se e al key secu e ea u es, including [47]:
- A use -based pe missions model.
- P ocess isola ion.
- Ex ensible mechanism o secu e IPC.
- The capabili y o emo e unnecessa y and po en ially insecu e pa s o he ke nel.
A undamen al goal o ke nel secu i y is o isola e he esou ces o one use om hose o
ano he use , hus [47]:
- P e en s one use om eading ano he use 's iles.
- Ensu es ha one use does no exhaus he memo y o ano he .
- Ensu es ha one use does no d ain ano he use 's CPU esou ces.
- Ensu es ha one use does no d ain ano he use 's de ices ( elephony, GPS,
Blue oo h...).
2.3.2 Applica ion Sandbox
The secu i y o And oid applica ions is en o ced by he applica ion Sandbox [84], which
isola es applica ions om each o he and p o ec s apps and he sys em om malicious apps.
I achie es his by assigning a unique use ID o each app and unning i in i s own p ocess.
The ke nel en o ces secu i y be ween apps and he sys em a he p ocess le el h ough
s anda d Linux acili ies such as use and g oup IDs ha a e assigned o di e en apps. By
de aul , apps canno in e ac wi h each o he and ha e limi ed access o he OS. As he
applica ion Sandbox is loca ed in he ke nel, his secu i y model ex ends o bo h sys em
applica ions and na i e code. All so wa e abo e he ke nel, such as ope a ing sys em
lib a ies, applica ion amewo ks, applica ion un ime (ART), and all applica ions, a e unning
inside an applica ion Sandbox.
Gene ally, o e ade he applica ion Sandbox on a p ope ly con igu ed de ice, ke nel secu i y
mus be comp omised. Ne e heless, he indi idual p o ec ions ha o ce he applica ion
Sandbox a e no in ulne able, so p o ec ion in o dep h is impo an o p e en a single
ulne abili y om comp omising he ope a ing sys em o o he apps. Wi h each And oid
e sion, p o ec ions ha e been added o p o ec he applica ion Sandbox, such as in 9.0,
33
which o ced all non-p i ileged apps o un in indi idual SELinux Sandboxes, p o iding
manda o y pe -app access con ol, o imp o e he sepa a ion o apps, p e en o e w i ing o
secu e de aul s, and p e en apps om making hei da a accessible o e e yone.
I is no a good idea o make da a accessible o e e yone, as his can be an in o ma ion leak
and a popula a ge o malwa e. F om And oid e sion 9 onwa ds his is no allowed.
The e o e, o ile sha ing i is used by con en p o ide s o MediaS o e class o hose media
iles ha should be accessible o e e yone.
2.3.3 SELinux
And oid uses Secu i y-Enhanced Linux (ke nel secu i y module) [48] o apply access con ol
policies and se manda o y access con ols on p ocesses. I applies Manda o y Access
Con ol (MAC) ins ead o Disc e e Access Con ol (DAC). This implies ha ins ead o he
owne o a esou ce con olling he access pe missions a ached o ha esou ce, any
access is que ied o a cen al au ho i y. This ensu es ha he so wa e uns only a he
lowes p i ilege le el, mi iga ing he e ec s o po en ial a acks.
2.3.4 Sys em’s Secu i y
The sys em pa i ion con ains he And oid ke nel, as well as sys em lib a ies, he applica ion
un ime (ART), he applica ion amewo k and applica ions [47]. The pa i ion is ead-only.
When he de ice is boo ed in sa e mode, hi d-pa y applica ions can be launched manually
by he de ice owne , bu a e no launched by de aul .
File sys em pe missions ensu e ha a use canno al e o ead ano he use 's iles, unless
he de elope explici ly sha es iles wi h o he applica ions [47]. In And oid, each applica ion
uns as i s own use .
Ve i ied boo ensu es he in eg i y o he de ice's so wa e, s a ing om a ha dwa e oo o
us ill he sys em pa i ion [87]. Du ing boo , each s age c yp og aphically e i ies he
in eg i y and au hen ici y o he nex s age be o e execu ing i . This makes p i ilege
escala ion non-pe sis en , because i de ec s ile sys em modi ica ions and comp omised
de ices a e no allowed o boo .
And oid p o ides a se o c yp og aphic APIs o use by applica ions [47]. This includes
implemen a ions o s anda d and commonly used c yp og aphic p imi i es, such as AES,
RSA, DSA and SHA. Addi ionally, hese APIs can be used by high-le el p o ocols, such as
SSH and HTTPS. I also has a KeyChain class ha allows applica ions o use sys em
c eden ial s o age o p i a e keys and ce i ica e chains.
By de aul , only he ke nel and a small subse o co e applica ions can be un wi h oo
pe missions. And oid does no p e en a use o applica ion wi h oo pe missions om
modi ying he ope a ing sys em, ke nel, o any o he applica ion. In gene al, oo has ull
access o all applica ions and hei da a. Use s who change pe missions on an And oid
de ice o allow oo access o applica ions inc ease hei exposu e o malicious applica ions
and po en ial applica ion c ashes.
34
2.3.5 Use ’s Secu i y
And oid suppo s ull ile sys em enc yp ion, so all use da a can be enc yp ed in he ke nel
[47]. I also allows ull disk enc yp ion, so ha a single key (p o ec ed by he de ice
passwo d) p o ec s he en i e use da a pa i ion; a boo ime he use mus p o ide
c eden ials be o e any pa o he disk becomes accessible. I also suppo s ile-based
enc yp ion, allowing di e en iles o be enc yp ed wi h di e en keys ha can be unlocked
independen ly.
Enc yp ing da a wi h a key s o ed in he de ice does no p o ec applica ion da a om use s
wi h oo pe missions. Applica ions can add a laye o da a p o ec ion by using enc yp ion
wi h a key s o ed ou side he de ice, such as on a se e , o a use passwo d. This p o ides
empo a y p o ec ion while he key is no p esen , bu a some poin he key mus be gi en o
he applica ion, making i accessible o use s wi h oo pe missions. A mo e obus app oach
o p o ec da a om possible access by use s wi h oo pe missions is he use o ha dwa e
solu ions. Manu ac u e s can implemen ha dwa e solu ions ha limi access o speci ic
con en .
And oid also allows o p e-access e i ica ion o he de ice h ough a passwo d gi en by he
owne . No only does i p e en access, bu i also p o ec s he c yp og aphic keys o ile
sys em enc yp ion.
In he case he de ice is los o s olen, he enc yp ion o he en i e ile sys em uses he
de ice's passwo d o p o ec he enc yp ion key, so ha modi ying he boo loade o
ope a ing sys em is no enough o gain access o he use 's da a.
2.3.6 Apps Secu i y
Applica ions can only access a limi ed se o esou ces managed by he OS [49].
Ne e heless, applica ions usually need access o a di e en se o esou ces ou side he
Sandbox such as he came a o Blue oo h. This equi es he use o p o ec ed APIs, which
a e in ended o be used by applica ions h ough pe missions. Since pe missions a e
managed by he OS, in o de o use hese APIs, applica ions mus de ine he pe missions in
he mani es and hen he de ice owne ei he accep s o ejec s hem du ing ins alla ion. In
case an applica ion ies o access a p o ec ed API no decla ed in he mani es , a secu i y
excep ion is aised and e u ned o he applica ion, denying i s access o he eques ed
esou ce.
2.4 And oid’s Malwa e
2.4.1 Malwa e ends
Malwa e de elopmen o mobile de ices has inc eased conside ably in he las ew yea s. In
2019, he e we e al eady mo e han 27 million malwa e p og ams in he And oid mobile
35
sec o [50]. A g ow h o 690,000 new malwa e p og ams was obse ed, esul ing in an
inc easing numbe o bo ne s a ge ing And oid sys ems [50]. Mos in ec ions a e due o
malicious apps ob ained om hi d pa ies, which has inc eased by a ound 85% pe yea
since 2011 [50]. Figu e 23 below shows he g ow h o malwa e samples on And oid om
2012 o 2018.
[40] Figu e 23: New And oid malwa e samples pe yea
In 2020, h ea s on And oid de ices a e di ided in o ou di e en ca ego ies [51]: Malwa e,
which accoun s o app oxima ely h ee qua e s o he o al; Adwa e, which ep esen s
15.4% o he o al; Riskwa e and PUA (Po en ially Unwan ed Applica ions) being almos
negligible a 6% and 4% espec i ely. As shown in Figu e 24, in 2020 malicious ac i i y
inc eased by 30% in Ma ch, which coincided wi h COVID-19 c isis [52]. As wo kplace wo k
has been o ced o mo e o home, much o he wo kload has shi ed o home, which is o en
less p o ec ed han a company's ne wo k.
36
[53] Figu e 24: The And oid h ea ac i i y in Q2 compa ed o Q1 2020
Figu e 25 illus a es he op mobile h ea s de ec ed by Kaspe sky in bo h 2019 and 2020. I
shows ha he use o Adwa e has doubled in a single yea .
[54] Figu e 25: Dis ibu ion o new mobile h ea s by ype in 2019 and 2020, Kaspe sky
37

Ou o he op en malwa e amilies de ec ed, i e o hem make in usi e use o ads, wi h
And oid/Hiddad opping he lis [53]. I is wo h men ioning ha T ojan d oppe s ep esen a
hi d o he op en amilies de ec ed in he second qua e o 2020, as shown in Figu e 26.
[53] Figu e 26: Top en de ec ed amilies in Q2 2020
2.4.2 Malwa e ypes, aims and cha ac e is ics
Common mechanisms:
-Pe sis ence: Usually, malwa e samples seek o pe sis on he de ice. One o he
mos common mechanisms o achie e pe sis ence is h ough componen hiding. One
possible echnique o achie e his objec i e is o disable he ac i i y componen
egis e ed in he Launche by he applica ion a he momen o i s ins alla ion, as a
esul o which he applica ion's icon disappea s. To u he enable code execu ion,
malwa e should implemen a ecei e componen o log sys em e en s and a se ice
componen o backg ound execu ion. This allows he malwa e o un in backg ound
a sys em e en s, such as s a -up o WiFi ac i a ion, e en hough he icon is no
isible. Examples o his can be seen in samples o spywa e, RATs, clicke s o
ansomwa e, as hey can deploy hei ull unc ionali y om backg ound execu ion.
-Denial o se ice: Malwa e seeks o block access o sc eens om which he
applica ion could be emo ed. I does his by using se ices ha , while unning in he
backg ound, de ec when he applica ion is ying o be unins alled and o e lay a
componen ha p e en s i om doing so. To achie e his, hey usually implemen he
GET_TASKS pe mission o ge he applica ion ha is unning in he o eg ound, as
well as he BIND_DEVICE_ADMIN pe mission o egis e as De ice Adminis a o .
This sec ion lis s he main ca ego ies o malwa e ha can be ound on he And oid ope a ing
sys em. Each ca ego y desc ibes i s objec i e and s a egies o iden i ica ion by he analys
[55].
38
Adwa e
This is he mos common ype o malwa e on And oid de ices. When aced wi h applica ions
wi h ads, i is con o e sial o classi y hem as malwa e, as i is di icul o es ablish a limi a
which he use o ads s a s o be abusi e o simply ano he mone iza ion sys em.
The main ea u e o his malwa e is he inclusion o API keys in he And oidMani es .xml ile
o ob ain he unc ionali y o a ious ads se ices, such as AdMob, Baidu, Adwhi l o Ad-X.
These API keys con ain he iden i ie s ha he ads se ices use o iden i y which app is
displaying he ads, hus enabling mone a y ewa d.
Ano he cha ac e is ic used by mo e agg essi e samples comes om he inclusion o
pe missions such as:
-SYSTEM_ALERT_WINDOW: I o e lays he cu en window wi h ano he one o you
choice.
-GET_TASKS: Allows you o see wha o he applica ion is unning. I adwa e de ec s
ha a b owse is being used, i can edi ec he use o an ad page.
Phishing
The aim o his ype o malwa e is o s eal sensi i e use in o ma ion (usually use name and
passwo d) by decep ion, p e ending o be a legi ima e applica ion ha hides malwa e.
De ec ing phishing is ela i ely easy i i ies o pass i sel o as a legi ima e applica ion. In
such a case, by compa ing he digi al ce i ica es, we can check whe he hey a e
applica ions p og ammed by he same de elope o whe he we a e dealing wi h a case o
impe sona ion, causing i o all in o he ca ego y o phishing.
Malwa e o his ype equi es pe missions ha allow i o send s olen in o ma ion, such as
access o he In e ne , SMS, e c. This allows us o iden i y his malwa e, especially i i
should no equi e hese pe missions gi en he unc ionali y i p omises (a social ne wo king
applica ion should no need access o SMS). Also, as hey a e copies o o he applica ions, i
is common o he e o be disc epancies wi h he o iginal o unc ional e o s.
Spywa e
This ca ego y co e s all ypes o applica ions which seek o s eal in o ma ion om a de ice,
such as phone numbe , email accoun , con ac s, loca ion, ins alled applica ions, calls,
messages, mic ophone access, de ice ID, ope a ing sys em, MAC add ess, e c.
In i s code, i he e is no ob usca ion, he e p obably a e s ings ela ed o in o ma ion hey
a e looking o , such as email, loca ion, model, phone, SMS, e c. Du ing execu ion, da a is
equen ly ei he sen o a se e , pos ed on a o um o sen by SMS, which in ol es ne wo k
a ic. Da a may be sen plain o enc yp ed, making i di icul o iden i y.
39
The pe missions equi ed by he spywa e depend on he in o ma ion ha needs o be
ex ac ed, o example:
-ACCESS_WIFI_STATE: I sea ches o ne wo k in o ma ion om he de ice.
-READ_CONTACTS: Access con ac s.
-ACCESS_COARSE_LOCATION oACCESS_FINE_LOCATION: Pa a accede a la
localización.
-READ_SMS o el RECEIVE_SMS: Access messages.
-PROCESS_OUTGOING_CALLS y el READ_PHONE_STATE: Phone calls.
RAT
RAT s ands o Remo e Access Tool o , i i is hidden inside ano he applica ion, Remo e
Access T ojan. The aim o his ype o malwa e is o gain emo e con ol o a de ice. These
ac ions can be: accessing web pages, ins alling applica ions, sending SMS, sending use
in o ma ion, changing de ice con igu a ions, e c.
As con ol is emo e, he applica ion mus communica e wi h a C&C (Command & Con ol)
se e . Commonly, hese se e s gi e he malwa e de elope he oppo uni y o dis ibu e
commands o speci ic de ices. I is o his eason ha he ul ima e goal o his ype o
malwa e is he c ea ion o bo ne s ha allow hem o launch dis ibu ed a acks o black ha
SEO (Sea ch Engine Op imiza ion) echniques ( hey a e used o imp o e he posi ioning o a
websi e in he sea ch engine esul s lis ). This malwa e no mally equi es as many
pe missions as possible, allowing o a wide ange o ac ions.
Keylogge s
This ype o malwa e collec s keys okes ha ha e been p essed by he use and sends
hem o an ex e nal se e . Some con o e sy also a ises wi h applica ions wi h his
unc ionali y, as he e a e keyboa d applica ions ha collec keys okes and s a is ics o
imp o e hei se ices, aising a dilemma as o whe he hey should be conside ed malwa e
o no .
Such applica ions usually ha e he ollowing pe missions:
-BIND_INPUT_METHOD: Mus be equi ed by an Inpu Me hodSe ice, o ensu e ha
only he sys em can bind o i .
-ACCESS_NETWORK_STATE: Allows applica ions o access in o ma ion abou
ne wo ks.
-INTERNET
40
Tapjacking
Malwa e o his ype is designed o ick he use in o p essing on he sc een, pe o ming a
di e en unc ion han he one he use hinks she/he is pe o ming. The wo mos ypical
implemen a ion echniques a e based on Toas and WindowManage .
Toas is a sys em o displaying ex messages in pop-up o ma . Clicks on i a e
non- unc ional, so hey a ec wha e e is unde nea h he pop-up. These messages can be
designed using XML, so hey can be made o look simila o a dialogue wi h bu ons. This
would allow he malwa e de elope o design a pop-up which guides he use 's aps o whe e
she/he wan s hem o go. I is common o such applica ions o equi e he GET_TASKS
pe mission o know which applica ion is open and hus which applica ion he use 's aps on
he Toas a e wo king on.
Clicke s
The pu pose o his kind o malwa e is o load web pages and click on links o imp o e he
anking o ha page (black ha SEO), in ads wi h he aim o c ea ing a la ge numbe o hi s
ha gene a e a inancial bene i o he de elope , o edi ec a ic im o download o he
malwa e.
I is common o many o he click-accoun ing sys ems on websi es o be Ja aSc ip code.
Clicke s mus he e o e ha e he abili y o load HTML code and in e p e Ja aSc ip . Some
decla e he SYSTEM_ALERT_WINDOW pe mission.
Ransomwa e
I s aim is o inhibi access o de ice esou ces, ypically o demand a inancial paymen . On
compu e s i is usually implemen ed by enc yp ing iles; None heless, on And oid his
me hod is less common due o he applica ion Sandbox, which limi s he esou ces ha each
applica ion can access, e en i a de ice is oo ed , he ansomwa e could escala e p i ileges
and gain access o all iles.
The e o e, he mos common in And oid a e ac i i y blocke s, which equi e pe missions o
iden i y he applica ion ha is in he o eg ound and o e lap wi h i , causing he use o be
unable o use hei de ice.
These applica ions usually equi e he ollowing pe missions:
-RECEIVE_BOOT_COMPLETED: Launch ansomwa e as soon as he de ice boo s
up.
-USER_PRESENT oSCREEN_ON: De ec i he use is in e ac ing wi h he de ice.
-WRITE_SETTINGS: Modi y se ings on he de ice.
- BIND_DEVICE_ADMIN: Allows Sys emUI o eques hi d pa y con ols.
41
And oid Vi ual Machine
An And oid emula o was equi ed in o de o es he analyze wi h eal malwa e. The
machine has been con igu ed wi h he i ualiza ion en i onmen VMwa e, and he e sion o
he ope a ing sys em is And oid 8.
PackageManage and PackageIn o
In o de o handle he me ada a in o ma ion ha he ins alled applica ions con ains, he
analyze uses he classes PackageManage and PackageIn o.
The PackageManage is a class o e ie ing a ious kinds o in o ma ion ela ed o he
applica ion packages ha a e cu en ly ins alled on he de ice [78].
The PackageIn o is a class ha con ains o e all in o ma ion abou he con en s o a
package. This co esponds o all he in o ma ion collec ed om And oidMani es .xml [77].
Gi hub Desk op
Gi hub Desk op is an applica ion ha enables use s o in e ac wi h Gi Hub using a GUI
ins ead o he command line o a web b owse [64].
We used his ool o manage he e sions o he applica ion and o seamlessly me ge each
con ibu ion o all he pa icipan s o he eam, allowing a pa allel de elopmen .
3.1.1 Samples
In addi ion o he ools necessa y o de elop he wo k p esen ed he e, we ha e had o look
o samples o malicious applica ions o pe missions misin o ma ion o es he ool.
Malicious Apps Hashes
Despi e e o s o acqui e a da abase con aining he digi al signa u es (hash unc ion)
enc yp ed in di e en enc yp ion algo i hms (SHA, MD5, e c.) o all exis ing malwa e, we
could only ind a lis o MD5 hashes o malwa e samples [76].
Nowadays mos common enc yp ion algo i hms o digi al signa u es o applica ions a e
SHA1, SHA2, and MD5. The e o e, we ied o ob ain a da ase which con ains one o hese
algo i hms. I is wo h men ioning ha he mos secu e op ion is he use o SHA256 algo i hm
o highe as i causes less collisions, so we ha e he e o e adap ed he C yp og aphic
Signa u e Analysis so ha i emains unc ional when using a di e en hashing algo i hm.
48

Pe missions Da ase
The pe missions da ase is mos ly used by he pe mission analysis bu i is also used in
o he aspec s o he applica ion. This sample has been made om a ious sou ces,
speci ically om he pe missions API e e ence page o he And oid De elope s O icial Si e
[79] and om he And oid Pe missions si e [80] so as o ge a da ase as comple e as
possible. Wha is s o ed in his da ase a e he pe mission cons an s, he le el o dange , a
desc ip ion o he pe missions and he g oup hey belong o.
Domains Da ase
The Domains da ase is also used by he pe mission analysis. This sample has been made
om he And oid Pe missions si e [42] whe e all he pe missions a e assigned o a speci ic
g oup. In his da ase i is s o ed he pe mission g oups, an alias o he domain and a
desc ip ion o he g oup.
3.2 Decisions
In his sec ion we p esen a summa y o he design decisions ha we ha e made h oughou
he de elopmen p ocess o his wo k and ha a ec he inal o m o he de eloped ool.
- We decided o implemen a log analysis o And oid because we wan ed o ha e a
dynamic analysis o add some unc ionali y o e he wo o he me hods o analysis.
Also, since we did no ind much in o ma ion abou i , we wan ed o y and c ea e
some hing ela i ely new.
- We op o implemen a pe mission analyze because i can gi e he use plen y o
in o ma ion abou wha he applica ion is ying o achie e. Also, by gi ing a sco e we
belie e we can show isually and e ec i ely i i is ac ually a bene olen applica ion.
Finally, we hink ha i can aise he use ’s awa eness ega ding pe mission g an ing
and encou age hem o check he pe missions o he applica ions being ins alled on
hei de ice.
- We chose o implemen a signa u e analyze since i he e is a collision ound wi h
i s signa u e, i is almos ce ain ha i is malwa e, implying ha his analysis me hod
gi es an almos absolu e ce ain y o he use .
- We decided o implemen a Se e Se ings F agmen because e e y ime he EC2
ins ance is launched, a new IP is se o he ins ance. I we had no de eloped his
agmen , each ime we launched he ins ance we would ha e needed o w i e he
new IP in he applica ion code, build he APK and ins all i on ou mobile phones.
Also, his agmen allows he use o c ea e hei own se e and only ha e o wo y
abou adding he IP wi hou changing any code.
- We chose o p ocess he logs on he cloud because doing i locally would ha e
implied ha he applica ion would p obably lag o c ash due o he amoun o
p ocessing powe needed. I also implies ha he ba e y usage is educed, since
less powe is needed. Finally, his allows he use o se up hei own se e o
p ocessing he logs.
49
- We also concluded ha we would only analyze he applica ions ins alled by he
use and no he s ock applica ions since hese applica ions a e de eloped by
ele an companies which a e globally us ed. Also, since he use canno unins all
hem, i would only mean ha he analyses would ake mo e ime and hey would no
gain any hing.
- We decided o implemen he upg ading and adjus men o he applica ion code
in case o a da abase eplacemen , because in case o being able o acqui e a da a
se wi h enc yp ion algo i hms be e han MD5 o e en con aining se e al ypes o
algo i hms applied o a single applica ion.
- We decided o de elop ou app o a leas And oid 8.x (O eo) e sions, as hey
mo ed om an Ins all- ime pe missions policy o a Run ime pe missions policy. In
addi ion, we make su e we a e up o da e wi h e sion 11, which can be conside ed
he mos up o da e e sion, as e sion 12 is s ill in es ing. Finally, we decided o
wo k wi h his e sion because, in he pe mission analysis, he app e ie es he
ca ego y o he ins alled apps. This ac ion can only be pe o med wi h a 26 API le el
which co esponds o And oid 8.
50
4. Analysis Me hods
This chap e in oduces he heo y equi ed o unde s anding he h ee analysis me hods we
ha e pe o med in he applica ion, which a e he C yp og aphic Signa u e Analysis, he
Heu is ic Log Analysis and he Pe mission Analysis.
4.1 C yp og aphic Signa u e Analysis
This sec ion ocuses on he concep s o c yp og aphic signa u es and hei subsequen
analysis o de ec malwa e. In he li e a u e on his subjec , inge p in s calcula ed wi h a
hashing algo i hm a e o en e e ed o as signa u es.
The e a e cu en ly o he me hods o malwa e de ec ion, bu he use o signa u es o hash
unc ions by compa ing wi h he esul s o p e iously de ec ed and analyzed malwa e is s ill
he mos unc ional echnique o an i i us o secu i y sys ems. Google Play S o e equi es
ha each APK mus be signed wi h wo digi al ce i ica es: an App signing key (used o sign
APKs ha a e ins alled on a use 's de ice) and an Upload key (used o sign he app bundle
o APK be o e you upload i o app signing wi h Google Play). As pa o And oid secu i y,
he signing key ne e changes du ing he li e ime o an applica ion, so i no only ensu es
ha And oid applica ions a e us wo hy, bu also e i ies ha he applica ion has been
p o ided by a us ed sou ce [65]. I a hi d pa y manages o ake an App signing key
wi hou he knowledge o pe mission o an app de elope , i could sign and dis ibu e he app
ha maliciously eplaces he au hen ic applica ion o co up s i . Mo eo e , i could also sign
and dis ibu e apps unde you iden i y ha a ack o he apps o he sys em i sel , o co up
o s eal use da a.
The ce i ica e inge p in is a sho and unique ep esen a ion o a ce i ica e ha is o en
eques ed by API p o ide s alongside he package name o egis e an app o use hei
se ice. The MD5, SHA-1 and SHA-256 inge p in s o he upload and app signing
ce i ica es can be ound on he app signing page o he Play Console. When you a e ying
o publish an applica ion you mus ha e p e iously signed i by you sel p o iding he SHA-1
o you signing ce i ica e o you upload i o he Play Console, and Play App Signing akes
ca e o he es . Google Play S o e checks ha he package name and ce i ica e ma ch wi h
he applica ion and i hey do no ma ch i is no o e ed o use s bu i i is an upda e o an
exis ing applica ion in he s o e i will conside i as a new applica ion and will no o e i o
use s as an upda e [66].
The analysis o c yp og aphic signa u es is based on da abase que ies, which s o e he
in o ma ion ob ained om p e iously epo ed o analyzed malicious iles o applica ions.
This in o ma ion con ains he summa y unc ions o he malicious iles which a e used o
uniquely and unambiguously iden i y each ile hos ed in he da abase.
C yp og aphic signa u es a e a ma hema ical algo i hm (hash unc ion) ha maps a da a se ,
ega dless o i s size, o a bi -a ay o a ixed size. They a e essen ial o malwa e de ec ion
51
since in case o e en he sligh es modi ica ion o he da a o code, he bi -a ay changes
ex ensi ely. They a e also de e minis ic so ha a malicious ile always gene a es he same
bi a ay when applying he same hash unc ion and i he hash unc ion chosen has a weak
collision, i would be impossible o ind one malicious ile and ano he alid ile con aining he
same hash.
The e a e di e en ypes o algo i hms used o hash unc ion gene a ion, bu he mos
common a e SHA2 (256, 384 o 512 bi s), SHA1 (160 bi s) and MD5 (128 bi s). The
no o ious di e ence be ween he p e iously men ioned algo i hms ocuses on he leng h o
he gene a ed hash s ing, he longe he leng h o he s ing he lowe he p obabili y o a
collision.
We can see in Figu e 28 an analysis o an And oid applica ion pe o med by he online ool
Vi usTo al [81], which makes use o a da abase managemen sys em ha s o es signa u es.
I ocuses on pe o ming ile que ies emo ely using a hash unc ion (SHA256) in o de o
check i he iles a e malicious.
[81] Figu e 28: Vi usTo al - Analysis o an And oid apk
52
4.2 Heu is ic Log Analysis
Log iles a e compu e -gene a ed ex iles ha a e au oma ically p oduced whene e a
speci ic e en akes place in a speci ic en i onmen , such as an ope a ing sys em,
applica ion, se e , e c. They con ain in o ma ion abou usage, ac i i ies and ope a ions. This
in o ma ion is use ul o oubleshoo ing and debugging he en i onmen , since hey keep a
eco d o e e y hing ha has happened in a ex ual o ma . They ypically ha e he LOG ile
ex ension.
Each ope a ing sys em has di e en me hods o s a ing o s opping logs eco ding, since
bo h he en i onmen and he speci ic e en s ha igge hem a e di e en . The e o e, each
OS is uniquely con igu ed o gene a e log iles in esponse o speci ic e en s. In he case o
Linux, i di ides log iles in o ou ca ego ies: Applica ion logs, E en logs, Se ice logs and
Sys em logs [67].
4.2.1 And oid logs
And oid Logging Sys em consis s o di e en ci cula bu e s, which p o ide logging o
di e en pa s o he sys em. These log bu e s a e [68]:
- adio: This bu e con ains adio/ elephony ela ed messages.
-e en s: This bu e s o es bina y sys em e en messages.
-main: This is he de aul log bu e , which does no con ain sys em and c ash log
messages (i con ains he applica ions logs). This is he only bu e a ailable o apps.
-sys em: This bu e con ains he sys em logs.
-c ash: This bu e s o es logs ela ed o c ashes.
-ke nel: This bu e s o es ke nel ela ed logs.
-secu i y: This is he secu i y log bu e .
-s a s: This bu e co esponds o s a is ics logs.
Each message in he log consis s o a ag indica ing he pa o he sys em o applica ion ha
he message came om, a imes amp, he message log le el and he log message i sel .
The log le el is a cha ac e ha encodes he p io i y o he log en y (i is And oid’s
e minology o se e i y le el). He e we lis all he possible alues i can ake, o de ed om
lowes o highes p io i y [68]:
-V: Ve bose (lowes p io i y)
-D: Debug
-I: In o
-W: Wa ning
-E: E o
-F: Fa al
-S: Silen (highes p io i y, on which no hing is e e p in ed)
The Log class (and oid.u il.Log [69]) is an API ha allows use s o c ea e log en ies
based on hei log le el. I con ains se e al public me hods o logging in each p io i y. Fo
53

example, o Ve bose p io i y he use can use he me hod Log. (), o Wa ning p io i y he
use can use Log.w(), e c. Typically, hese me hods ake wo a gumen s: he log’s ag ( o
example, i could be he name o he ac i i y ha c ea es he log) and i s message. The API
hen c ea es he log en y wi h he passed alues and adds he imes amp, he iden i ie o
he issuing p ocess and h ead and o he in o ma ion.
On he o he hand, he Logca command-line ool is used o eading logs. The use can un
logca h ough an adb shell using he ollowing syn ax:
[adb] logca [<op ion>] ... [< il e -spec>] …
This command has a wide a ie y o op ions; hese a e he mos ele an [70]:
--b <bu e >: Speci ies he log bu e ha is going o be ead.
--c: Clea s he en i e bu e .
--d: Dump he log con en s.
-- < o ma >: Se s he ou pu o ma o log messages. The de aul is h ead ime
o ma .
The e a e se e al ou pu o ma s ha modi y he ou pu so ha hey display ce ain me ada a
ields. The ollowing lis co esponds o he suppo ed ou pu o ma s [70]:
-b ie : Display p io i y, ag, and PID o he issuing p ocess.
-long: Display all me ada a ields.
-p ocess: Display PID only.
- aw: Display he aw log message wi h no o he me ada a ields.
- ag: Display he p io i y and ag only.
- h ead: A legacy o ma ha shows p io i y, PID, and TID o he h ead issuing he
message.
- h ead ime (de aul ): Display he da e, in oca ion ime, p io i y, ag, PID, and TID o
he h ead issuing he message.
- ime: Display he da e, in oca ion ime, p io i y, ag, and PID o he p ocess issuing
he message.
Now we show some examples o he mos ele an o ma s:
- The de aul ou pu o ma has he ollowing s uc u e:
Da e Time PID TID P io i y Tag: Message
05-16 20:04:58.151 6992 7560 i came a : open came a: 1, package
name: com.wha sapp
- The b ie ou pu o ma has he ollowing s uc u e:
P io i y/Tag( PID): Message
I/Ac i i yManage ( 585): S a ing ac i i y: In en {
ac ion=and oid.in en .ac ion...}
- The long ou pu o ma has he ollowing s uc u e:
54
[ Da e Time PID: TID P io i y/Tag ]
Message
[ 05-28 18:30:53.542 3716: 3733 I/com.wha sapp ]
Backg ound young concu en copying GC eed 25395(1669KB)
AllocSpace objec s, 0(0B) LOS objec s, 24% ee, 6753KB/8917KB,
paused 262us o al 112.240ms
4.2.2 Log handling
Log iles eco d a la ge amoun o in o ma ion ha con eys e e y hing ha is happening in
he sys em. This makes log iles an impo an elemen o conside i we wan o analyze wha
applica ions a e unning on he sys em and y o igu e ou wha ac ions hey a e ca ying
ou . The e o e, log analysis is a sc u iny me hod widely used in he indus y o malwa e
de ec ion. The mos ypical use cases o log analysis a e [71]:
-Compliance wi h secu i y policies, audi s o egula ions.
- Sys em oubleshoo ing.
-Fo ensics.
- Secu i y inciden esponse.
- Unde s anding online use beha iou .
-Pe o mance imp o emen .
Depending on he use case, he beha iou o log analysis di e s acco ding o he con ex o
he log iles. A e all, bo h he da a and objec i e behind a ne wo k log analysis a e no he
same as a sys em log analysis. Hence, log analysis mus in e p e messages wi hin he
con ex o he applica ion o sys em. None heless, hey usually ha e some p ocedu es in
common [71]:
-No maliza ion: Con e ing log messages om di e en sou ces in o a uni o m
o ma .
-Pa e n ecogni ion: Selec ing incoming log messages and compa ing hem wi h a
p e iously es ablished da ase o il e o handle he logs in di e en ways.
-Classi ica ion and agging: O de ing and classi ying log messages in o di e en
ca ego ies based on speci ic keywo ds, da es, e c o la e usage.
-Co ela ion analysis: Collec ing messages om di e en sys ems and inding all he
messages belonging o one single e en .
-A i icial Igno ance: Disca ding log en ies which a e known o be unin e es ing.
The no maliza ion and classi ica ion p ocedu es ensu e an ease o use while handling he
log messages. Secondly, he pa e n ecogni ion and co ela ion analysis p ocedu es g an
he analys he in o ma ion necessa y o d aw use ul conclusions om he log en ies. Las ly,
he a i icial igno ance p ocedu e ensu es he ce ain y o he esul s as well as a be e
pe o mance.
Log analysis is a ype o dynamic analysis, since i examines he beha iou o a sys em,
ne wo k o applica ions while hey a e in execu ion. This implies i is a ime and esou ces
consuming p ocess, since huge amoun s o in o ma ion a e gene a ed each second and
55
e e y log mus be checked. Ne e heless, i s g ea es ad an age is ha i allows he
adminis a o o disco e how he analyzed elemen is in e ac ing wi h he sys em, which
helps disco e mal unc ion o damages.
The e a e ools cen ed in And oid log analysis o moni o sys em use. As an example,
Sola Winds Loggly [72] has se e al unc ionali ies ha allow he use o pe o m an analysis
o he logs o his de ice: i agg ega es all o he And oid logs on he cloud so ha he use
can moni o and analyze hem by means o sea ch que ies and simpli ied cha s and
dashboa ds. Ano he example is And oidLogViewe [73], which displays he logs o he
use ’s And oid de ice and allows him o sea ch in hem using egula exp essions, il e hem
by ag, PID, p io i y, e c and mo e.
4.3 Pe mission Analysis
And oid app pe missions a e conside ed o be a il e ha helps o p ese e use p i acy by
p o ec ing access o es ic ed in o ma ion, such as he use 's sys em s a us and con ac
in o ma ion, and o es ic ed ac ions, such as connec ing o a linked de ice o eco ding
audio. They lie in he And oidMani es .xml ile [24] and he e a e di e en classes depending
on hei pu pose and es ic ion scope ha hey g an . This sec ion co e s he impo ance o
And oid pe missions om a malwa e analysis app oach and p o ides a de ailed explana ion
o how hey a e assessed and classi ied.
Al hough he p e ious analysis and all he in o ma ion decla ed in he And oidMani es ile
mus be conside ed as ele an , an And oid pe missions assessmen is undoub edly one o
he sec ions o which mo e a en ion should be paid as a s a ing poin when analyzing
malwa e on And oid. All sys em unc ionali y ha he applica ion wan s o access ha e o be
decla ed wi hin he And oidMani es .xml ile unde he ollowing ags s uc u e:
<mani es >
<uses-pe mission />
<pe mission />
<pe mission-g oup />
…
</mani es >
Since in his wo k he pe mission analysis is pe o med on he <uses-pe mission /> ag,
nex , we e iew wha i s objec i e is.
<uses-pe mission> ag
This ag indica es wha pe missions an applica ion equi es, e e ing o ha dwa e and
so wa e componen s ha a e on he de ice and ha he applica ion can make use o . F om
a malwa e analysis pe spec i e, he key is o ind some kind o unusual beha iou s and
o he indica o s. The e o e, in a s udy o decla ed pe missions i is impo an o ba e in mind
he ollowing asks [74] as a guide:
56
- Iden i y hose applica ions ha eques a la ge amoun o pe missions. These kinds
o applica ions gene ally demand addi ional pe missions wi hou ac ually equi ing
hem, which is a sign o unusual beha iou and migh be a hin o a malwa e en y.
- Iden i y he unc ions ha he applica ion in ends o pe o m h ough he decla ed
pe missions.
- Iden i y he pe missions ha i does no make sense o decla e acco ding o he
supposed na u e o he applica ion. Fo example, an applica ion whose supposed
unc ionali y is o allow he use o change he wallpape desk op backg ound, bu
which, h ough i s pe missions, eques s sending o SMS messages.
- Iden i y he pe missions ha he applica ion does no decla e, bu i would be
expec ed o decla e acco ding o he supposed na u e o he applica ion. Fo
example, a pho og aphy applica ion ha does no equi e access o he came a.
- Iden i y he pe missions ha he applica ion decla es and, acco ding o i s
classi ica ion, look o hose which a e conside ed o be in asi e and po en ially
dange ous. Fo example, pe missions ha dele e packages, moun /unmoun
ilesys ems, ead logs, e c.
On he o he hand, i he applica ion ins alla ion p ocess is analyzed, some peculia i ies
should be obse ed depending on he ype o ins alla ion ha is ca ied ou :
- In case o ins alling h ough he Google Play S o e, he pe missions a e shown o he
use g ouped by ca ego ies o eques hei consen . A his poin i is impo an o
no e a peculia i y ha occu s when upda ing applica ions ha a e al eady ins alled on
he de ice, since he e may be h ea s ha make use o i :
○ I a pe mission om a ca ego y ha has no been p e iously app o ed is
added, a con i ma ion dialog is shown o he use in o de o app o e he new
g oup o pe missions.
○ I a pe mission om a ca ego y ha has been p e iously app o ed is added,
no con i ma ion is eques ed om he use . So he e migh be he possibili y
ha an applica ion ha ini ially eques ed a ce ain ca ego y, a e an upda e,
inco po a es a new pe mission ha belongs o he same ca ego y wi hou
asking he use o any con i ma ion. Fo example, an app ha ini ially
eques s he Messaging ca ego y because i uses he
and oid.pe mission.READ_SMS pe mission, a e an upda e, i inco po a es
he and oid.pe mission.WRITE_SMS pe mission wi hou asking he use o
app o al.
- In case o ins alling an APK h ough al e na i e ma ke s such as Amazon AppS o e
o Ap oide (in any o he cases i is necessa y o ha e allowed he ins alla ion om
57
-Ins alledAppsAdap e : I is a iew adap e which con ols how he Recycle iew
shows he iew. I also maps all applica ion’s in o ma ion om he xml ile o unc ions
in he adap e . The e is implemen ed a lis ene which w aps he en i e i em and i he
checkbox is clicked, i is se o he opposi e o wha i was, so ha wi h he use o
no i yDa aSe Changed() me hod, he lis o apps is e eshed wi h i s espec i e
checkbox om Recycle View.
-Signa u eAnalyze F agmen : I is he main class whe e all bu on’s unc ionali ies
a e de ined wi h hei own lis ene and mapped o XML componen s based on he
g aphical iew. Un o una ely, MD5 has been c yp og aphically b oken and
conside ed insecu e. Fo his eason, i is always ecommended o s o e
c yp og aphic signa u es using a di e en hashing algo i hm, so we decided o
implemen a me hod (Figu e 35) in which i examines he i s line o a da abase
added and i checks which hashing algo i hm is used by i s cha ac e leng h. This
makes ou app capable o upda ing he da abase managemen in case he e is a
hash da abase subs i u ion.
Figu e 35: Me hod o ecognise which algo i hm is used in he da abase
P oblems o e come
The i s e sion o he da abase p esen ed a p oblem which was he epe i ion o he uples
when ini ialising ou da abase, so o sol e i we p oceeded o modi y hash, d_g p and idpe m
columns o ype UNIQUE.
Rega ding he de elopmen o he c yp og aphic signa u e analyze , se e al modi ica ions
we e made un il we eached he inal e sion. A e managing o display he lis o
applica ions ins alled on he And oid de ice along wi h a checkbox, we decided o implemen
he SELECT ALL op ion o make i s aigh o wa d o he use o make a ull selec ion o
apps. In addi ion, i was decided o add a Sea chbox as i was di icul o ind a speci ic app
among all he ins alled ones.
Being awa e o he ac ha he Malwa e Lis able was no secu e enough in e ms o he
hashing algo i hm used, we s uc u ed he c yp og aphic signa u e analyse so ha i can be
unc ional wi h any da abase con aining a di e en hashing algo i hm.
64

5.2 Heu is ic Log Analysis Implemen a ion
In he discussions ca ied ou by he membe s o he eam o he design o he malwa e
de ec ion ool, we came o he conclusion ha a heu is ic analysis o he log iles was
necessa y. The easons behind ou decision o implemen his analysis a e he ollowing:
- To ale he use o all he applica ions ha a e cu en ly unning on he de ice,
since some o hem may be unning in he backg ound wi hou he use ’s knowledge.
- To le he use know wha a ge elemen s (came a, SMS, s o age, e c) each
unning applica ion is ying o access.
- To le he use es ablish speci ic keywo ds ha will be moni o ed. The esul shows
all he applica ions ha sha ed a log en y wi h ha speci ic keywo d.
- To check i he applica ions ha accessed ce ain a ge elemen s had he
pe missions necessa y o do so.
O all he p ocedu es commonly used in log analysis, we use he ollowing:
-Classi ica ion and agging: We classi y he logs by package name and keywo d.
-Co ela ion analysis: We g oup all he logs o each applica ion and co ela e all he
logs o a speci ic applica ion by he a ge elemen s accessed.
-A i icial Igno ance: We only use hose logs ha con ain some hing ela ed o
applica ions, since he e a e plen y o sys em logs ha a e no in e es ing o
malwa e de ec ion pu poses.
We ha e de eloped his analysis di iding i s unc ionali y in o wo pa s:
-Applica ion: I connec s he And oid mobile de ice o he se e , ex ac s i s log
en ies, sends hem o he se e along wi h he package names o all he use apps
ins alled on he de ice and some il e s se by he use . A e he analysis is s opped,
i e ie es he esul om he se e and s o es ha esul in he P e ious Resul s
da abase loca ed in he And oid de ice. Finally, i displays he conclusion isually,
a e p ocessing he esul .
-Se e : Whene e an incoming connec ion om any mobile de ice a i es, i
p ocesses he logs ecei ed based on he il e s es ablished by he use and, a e
s o ing all he logs, i summa izes he en ies o in e es . Once he s op signal is
ecei ed, i e ie es he esul s ob ained and sends hem back o he applica ion
ins alled in he mobile de ice h ough he connec ion.
5.2.1 Applica ion
Se up
Reading logs is no some hing ha a egula applica ion should do. Fo his eason, he
pe mission needed o accessing hem, called and oid.pe mission.READ_LOGS, is a
o bidden pe mission, which means ha i canno be g an ed by he use like no mal
pe missions. One way o g an ing his ype o pe missions o applica ions is by oo ing he
de ice, which is ex emely isky. Ins ead, he use can use ADB (And oid Debug B idge) [45]
o open a shell ha communica es wi h he de ice.
65
Fi s o all, he use mus be able o access he de elope op ions o he And oid de ice:
- This is achie ed by clicking 7 imes he build numbe , ke nel e sion o o he alue
inside he in o ma ion abou he phone (depends on he de ice).
- Inside he de elope op ions he use mus allow he USB debugging.
- The use needs o ha e ins alled ADB h ough pla o m- ools [82] on he compu e o
which he phone is going o be plugged.
- A e plugging he phone o he compu e and accep ing o connec o said compu e ,
he use mus en e he di ec o y o pla o m- ools h ough a e minal (CMD in
Windows). Using he command adb de ices we can check i he de ice is being
de ec ed. I i is, he use mus execu e he command adb shell pm g an
com.example.and oidmalwa eanalyze and oid.pe mission.READ_LOGS,
which g an s And oidMalwa eAnalyze he READ_LOGS pe mission.
Classes de eloped
As Figu e 36 shows, h ee di ec o ies we e de eloped o con ain he unc ionali y o he Log
Analysis:
-se e Se ings: Handles he IP and Po numbe s used o connec o he se e .
-logAnalyze : All he unc ionali y o he analysis is con ained inside his di ec o y,
excep sa ing he esul ob ained om he se e and displaying i .
-p e Resul s: Con ains he P e Resul sDB, which is he da abase used o s o e he
esul s o bo h he signa u e and log analyses. I also con ains he unc ionali y
needed o displaying said esul s.
Figu e 36: O ganiza ion o he Se e Se ings, Log Analyze and P e ious Resul s classes
66
Nex , we explain each class ha composes he Se e Se ings:
-Se e Se ingsF agmen : This F agmen is used o handle he add esses (IP:Po )
ha he Log Analyze will use o connec o he use . All he al eady s o ed add esses
a e shown h ough a Lis View.These add esses can be selec ed by he use , simply by
p essing hem. The add ess selec ed by he use is he one ha is going o be used
o he connec ion. This F agmen also displays one bu on o adding add esses and
one o dele ing he selec ed add ess. The add esses a e s o ed inside
Sha edP e e ences. When he use adds a new add ess, bo h IP and Po numbe s
a e pa sed. The pa sing me hod is shown in Figu e 37.
Figu e 37: Se e Se ingsF agmen - Add ess pa sing
Nex , we explain each class ha composes he Log Analyze :
-LogAnalyze F agmen : This F agmen is he en ypoin o he log analysis. I is
used o displaying wo bu ons. Bo h bu ons edi ec o he
LogAnalyze F agmen Applica ions, passing a boolean pa ame e , which ells he
class i he applica ions o be lis ed ha e o be use applica ions (ins alled by he
use ) o sys em applica ions (s ock-apps, sys em se ices). The use will ha e o
choose be ween one o hem.
-LogAnalyze F agmen Applica ions: This F agmen is he on end o he analyze .
I i s c ea es a Recycle View and se s i s Adap e wi h a new class, called
67
LogAppsAdap e . Then, i also ini ializes he LogAnalyze Connec . In his F agmen ,
he use can ype some keywo ds ha will be moni o ed while analyzing he logs.
When he analysis is s a ed, he LogAnalyze Connec is execu ed. When he
analysis is s opped, i sa es in he P e Resul sDB he esul ob ained and calls he
class ShowLogResul o display he esul . This class also has an ale message
sys em ha , based on an in ege , displays a Snackba wi h in o ma ion ega ding he
s a us o he analysis (Figu e 38).
Figu e 38: LogAnalyze F agmen Applica ions - s a us
-LogAppsAdap e : This class ex ends Recycle View.Adap e . I is esponsible o
con olling he checkbox lis o applica ions. I i s e ie es all he applica ions
ins alled on he de ice, bo h use and sys em apps (Figu e 39). The package name,
applica ion name and icon o all he applica ions a e s o ed in wo A ayLis s o
PackageIn oS uc classes, which we de eloped o s o e ypical alues o
applica ions (Figu e 40). One o he a ays con ains he use apps and he o he he
sys em apps. Depending on whe he he use chose o lis use o sys em
applica ions, he co esponding a ay is used in he checkbox lis . Fo each
applica ion, his Adap e shows i s icon and applica ion name and a checkbox; i no
applica ion name is ound, he package name is p in ed.
68
Figu e 39: LogAppsAdap e - ge ins alled apps
Figu e 40: LogAppsAdap e - PackageIn oS uc
-LogAnalyze Connec : This class ex ends AsyncTask [86]. I is esponsible o
ex ac ing he logs, sending hem o he se e and e ie ing he esul om he
se e . I i s loads he selec ed add ess ha was s o ed in Sha edP e e ences in he
Se e Se ingsF agmen . When his AsyncTask is execu ed, he AsyncTask me hod
doInBackg ound() is called. This me hod i s connec s o he se e using he
loaded add ess (Figu e 41). Once connec ed o he se e , he logs a e sen h ough
he connec ion (Figu e 42). When he use p esses he bu on o s op he analysis,
he esul is e ie ed h ough he connec ion (Figu e 43). Finally, when
doInBackg ound() inishes, he AsyncTask me hod onPos Execu e() sends
he esul back o LogAnalyze F agmen Applica ions.
Figu e 41: LogAnalyze Connec - New connec ion
69

Figu e 42: LogAnalyze Connec - Ex ac and send logs
Figu e 43: LogAnalyze Connec - Re ie e esul
- LogResul : This class is esponsible o con e ing he esul om ex in o an a ay
o LogIn e ac ions classes (Figu e 44), which we de eloped o s o e in o ma ion
needed o display he esul . I also has a unc ion ha educes he size o he esul ,
as he da a e ie ed om he se e may ha e some applica ion esul s spli o e
mo e han one line, allowing i o be educed o a single line. This way, he da abase
sa es some space.
Figu e 44: LogResul - A ibu es
70
Nex , we explain each class ha composes he P e ious Resul s:
-P e Resul sDB: This class ac s as a da abase o he esul s ob ained om he log
and signa u e analysis me hods. This da abase con ains a able called p e Resul s,
which is o med by he columns shown in Table 4. The da e ime o he comple ion o
he analysis is s o ed o know when he analysis was pe o med. The analysis_ ype
ow di e en ia es be ween he signa u e and log me hods. The apps_analysed alue
is used o know wha elemen s we e analyzed and he analysis_ esul s o es he
esul ob ained om he analysis. The wo main me hods o his da abase a e
inse ToDB() (inse s a new esul in o he able) and eadAllF omDB()
( e ie es all he esul s pe o med).
P e Resul s
Column name
Type
Schema
_id
INTEGER
PRIMARY KEY AUTOINCREMENT
da e
TEXT
Da e and ime when he analysis was
inished
analysis_ ype
TEXT
Desc ibes he analysis ype (log o
signa u e)
apps_analysed
TEXT
Lis o he keywo ds and package names
o he applica ions analyzed
analysis_ esul
TEXT
Resul o he analysis
Table 4: P e ious Resul Table s uc u e
-P e Resul sF agmen : his F agmen is he en ypoin o he P e ious Resul s. I
i s ge s all he esul s s o ed in he da abase h ough he me hod
eadAllF omDB() and displays hem in a Recycle VIew whose Adap e is an
ins ance o P e Resul sAdap e . I he use selec s one o he elemen s o he lis ,
she/he will be edi ec ed o ShowResul i i is a signa u e analysis esul o
ShowLogResul i i is a log analysis esul . I no analysis has been pe o med, he
message "No analysis pe o med ye " is displayed.
-P e Resul sAdap e : This class ex ends Recycle View.Adap e . Fo each elemen ,
i displays he da e when he analysis was pe o med and he analysis ype
(signa u e o log).
-ShowResul : This F agmen displays he esul ob ained om a signa u e analysis.
Ini ially, his class calls i s me hod ge Ins alledApps() (see Figu e 45). Fi s o
all, his me hod checks i no applica ions ha e been analyzed. I ue, hen he lis o
apps analyzed will display “None”. I a leas one applica ion has been analyzed, i
ge s he applica ion name, package name and applica ion iconn o he analyzed
71
applica ions. This p ocess is simila o he one used in LogAppsAdap e . These
applica ions a e hen displayed using he P e Resul sRecycle View class, wi h he
Elemen sAdap e . A e wa ds, a Tex View displays he esul .
Figu e 45: ShowResul - ge Ins alledApps
-P e Resul sRecycle View: This class ex ends Recycle View. I was de eloped o
es ablish a dynamic size o he lis , since he lis had o ha e he necessa y heigh o
w ap i s con en s, bu also maximum heigh , so ha i did no ake up oo much
space. As seen in Figu e 46, his was accomplished by o e iding he
onMeasu e() me hod and se ing a heigh o 750 a mos .
Figu e 46: P e Resul sRecycle View - onMeasu e
-Elemen sAdap e : This class ex ends Recycle View.Adap e . I displays all he
applica ions o elemen s analyzed ( he keywo ds speci ied in
LogAnalyze F agmen Applica ions).
72
-ShowLogResul : This F agmen is used o show he esul s o a log analysis. I
i s ly c ea es an ins ance o LogResul and calls i s me hod ge Lis (), which
con e s he esul om ex o an a ay o LogIn e ac ions. A e wa ds, he me hod
ge Ins alledApps() o ShowLogResul is called (see Figu es 47 and 48). The
unc ionali y o his me hod is qui e simila o he also named ge Ins alledApps()
me hod o ShowResul . Fi s , i no elemen s we e analyzed, an A ayLis is c ea ed
wi h only one elemen ha will be displayed as “E e y hing”, since no choosing any
elemen o analyze implies analyzing all he use applica ions. I a leas one elemen
was analyzed, he A ayLis is se wi h he applica ion name, package name and
applica ion icon o he analyzed apps. Then, i a e ses all he elemen s and sub
elemen s p esen in he esul , adding he applica ion name, package name and
applica ion icon o he applica ions and he name o keywo ds and a ge elemen s o
wo A ayLis s o LogIn e ac ions. The elemen s o he esul can ei he be
applica ions (which implies ha hei sub elemen s a e he a ge elemen s hey ha e
accessed) o keywo ds se by he use (which implies ha hei sub elemen s a e he
applica ions ha ha e accessed ha keywo d). Ha ing he h ee A ayLis s, i s he
elemen s analyzed (apps and keywo ds) a e displayed h ough a
P e Resul sRecycle View, wi h he Elemen sAdap e . Then, a lis o all he
applica ions ha we e unning du ing he analysis is shown in a Recycle View, wi h
he LogElemen sAdap e o he elemen s (applica ions) and
LogSubElemen sAdap e o he sub elemen s ( a ge elemen s) since he
applica ions ha ha e accessed a leas one a ge elemen can be expanded. Nex ,
a lis o he keywo ds speci ied by he use and ha we e ound du ing he analysis is
shown in a Recycle View, wi h he LogElemen sAdap e o he elemen s (keywo ds)
and LogSubElemen sAdap e o he sub elemen s (applica ions) since he keywo ds
ha ha e been accessed by one applica ion can be expanded. Finally, he
se Pe missionsLis () me hod checks i he applica ions ha ha e accessed a a ge
elemen had he pe missions necessa y o do so (see Figu e 49) (we decided i
would be be e o check whe he he apps ha e a pe mission wi hin a speci ic
pe mission g oup ins ead o compa ing all possible pe missions, because he
pe missions needed a e well summa ized by hei pe mission g oup; he only
excep ion is NFC, since i is a e y speci ic pe mission inside he pe mission g oup
Ne wo k, which is ex emely b oad). This is achie ed by e i ying all he pe missions
g an ed o hose applica ions (see Figu e 50) and con as ing i one o hose
pe missions allows he app o access he speci ic a ge elemen . Fo his pu pose a
lis wi h he a ge elemen s and hei co esponding necessa y pe missions () has
been c ea ed o check i he applica ions ha e hem g an ed; he alues a e
displayed in Table 5. The esul o checking he pe missions is shown in a
Recycle View, wi h he LogElemen sAdap e o he elemen s (apps / keywo ds) and
LogSubElemen sAdap e o he sub elemen s ( a ge elemen s / apps) since he
applica ions ha ha e accessed a leas one a ge elemen can be expanded. A
symbol a he igh o each elemen shows i he necessa y pe mission is g an ed
(g een check) o no ( ed c oss).
73
sudo cu l -O
h p://d3kbcqa49mib13.cloud on .ne /spa k-2.2.0-bin-hadoop2.7. gz
sudo a x ./spa k-2.2.0-bin-hadoop2.7. gz
sudo mkdi /us /local/spa k
sudo cp - spa k-2.2.0-bin-hadoop2.7/* /us /local/spa k
Add /us /local/spa k/bin o he PATH:
expo PATH="$PATH:/us /local/spa k/bin"
Include he in e nal hos name and IP o /e c/hos s. Fo example:
127.0.0.1 localhos
172.30.4.210 ip-172-30-4-210
Finally, download he wo necessa y sc ip s ha we ha e de eloped o he se e :
-se e .c: Manages incoming connec ions, pa ses incoming logs, sends hem o he
analyze .py sc ip and, when he use has s opped he analysis, i gi es he esul
back o he use .
-analyze .py: Spa k S eaming sc ip ha s o es, spli s and educes he logs.
To execu e he sc ip s, open wo e minals. In he i s one execu e:
gcc -Wall -g se e .c -o se e
./se e
In he o he one execu e:
spa k-submi analyze .py
Nex , he unc ionali y o bo h sc ip s (se e .c and analyze .py) is going o be explained in
de ail.
Se e .c
The se e .c sc ip pe o ms h ee unc ions desc ibed below:
1. Connec ion managemen
Fi s , he sc ip wai s un il i can connec wi h analyze .py ia TCP. The socke
es ablished o his connec ion is iden i ied by he add ess localhos and he po
9999. Once he connec ion wi h he sc ip has been es ablished, he se e begins o
accep clien connec ions.
We ha e p og ammed his sc ip o always be in execu ion, allowing all clien s o
connec o he se e whene e hey need. Fo his eason, he se e has been
de eloped as a concu en se e wi h an accep -and- o k pa e n. We can see his
pa e n in Figu e 52, bu a e he me hod accep () e u ns, he se e o ks.
80

[85] Figu e 52: Elemen a y TCP Socke
When he connec ion has been es ablished, he unc ion ecei eDa a() is called.
2. Log managemen
The logs a e managed inside he me hod ecei eDa a().This me hod i s
ecei es he keywo ds and applica ions ha a e used as il e s and he package
name o all he use applica ions o he clien ’s de ice.
Then, he p ocess loops un il he clien sends a speci ic signal ha ins uc s he
se e ha he use has inished sending logs. Fo ease o use, we decided o lowe
case all he logs ecei ed.
Now, he se e checks i he logs con ain any o he package names om among all
he use applica ions on he clien de ice, which we e ecei ed a he s a o his
me hod. I one is ound, we conside ha log o be o in e es , since we only wan o
moni o he beha iou o he use applica ions.
Since we wan o show he use wha applica ions a e unning, we send he logs
ela ed o he a ge elemen s o be moni o ed o he analyze .py sc ip ,
conca ena ing a he beginning o he log he IP o he de ice o he clien and he
package name o he applica ion ound wi hin he log.
81
We decided ha he e a e se e al a ge elemen s ha equi e special a en ion in
e ms o possible malicious beha io . These a ge elemen s a e:
- loca ion
- gps
- came a
- mic ophone
- sound
- eco de
- elephony
- blue oo h
- wi i
- ne wo k
- messaging
- mms
- sms
- sdca d
- s o age
- con ac s
- n c
- mail
- accoun
Now, h ee checks a e pe o med:
-The keywo ds and applica ions il e s a e emp y: we check i he e a e
any a ge elemen s in he log. I he e is one ound, we send i o analyze .py,
conca ena ing he clien ’s de ice IP, he package name o he applica ion
ound inside he log and ha a ge elemen .
-The keywo ds il e is no emp y: we check i he e a e any keywo ds o he
keywo ds il e in he log. I he e is one ound, we send i o analyze .py,
conca ena ing he clien ’s de ice IP, he keywo d and he package name o
he applica ion ound inside he log.
-The applica ions il e is no emp y: we check i he applica ion is in he
speci ied applica ions il e . I i is, we check i he e a e any a ge elemen s in
he log. I he e is one ound, we send i o analyze .py, conca ena ing he
clien ’s de ice IP, he package name o he applica ion ound inside he log
and ha a ge elemen .
3. Ge ing he esul
Since spa k s eaming s o es e e y hing in se e al pa i ions, we c ea ed he unc ion
ge Resul s(), which opens e e y ile inside e e y subdi ec o y ound in he Resul
di ec o y. Then, we send o he clien all he esul s ha con ain his IP and dele e hose
esul s.
Analyze .py
82
We ha e p og ammed his sc ip o always be in execu ion, allowing all clien s o connec o
he se e whene e hey need. Figu e 53 shows he code o his sc ip .
Figu e 53: analyse .py
Fi s , he sc ip wai s un il i can connec wi h he se e .c ia TCP. The socke es ablished
o his connec ion is iden i ied by he add ess localhos and he po 9999. Once he
connec ion wi h he sc ip has been es ablished, he se e begins o accep clien
connec ions.
I is a Spa k S eaming sc ip , which implies ha i is cons an ly ge ing in o ma ion. Fi s , i
sa es he logs ecei ed in he And oidLogs di ec o y. Then, i pa ses hose logs and educes
hem wi h he ollowing o ma ((IP, package name, a ge elemen ), numbe
o g ouped logs). Finally, i sa es hose educ ions in he Resul di ec o y. Figu e 54
shows a snippe o he sc ip in execu ion.
Figu e 54: analyze .py unning
83
5.2.3 P oblems o e come
-The IP and Po numbe s o he se e we e ini ially ha d-coded. The p oblem o his
app oach is ha he IP o he EC2 ins ance changes each ime he ins ance is
launched, which implies ha he applica ion had o be modi ied, compiled and
ins alled whene e he cloud ins ance was launched. Fo his eason, we decided o
implemen a Tex View whe e he use could w i e he IP and Po . We hen ealized
ha e e y ime he applica ion was launched, he use had o inpu he IP and Po ,
which was a e y exhaus ing ask. Finally, we op ed o de elop he Se e Se ings
class o s o ing he IP and Po s. Wi h his class, he use has o inpu hem only
once.
- A i s , all ypes o applica ions we e p in ed (use and sys em apps). This made i
oo di icul o he use o choose a speci ic applica ion, so we decided o di ide hem
in o wo di e en agmen s. We also decided o keep he sys em applica ions
because i can be e y in e es ing when pe o ming a log analysis o analyze by
Came a, Blue oo h, e c.
- In And oid, an applica ion canno connec o a socke in he UI Th ead (main h ead
o execu ion o he applica ion). This mean ha he connec ion o he se e had o
be execu ed in ano he h ead. We decided o achie e his by using he AsyncTask
class o i s simplici y in p og amming and he ac ha i s compu a ion uns in a
backg ound h ead and i s esul is pos ed o he UI h ead.
- When sending da a o he se e , we ealized ha ec () call did no always ead all
he da a sen . Mo e speci ically, i he size o he da a was oo big, only a ac ion o
ha da a was ecei ed. We a i s hough ha i could be due o he size o he
bu e whe e he da a was being s o ed, bu we la e ealized ha we shouldn' expec
o ecei e he da a in he same numbe o ead calls as he e we e w i e calls. Fo
ha eason, we used e mina ion cha ac e s, o speci y he end o he da a being
sen . We used ‘#’ o he use app package names, ‘ n’ o he logs and ‘Q’ o
signaling he end o he communica ion.
- A i s we pe o med he log il e ing in he applica ion. A p oblem a ose, which was
ha some de ices could no handle such a la ge amoun o p ocessing. Fo ha
eason, we decided o mo e he log il e ing o he se e . This also allowed us o
s o e all he logs in he se e be o e doing any il e ing.
- One o he bigges challenges we aced was how o ex ac use ul in o ma ion om
he logs. The main p oblem wi h logs is ha hey sha e a sha ed o ma , bu he
message i sel does no ha e a common o m, so each message is di e en . We i s
hough ha i would be in e es ing o know which applica ions c ea ed a log en y
wi h a le el abo e Wa ning, because ha could e eal applica ions wi h bugs in he
code o applica ions ha access speci ic p o ec ed i ems. In he end, we decided ha
he bes way was o check o speci ic pa e ns inside hose messages, and ha ’s
how we came up wi h he idea o he a ge elemen s.
84
- We also aced some issues e u ning he esul om LogAnalyze Connec o
LogAnalyze F agmen Applica ions, as i uns on a di e en h ead. We managed his
by c ea ing a delega e unc ion in he UI h ead and passing i o
LogAnalyze Connec . This unc ion ac s as an asynch onous esponse ha is called
wi hin AsyncTask’s onPos Execu e() me hod, which is called when all p ocessing
has al eady been done.
5.3 Pe mission Analysis Implemen a ion
Ano he aspec ha mus be conside ed in he de elopmen o a malwa e analysis ool is he
s udy o he ele ance o he pe missions eques ed by each applica ion. Pe missions play a
e y impo an ole when analyzing malwa e as hey help suppo use p i acy by p o ec ing
access o es ic ed da a and es ic ed ac ions om malicious pu poses [55]. This sec ion
goes h ough he mo i a ions behind pe o ming his assessmen and explains all he de ails
and s eps ollowed du ing he implemen a ion o he pe mission analysis.
The pe missions de e mine wha is allowed o be done by an app. In o de o pe o m a mo e
comp ehensi e and elabo a e malwa e s udy, he eam has concluded ha a pe mission
analysis would make a solid suppo ing ea u e o ou And oid Malwa e Analyze App. To
ca y ou an analysis o his s yle, he main hing is o emain neu al and always ely on
objec i e ac s o achie e he mos accu a e esul possible in he pe mission assessmen .
The ac o ul illing hese condi ions de e mines he igo and p ecision o he analysis.
The basis and wha we a e ying o e alua e in his analysis a e he pe missions eques ed
by he applica ion, which can be ound inside he And oidMani es .xml ile [24] unde he
<uses-pe mission /> ag [88]. The ollowing sec ions desc ibe how hese pe missions ha e
been handled and analyzed.
5.3.1 Da ase o pe missions
Be o e s a ing wi h he analysis i is essen ial o c ea e a da ase ha collec s all he exis ing
pe missions and in o ma ion abou hem. The aim o ha ing his lis is o know he ins alled
apps pe missions and o classi y hem acco ding o he domain ha hey belong o and hei
le el o dange .
Fo his wo k, he eam conside s ha he bes implemen a ion o he pe mission da ase is
o ha e a da abase o med by wo ables, one wi h he pe missions in o ma ion and ano he
wi h he g oups in o ma ion (see Figu e 55).
85

Figu e 55: Pe missions Da ase Rela ional Model
The able Pe missions (Table 6) con ains all he ele an in o ma ion ega ding And oid
pe missions. As i conce ns he iden i ica ion o his able, he Pe missions ID ield is he
cons an alue o he pe mission which is s o ed in he <uses-pe missions/> ag o he
And oidManid es .xml.
The aim o he sco e ield is o g ade he pe missions acco ding o how exposed he
in o ma ion is as well as he scope o es ic ed ac ions you can pe o m when he sys em
g an s you ha pe mission. The alues aken by he sco es ange om 0 o 6 and hey a e
explained in he 5.3.2 sec ion.
Table 6: F agmen o he able Pe missions
The able Domains (Table 7) con ains all he ele an in o ma ion ega ding he di e en
g oups which he pe missions belong o. This able jus s o es he iden i ica ion o he g oup
and an alias and a desc ip ion o acili a e he unde s anding o he domain o he use and
show him a a high le el wha unc ionali ies o he de ice a e used by he app.
86
Table 7: F agmen o he able Domains
In o de o ge a pe missions da ase as comple e as possible, he eam elies on he
pe missions API e e ence page [79] om he And oid o De elope s o icial si e. This page
p o ides de elope s wi h a ull lis o pe missions ecognized by And oid. In Figu e 56 all he
in o ma ion used in he pe missions da ase is highligh ed.
87
[79] Figu e 56: And oid De elope s, API Re e ence Page
1 - Pe mission ID, 2 - Pe mission Sco e, 3 - Pe mission Desc ip ion, 4 - Pe mission Alias, 5 - API le el (no used)
As addi ional in o ma ion, he eam has also used he da ase o pe missions o m he sou ce
and oidpe missions.com [80] which comple es he lis p o ided by And oid De elope s.
Fu he mo e, his si e ela es he pe missions wi h hei domain and gi es an explana ion. In
Figu e 57 all he in o ma ion used in he domains da ase is highligh ed.
88
[80] Figu e 57: and oidpe missions.com
1 - Domain ID, 2 - Domain Alias, 3 - Domain Desc ip ion, 4 - Pe mission ID, 5 - Pe mission Desc ip ion
5.3.2 Classi ica ion o pe missions
E en hough And oid al eady classi ies i s pe missions acco ding o he scope o es ic ed
da a and ac ions ha an app can access and pe o m when he sys em g an s ha
pe mission [9], he eam decides o adop a mo e de ailed way o labelling he pe missions.
In Table 8 i can be seen his adap a ion. The column Sco e is he alue s o ed in he
da abase ha alloca es he pe mission scope and he column Pe mission Class is he
pe mission classi ica ion acco ding o And oid.
Table 8: Explana o y able o he di e en le els assigned o he pe missions
89
pe missions is 10 imes he a e age numbe o pe missions acco ding o he
ca ego y.
This way, o an applica ion o ca ego y Games (ideal = 5), depending on he numbe
o pe missions, he Quan i a i e Sco e is highe o lowe :
5. So he lis o apps
The nex and inal s ep o he pe mission analyze is o so in o a lis he ins alled
apps acco ding o hei Final Sco e. This sco e is compu ed as he lowes alue
be ween he Quan i a i e and Quali a i e sco es.
5.3.4 Resul s
Once he analysis o pe missions is done, he esul s a e shown o he use . These esul s
consis on:
- The a e age o he Final Sco es (Figu e 61).
Figu e 61: Pe mission Analysis Resul s iew
96

- Lis o he ins alled applica ions ha eques o bidden pe missions (Figu e 62 and
Figu e 63).
Figu e 62: Apps ha eques special pe missions
[91] Figu e 63: Ap oide eques s “Ins all Packages,
which is a special pe mission
- Lis o ins alled applica ions ha eques dange ous pe missions (Figu e 64 and 65).
Figu e 64: Apps ha eques dange ous pe missions
97
Figu e 65: Adobe Scan eques s se e al dange ous pe missions
- Lis o ins alled applica ions ha eques dep eca ed pe missions (Figu e 66 and 67).
Figu e 66: Apps ha eques dep eca ed pe missions
Figu e 67: Ins ag am eques s wo dep eca ed
pe missions:
“Unins all_Sho cu ” (see Figu e 68) and
“Use_Finge p in ” (see Figu e 69)
98
[98] Figu e 68: Unins all Sho cu is a dep eca ed pe mission
[92] Figu e 69: Use Finge p in is a dep eca ed pe mission
- Lis o ins alled applica ions ha eques unknown pe missions (Figu e 70 and 71).
Figu e 70: Apps ha eques unknown pe missions
Figu e 71: Ins ag am eques s an unknown
pe mission: “Billing”
99
- Lis o ins alled applica ions so ed by Final Sco e (Figu e 72).
Figu e 72: Apps so ed by Final Sco e
100
6. And oid Malwa e Analyze App
This chap e shows he s uc u e o he applica ion de eloped as a esul o he wo k ca ied
ou in his p ojec . This chap e p o ides a de ailed explana ion o each layou o he
applica ion and he in e ac ion o he use wi h i . Th ough his chap e we will e e o he
applica ion de eloped as AMA, (And oid Malwa e Analyze ). We ha e also designed a logo
as shown in Figu e 73.
Figu e 73: Applica ion Logo
6.1 F agmen Menu
The AMA applica ion has been s uc u ed h ough he use o F agmen s. And oid F agmen s
ep esen a eusable po ion o he app's UI ha de ines and manages i s own layou and a e
a ached o an Ac i i y. As shown in Figu e 74 and 75, AMA consis s o 8 main agmen s,
accessible by a agmen menu, which can be e ealed by clicking on he op le h ee ba
icon. The main agmen s a e:
-Home: En y poin o he applica ion. Shows some s a ing in o ma ion o he analysis
pe o med.
-Apps In o ma ion: Lis s all he applica ions ins alled on he de ice and when one o
hem is selec ed displays in o ma ion abou i .
-Signa u e Analyze : F agmen in cha ge o ca ying ou he signa u e analysis.
-Pe mission Analyze : F agmen in cha ge o ca ying ou he pe mission analysis.
-Log Analyze : F agmen in cha ge o ca ying ou he log analysis.
-P e ious Resul s: Displays he esul s o p e iously pe o med analysis.
-Se e Se ings: Handles he IPs used o es ablish he connec ion o he se e .
-Abou Us: Shows some in o ma ion abou he p ojec and he h ee analyses.
101

Figu e 74: And oid p ojec o ganisa ion
Figu e 75: F agmen menu
102
6.2 Home F agmen
The Home F agmen , shown in Figu e 76, is he isual en y poin o he applica ion. I
accesses he P e Resul s da abase o in o m he use abou he las analysis pe o med,
displaying he analysis ype as well as he da e and ime. I no analysis is pe o med, he ex
“None” is displayed. Below his in o ma ion, he applica ion shows o he use all he apps
whose hash has no been analyzed ye . We ha e implemen ed his unc ionali y because we
ha e hough i would be highly ecommended o encou age he use o analyze all he
applica ions ins alled on his de ice. I all he apps had been analyzed, he ex “None” is
displayed.
Figu e 76: Home F agmen
103
6.3 Apps In o ma ion F agmen
The Apps In o ma ion F agmen (Figu e 77) shows he use a lis o he ins alled
applica ions. By clicking on a speci ic app, he use ge s he di e en in o ma ion ha he
package p o ides, he applica ion sco es, he eques ed pe missions and a lis o he
domains ha he app has access o.
Figu e 77: App In o ma ion F agmen
The applica ion sco es a e he quan i y and quali y esul s o he assessmen pe o med by
he pe mission analyze . The o e all sco e o he applica ion is he lowes alue o bo h
sco es, Adobe Scan would ha e an o e all sco e o 3.82 whe eas Among Us would ha e an
8.75 (Figu e 78). As seen p e iously his is based on he pe missions eques ed by he
applica ions. O he ele an in o ma ion ha he package p o ides is he package name, he
pa h and he ca ego iza ion o he app.
Nex , he agmen shows all he domains o he app, ha is, all he pe mission g oups ha
he applica ion eques s. They a e displayed in he o m o an expandable lis ha , when
clicked, he pe missions ha belong o ha g oup appea . I also displays o he use a b ie
desc ip ion o ha domain (see Figu e 79).
104
Figu e 78: App De ails F agmen (Sco es and Package In o ma ion)
Figu e 79: Apps De ails F agmen (Domains ha Adobe Scan has access o)
105
Finally, a he bo om, he e is a lis ha con ains he ins alled applica ions so ed by inal
sco e (Figu e 90). I he use decides o click in one o he apps, he applica ion is edi ec ed
o he Pe mission Lis F agmen (Figu e 80).
Figu e 88: Pe missions Analyze F agmen
Figu e 89: Pe missions Analyze
F agmen
Figu e 90: Top and Bo om o he applica ions lis so ed by sco es
112

6.6 Log Analyze F agmen
Fi s ly, he Log Analyze F agmen le s he use decide i he apps she/he wan s o analyze
a e use applica ions (applica ions ins alled by him, such as Wha sapp, Ins ag am,
And oidMalwa eAnalyze , e c) o unc ionali ies (p e-ins alled apps, such as Came a, Gmail,
e c) as shown in Figu e 91.
Figu e 91: Log Analyze F agmen
Depending on he decision he use has made, he lis o applica ions ha a e displayed
changes acco dingly, as shown in Figu e 92. I he connec ion o he se e has been
co ec ly se and selec ed in he Se e Se ings F agmen (see sec ion 6.8), an ale
message as he one in Figu e 92 is displayed, elling he use o selec he apps o moni o .
113
Figu e 92: Log Analyze F agmen - Applica ions
Howe e , i no add ess has been co ec ly se up in he Se e Se ings F agmen , he ale
shows an e o message elling he use o add a connec ion in he Se e Se ings sec ion
(Figu e 93).
Figu e 93: Log Analyze F agmen - No connec ions
114
As Figu e 94 displays, a e he p e ious s ep he use can selec he applica ions ha wan s
o analyze. I none is selec ed, all o hem a e analyzed, which will consume mo e ime
compa ed o selec ing some applica ions. The use can also inpu some keywo ds sepa a ed
by commas, which a e used la e on du ing he analysis (see sec ion 5.2.2 o mo e
in o ma ion). When he use wan s o s a he analysis, she/he needs o p ess he S a
Analysis bu on. Du ing his ime, he connec ion is es ablished and he applica ion begins o
send logs o he se e (Figu e 94).
Figu e 94: Log Analyze F agmen - Analysis S a ed
The use is able o see i some hing goes w ong h ough he ale messages ha appea on
he sc een (Figu e 95). Since he de ice is now being analyzed, he use can in e ac wi h
he applica ion she/he wan s o analyze, so ha AMA ge s i s logs. As i is a be a e sion, we
ecommend accessing he And oidMalwa eAnalyze once in a while, because i can
some imes ge s uck i i is kep in he backg ound o oo long.
115
Figu e 95: Log Analyze F agmen - Connec ion E o
A e some ime, he use can p ess he S op Analysis bu on o s op he connec ion and
e ie e he esul s. As shown in Figu e 96, he esul i s in oduces he analyzed elemen s.
Then i shows he apps analyzed, which can be expanded o show he a ge elemen s hey
accessed. Some o hem may no be expandable i no a ge elemen was ecognized. The
numbe displayed indica es how many imes ha elemen appea ed in a log en y. A e ha ,
he keywo ds analyzed a e shown, which can also be expanded o display which applica ion
accessed hem. Las ly, he use can see i he applica ions ha e he pe missions needed o
access hose a ge elemen s.
116
Figu e 96: Log Analyze F agmen - Show Resul
117

6.7 P e ious Resul s F agmen
This agmen displays all he log and signa u e analyses ha ha e been made p e iously.
This is a simple way o keep ack o wha is happening on you mobile phone wi h he
applica ions ins alled. In addi ion, analysis o e ime o his da a could indica e unwan ed
ope a ion o ins alled apps; o example, an app accessing an i em oo much e en hough
he use is no awa e o ha ing ha app in use (a leas in he o eg ound). Howe e , we
ha e decided ha he pe mission analysis should no be sa ed, since i would ake up a lo
o space due o he amoun o in o ma ion and because i is mo e in e es ing o calcula e i
each ime. In sec ion 5.2.1 he con en s o he P e Resul s able a e shown (Table 4).
As shown in Figu e 97, each elemen o he lis o analyses shows he ype o analysis and
he day and ime. They a e o de ed by bo h he da e and ime, in descending o de .
Figu e 97: P e ious Resul s F agmen
I one o he esul s is selec ed, he speci ic da a is displayed. Figu e 98 displays he esul s
o he signa u e analysis and log analysis ha ha e been selec ed.
118
Figu e 98: P e ious Resul Selec ed
6.8 Se e Se ings F agmen
In his agmen communica ion wi h he se e is con igu ed. The use can se he IP and
Po numbe s ha a e going o be used in he Log Analyze o connec ing o he se e .
They a e s o ed using Sha edP e e ences. The use can selec each o he sa ed
connec ions, which is he one used when connec ing o he se e . As shown in Figu e 99,
he e a e wo bu ons: he Add bu on and he Dele e bu on.
I he Add bu on is p essed, a popup appea s, asking he use o inpu he IP and Po
numbe in he o ma IP:Po (Figu e 100). I he use p esses he Cancel bu on, he
ope a ion is disca ded.
119
Figu e 99: Se e Se ings F agmen
Figu e 100: Se e Se ings F agmen - Add IP:Po
I he use p esses he Add bu on, he use ’s inpu is pa sed. In case some hing is w ong
wi h he IP o Po numbe s (i.e. i i is no a numbe , one o he by es o he IP is in e io o 0
o supe io o 255, e c) he connec ion is no added and an ale message ells he use wha
wen w ong, as shown in Figu e 101.
I he Dele e bu on is p essed, he selec ed add ess is dele ed. Once i has been emo ed,
an ale message no i ies he use o he dele ion (Figu e 102).
120
Figu e 101: Se e Se ings F agmen - W ong Inpu
Ale
Figu e 102: Se e Se ings F agmen - Dele e
add ess
121
Figu e 108: Pe mission manage - TikTok
-Figu e 109 displays he in o ma ion ob ained om he Apps In o ma ion
F agmen o And oidMalwa eAnalyze . I can be seen ha he ca ego y in
which his applica ion alls in o is Social & Communica ion, which is co ec o
he app's unc ionali ies. The package name o he applica ion is
com.zhiliaoapp.musically, which seems o be qui e suspicious since he
cu en name is TikTok. Howe e , i migh be legi ima e because Musically is
he o me name o he app.
128

Figu e 109: Apps In o ma ion - TikTok
-Dicciona io de la Lengua Española (DLE)
- DLE is he o icial applica ion ha he Real Academia Española (RAE) and he
Asociación de Academias de la Lengua Española (ASALE) made a ailable o
consul he Spanish Dic iona y.
- I s main unc ionali y is he sea ch o he meaning o speci ic wo ds in he
dic iona y, being able o apply di e en il e s. I also has some links ha allow
he use o ob ain in o ma ion abou he app and he en i ies behind i s
de elopmen .
-Figu e 110 shows he pe missions equi ed by he app and whe he hey ha e
been g an ed o denied. In his case, i has no equi ed any.
129
Figu e 110: Pe mission manage - DLE
-Figu e 111 displays he in o ma ion ob ained om he Apps In o ma ion
F agmen o And oidMalwa eAnalyze . I can be seen ha he ca ego y in
which his applica ion alls in o is P oduc i i y, which is co ec o he app's
unc ionali ies. Also, he package name o he applica ion is es. ae.dle, which
seems o be legi ima e.
130
Figu e 111: Apps In o ma ion - DLE
- Nasip Kisme degilmis
- I is a supposed TV emo e con ol ha ac ually does no wo k as a emo e
con ol, bu as a Clicke .
-Figu e 112 displays he in o ma ion ob ained om he Apps In o ma ion
F agmen o And oidMalwa eAnalyze . I can be seen ha he ca ego y in
which his applica ion alls in o is Unde ined, which is al eady suspicious.
Also, he package name o he applica ion is com.ndsonken ucki.kuma, which
also seems suspicious.
131
Figu e 112: Apps In o ma ion - Nasip Kisme degilmis
- Sma ca dSe ice
- I is a malwa e ha ob ains he phone numbe , MAC add ess, de ice usage
and eco ds SMS and oice con e sa ions.
7.2 Pe mission Analysis
In his sec ion, he pe mission analyze will examine he apps men ioned in he p e ious
sec ion. Based on he esul , he pe missions eques ed will be discussed o see i hei use
is legi ima e o i i con adic s i s alleged unc ionali y.
-Ins ag am
-Figu e 113 shows he o e all sco e ob ained by analyzing he app wi h he
pe mission analyze . As seen, i sco ed a 4.75 ou o 10, which is a low sco e.
This is due, as we will la e see, o i s huge numbe o pe missions and he
high a io o dange ous pe missions.
Figu e 113: O e all Sco e - Ins ag am
- Accessing he esul o he analysis, shown in Figu e 114, i can be seen ha
he applica ion eques s se e al ypes o pe missions. Speci ically, his app
eques s 15 dange ous pe missions, 2 dep eca ed, 14 no mal and 11
132
unknown, which gi es i a a ing o 5.8 ou o 10 in quali y. In e ms o quan i y,
i eques s 42 pe missions in o al, hence i has a 4.75. O all o hem, he
mos no able pe missions a e hose ela ed o he Came a, Accoun s,
Con ac s, Loca ion, Mic ophone, Phone, S o age and Billing, which make
sense wi hin all he unc ionali ies ha he app o e s. All in all, i can be
app ecia ed ha his applica ion eques s a g ea numbe o pe missions,
which could be dange ous in case he applica ion we e malicious. In his
case, his applica ion is he legi ima e one, and hose pe missions a e needed
o pe o m se e al o he unc ionali ies o he app.
Figu e 114: Pe mission Analyze - Ins ag am
-Wha sApp
-Figu e 115 shows he o e all sco e ob ained by analyzing he app wi h he
pe mission analyze . As seen, i sco ed a 2.5 ou o 10, which is a e y low
sco e. This is due, as we will la e see, o i s la ge numbe o pe missions and
he poo balance o pe mission ypes acco ding o he secu i y le els.
Figu e 115: O e all Sco e - Wha sapp
133

- Accessing he esul o he analysis, shown in Figu e 116, i can be seen ha
he applica ion eques s se e al ypes o pe missions. Speci ically, his app
eques s 22 dange ous pe missions, 3 dep eca ed, 1 signa u e, 20 no mal
and 14 unknown, which gi es i a a ing o 5.73 ou o 10 in quali y. In e ms o
quan i y, i eques s 60 pe missions in o al, hence i has a 2.5. O all o hem,
he mos no able pe missions a e hose ela ed o he Came a, Accoun s,
Con ac s, Loca ion, Mic ophone, Phone, SMS, Read Call Log, NFC,
Biome ic, S o age and Billing, which make sense wi hin all he unc ionali ies
ha he app o e s. All in all, i can be app ecia ed ha his applica ion
eques s a g ea numbe o pe missions, which could be dange ous in case
he applica ion we e malicious. In his case, his applica ion is he legi ima e
one, and hose pe missions a e needed o pe o m se e al o he
unc ionali ies o he app.
Figu e 116: Pe mission Analyze - Wha sApp
-TikTok
-Figu e 117 shows he o e all sco e ob ained by analyzing he app wi h he
pe mission analyze . As seen, i sco ed a 2.25 ou o 10, which is a e y low
sco e. This is due, as we will la e see, o i s huge numbe o pe missions and
he high a io o unknown and dange ous pe missions.
134
Figu e 117: O e all Sco e - TikTok
- Accessing he esul o he analysis, shown in Figu e 118, i can be seen ha
he applica ion eques s se e al ypes o pe missions. Speci ically, his app
eques s 9 dange ous pe missions, 2 dep eca ed, 12 no mal and 39
unknown, which gi es i a a ing o 5.08 ou o 10 in quali y. In e ms o
quan i y, i eques s 62 pe missions in o al, hence i has a 2.25. O all o
hem, he mos no able pe missions a e hose ela ed o he Came a, Audio,
Con ac s, Mic ophone, Phone, S o age and Billing, which make sense wi hin
all he unc ionali ies ha he app o e s. Wha is qui e a e is he g ea
amoun o unknown pe missions ha appa en ly eques o ead/w i e he
sys em se ings. Apa om ha , i can be app ecia ed ha his applica ion
eques s a g ea numbe o pe missions, which could be dange ous in case
he applica ion we e malicious. In his case, his applica ion is he legi ima e
one, and hose pe missions a e needed o pe o m se e al o he
unc ionali ies o he app.
Figu e 118: Pe mission Analyze - TikTok
-Dicciona io de la Lengua Española (DLE)
-Figu e 119 shows he o e all sco e ob ained by analyzing he app wi h he
pe mission analyze . As seen, i sco ed a 9.6 ou o 10, which is a e y high
135
sco e. This is due, as we will la e see, o i s impeccable quali y and quan i y
o pe missions.
Figu e 119: O e all Sco e - DLE
- Accessing he esul o he analysis, shown in Figu e 120, i can be seen ha
he applica ion only eques s no mal pe missions, which gi es i a a ing o 10
ou o 10 in quali y. In e ms o quan i y, i only eques s wo pe missions,
hence i has a 9.6. Wi hin he unc ionali ies o he applica ion, i makes sense
ha i uses he In e ne and Fo eg ound Se ice pe missions. All in all, i can
be app ecia ed ha his applica ion is highly eliable, as i is a om wha
could be conside ed a dange ous o suspicious applica ion.
Figu e 120: Pe mission Analyze - DLE
-Nasip Kisme degilmis
-Figu e 121 shows he o e all sco e ob ained by analyzing he app wi h he
pe mission analyze . As seen, i sco ed a 8.8 ou o 10, which is a e y high
sco e. This is due, as we will la e see, o he good quali y and quan i y o
pe missions.
136
Figu e 121: O e all Sco e - Nasip Kisme degilmis
- Accessing he esul o he analysis, shown in Figu e 122, i can be seen ha
he applica ion only eques s no mal and signa u e pe missions, which gi es i
a a ing o 10 ou o 10 in quali y. In e ms o quan i y, i only eques s six
pe missions, hence i has a 8.8. Wi hin he unc ionali ies o he applica ion, i
should eques di e en pe missions, which is suspicious. All in all, i can be
app ecia ed ha his applica ion does no eques dange ous pe missions, bu
i is suspicious ha i does no eques he pe missions i should need o keep
up wi h i s unc ionali y.
Figu e 122: Pe mission Analyze - DLE
-Sma ca dSe ice
-Figu e 123 shows he o e all sco e ob ained by analyzing he app wi h he
pe mission analyze . As seen, i sco ed a 4.13 ou o 10, which is a e y low
sco e. This is due, as we will la e see, o he huge numbe o dange ous
pe missions i eques s.
Figu e 123: O e all Sco e - Sma ca dSe ice
137
Figu e 136: Signa u e Analyze - Sma ca dSe ice
7.4 Heu is ic Log Analysis
In his sec ion, he log analyze will analyze he apps men ioned in sec ion 7.1. The esul will
hen be discussed.
-Ins ag am
- While he log analyze was collec ing he logs, we accessed Ins ag am and
in e ac ed a bi wi h he main page, looking a ecen pos s and some s o ies.
We hen ied o ake a pho o, o which i asked o pe mission o access he
came a which we decided no o g an . A e ha , we accessed Di ec s and
ied o send an audio o a con ac , o which i asked o pe mission o access
he mic ophone which we decided no o g an . Finally, we saw some o he
pos s and Reels ha appea ed in he Explo e ab and accessed a speci ic
accoun a e sea ching o i in he sea ch ba .
- A e we we e done, we s opped he analysis and he esul s we e ob ained
(Figu e 137). I can be seen ha du ing he execu ion o he analysis, ou
applica ions we e unning: Ins ag am, And oidMalwa eAnalyze , Wha sApp
and S icke s. Wha sApp p obably had some se ice unning in he
backg ound, so i is no su p ising o see ha i gene a ed some logs. As o
he S icke s app, pe haps i would be in e es ing o he use o analyze i
sepa a ely since i should no be unning, bu ha is no he scope o his
144

analysis. Fou a ge elemen s ha e been de ec ed du ing he execu ion o
Ins ag am: Came a, Messaging, Mic ophone and In e ne . Since he e a e a
low numbe o logs ela ed o each a ge elemen , he use should no wo y,
as hey a e p obably alse posi i es o , ha ing been asked o g an
pe missions o he came a and mic ophone, i may ha e gene a ed some logs
ela ed o hem. Fo his eason, inding ha he app has no access o he
came a and mic ophone should no be ala ming.
Figu e 137: Log Analyze - DLE
- Reading he logs ha we e s o ed on he se e , we saw ha Came a was
igge ed when he came a ac i i y was loaded: “06-15 17:07:55.469
1375 8410 windowmanage : adding window{a67672 u0
khcd.4zp. eel_compose _came a} o window{620175e u0
com.ins ag am.and oid/com.ins ag am.mainac i i y.mainac
i i y}”. Rega ding he Mic ophone, he logs we e gene a ed when we we e
p omp ed o g an he pe mission: “06-15 17:08:03.273 31338 31338
g an pe missionsac i i y: logged bu ons p esen ed and
clicked
pe missiong oupname=and oid.pe mission-g oup.mic ophone
uid=10278 package=com.ins ag am.and oid
p esen edbu ons=25 clickedbu on=8”
145
- F om his analysis we can conclude ha his applica ion pe o ms he
p omised unc ionali ies and does no a emp o do any hing ou side o i s
supposed beha iou .
-Wha sApp
- While he log analyze was collec ing he logs, we accessed a Wha sApp
con e sa ion o ake a pho o and send i . We also ac i a ed he mic ophone
and sen a documen s o ed in he de ice. Finally, we made a ideo call wi h
ano he con ac .
- A e we we e done, we s opped he analysis and he esul s we e ob ained
(Figu e 138). I can be seen ha du ing he execu ion o he analysis, h ee
applica ions we e unning: Wha sApp, And oidMalwa eAnalyze and
Ins ag am. Ins ag am p obably had some se ice unning in he backg ound,
so i is no su p ising o see ha i gene a ed some logs. Fi e a ge elemen s
ha e been de ec ed du ing he execu ion o Ins ag am: Came a, Mic ophone,
Messaging, SDca d and In e ne . As he numbe o logs ega ding he
mic ophone and came a, hei numbe s a e high enough o be su e ha hose
ha e been accessed.
Figu e 138: Log Analyze - Wha sApp
- Reading he logs ha we e s o ed on he se e , we saw ha he Came a logs
we e gene a ed when he came a was opened and when he came a ac i i y
146
was called. As an example, we show his log: “06-15 19:33:12.549
14324 15103 i came a : open came a: 1, package name:
com.wha sapp”. Rega ding he SDca d, he logs we e gene a ed when we
sea ched he locally s o ed documen s o send one o hem: “06-15
19:33:12.444 14324 14324 w com.wha sapp: ype=1400
audi (0.0:10590): a c: g an ed { ge a } o pid=14324
name="/" de ="sdca d s" ino=11048
scon ex =u: :un us ed_app:s0:c147,c256,c512,c768
con ex =u:objec _ :sdca d s:s0 class= ilesys em”.
- F om his analysis we can conclude ha his applica ion pe o ms he
p omised unc ionali ies and does no a emp o do any hing ou side o i s
supposed beha iou .
-TikTok
- While he log analyze was collec ing he logs, we accessed TikTok and
in e ac ed a bi wi h he main page, looking a ecen pos s. We hen eco ded
a ideo, o which i asked o pe mission o access he came a which we
decided o g an .
- A e we we e done, we s opped he analysis and he esul s we e ob ained
(Figu e 139). I can be seen ha du ing he execu ion o he analysis, jus i e
applica ions we e unning: TikTok, And oidMalwa eAnalyze , Zi y, Wible and
Ins ag am. Rega ding Ins ag am, i p obably had some se ice unning in he
backg ound, so i is no su p ising o see ha i gene a ed some logs. As o
Zi y and Wible apps, pe haps i would be in e es ing o he use o analyze i
sepa a ely since i should no be unning, bu ha is no he scope o his
analysis. Fou a ge elemen s ha e been de ec ed du ing he execu ion o
TikTok: Came a, Messaging, Loca ion and SDCa d. As i conce ns he
Came a, i makes sense o ind logs because du ing he analysis i has been
used. Rega ding he es o he logs, since he e a e a low numbe o logs
ela ed o each a ge elemen , he use should no wo y as hey a e p obably
alse posi i es. Fo his eason, inding ha he app has no access o he
loca ion should no be ala ming.
147
Figu e 139: Log Analyze - TikTok
- Reading he logs ha we e s o ed on he se e , we saw ha Came a was
igge ed when he came a was opened: “06-15 19:14:15.738 31375
32062 i came amanage : open came a: 1, package name:
com.zhiliaoapp.musically”.
- As ega ds he SDca d, he logs we e: “06-15 19:14:57.411 31375
31375 w escoioboundex: ype=1400 audi (0.0:7330975):
a c: g an ed { ead open } o pid=31375
pa h="/s o age/emula ed/0/and oid/da a/com.zhiliaoapp.mu
sically/cache/pic u e/ esco_cache/ 2.ols100.1/35/eq_mss
q_qyzox xqya kx5b5wjw.cn " de ="sdca d s" ino=254257
scon ex =u: :un us ed_app:s0:c99,c257,c512,c768
con ex =u:objec _ :sdca d s:s0 class= ile”
- As o he Loca ion, he logs ound we e “06-15 19:14:12.993 2089
2467 i pg_ash : unp_gps:com.zhiliaoapp.musically
uid:10355 esul : ue”.
- Finally, ega ding o he SDCa d, he logs ound we e “06-15
19:14:12.991 2009 5099 d assis an se ice-1030200:
handlemessage app swi ch
148
ompackage:com.huawei.and oid.launche ,
opackage:com.zhiliaoapp.musically”.
- F om his analysis we can conclude ha his applica ion pe o ms he
p omised unc ionali ies and does no a emp o do any hing ou side o i s
supposed beha iou .
-Dicciona io de la Lengua Española (DLE)
- While he log analyze was collec ing he logs, we accessed he DLE
applica ion and did a couple o sea ches o he meanings o di e en wo ds.
We also accessed wo o he links in he applica ion, which edi ec o he
de aul b owse o display in o ma ion om he RAE and he app.
- A e we we e done, we s opped he analysis and he esul s we e ob ained
(Figu e 140). I can be seen ha du ing he execu ion o he analysis, h ee
applica ions we e unning: DLE, And oidMalwa eAnalyze and Fi e ox Focus.
Fi e ox Focus appea s because he DLE applica ion links edi ec ed he use
o he de aul b owse , which in he case o he de ice on which we es ed he
analysis, was Fi e ox Focus. Two a ge elemen s ha e been de ec ed du ing
he execu ion o he DLE applica ion: Messaging and S o age. Since he e a e
a low numbe o logs ela ed o each a ge elemen , he use should no
wo y, as hey a e p obably alse posi i es. Fo his eason, inding ha he
app has no access o he s o age should no be ala ming.
149

Figu e 140: Log Analyze - DLE
- Reading he logs ha we e s o ed on he se e , we ealized ha Messaging
was igge ed because when swi ching om he DLE applica ion o Fi e ox
Focus and back, se e al logs like “06-13 17:40:41.598 1975 4130
d assis an se ice-1030200: handlemessage app swi ch
ompackage:com.huawei.and oid.launche ,
opackage:es. ae.dle” we e gene a ed, which is de ec ed as
Messaging by a alse posi i e. S o age has been de ec ed because wo logs
we e c ea ed in his o m “06-13 17:40:31.424 13742 13760 i
hwapicachemange ex: apicache pa h=/s o age/emula ed/0
s a e=moun ed key=es. ae.dle#10122#”.
- F om his analysis we can conclude ha his applica ion pe o ms he
p omised unc ionali ies and does no a emp o do any hing ou side o i s
supposed beha iou .
-Nasip Kisme degilmis and Sma ca dSe ice
- Due o hei malicious na u e, i is necessa y o pe o m an analysis o hese
wo applica ions in a secu e en i onmen such as a i ual machine. When
ying o pe o m he analysis, we ealized ha he applica ions c ashed each
ime hey we e opened, p obably because hey we e p og ammed o wo k in
150
an olde And oid e sion. Fo his eason, we we e unable o pe o m he log
analysis o hese applica ions.
151
8. Indi idual Wo k
This chap e summa ises he con ibu ions o each pa icipan in his p ojec , lis ing
e e y hing lea ned in he p ocess o ca ying i ou . The wo k has been ca ied ou join ly and
ai ly, di iding he wo k in o each o he poin s ha make i up. These a e he c yp og aphic
signa u es analysis, he analysis o logs and he analysis o pe missions.
8.1 Daniel Puen e A ibas
My wo k has had mo e weigh in he analysis o pe missions.
The beginning o my wo k consis ed o a global s udy o he me ada a con ained wi hin he
PackageIn o objec . In his way, I lea ned abou i s uses and cha ac e is ics o unde s and
how o ob ain he da a and say which ields we e he mos use ul and ele an o de elop ou
analysis.
Nex , I began he de elopmen o he Apps In o ma ion agmen and my i s app oach
o he logical and isual de elopmen o he applica ion consis ed in showing he lis o all he
ins alled applica ions, as well as he ele an in o ma ion o each one.
Once his was done, I con inued wi h he de elopmen o he agmen ha shows he de ails
and in o ma ion o each applica ion. Du ing his s age, I s a ed o wo k wi h he eques ed
pe missions and I saw he need o c ea e a iew dedica ed o he pe missions in o de o
classi y hem acco ding o he scope o es ic ed da a ha he apps can access, and he
scope o es ic ed ac ions ha apps can pe o m when he sys em g an s hem pe mission.
This way, be o e ge ing in o he pe missions analysis, I did a deep esea ch abou And oid
pe missions and lea ned how o decla e pe missions, whe e o decla e hem, how o access
hem and how o classi y hem acco ding o he domain which hey belong o and acco ding
o he le el o access hey eques o he de ice.
Subsequen ly, I buil a da ase composed o pe missions and pe mission g oups ou o
a ious sou ces wi h he objec i e o using i la e in pe missions analysis. The in e es ing
hing abou his da ase is ha i u ned ou o be e y comple e and e y use ul when i
comes o co ec ly classi ying he pe missions. A e all he in o ma ion had been collec ed,
he da ase in o ma ion was added as ables o he applica ion's SQLi e da abase.
Once I ob ained he necessa y knowledge abou And oid pe missions and ha ing c ea ed a
da ase ha s o es hem, I began o de elop he
Pe mission Analyze
agmen . To do his, I
came up wi h wo algo i hms ha assign wo di e en a ings in o de o e alua e
applica ions based on he pe missions hey eques . Ac ually, hese wo a ings p o ide wo
e y in e es ing iews on applica ions; a quan i a i e iew and ano he deepe and quali a i e
iew.
A e I ha e inished designing he logical and unc ional pa o he pe missions analyze , I
implemen ed i in he applica ion and I con inued de eloping he GUI o he analyze .
152
Rega ding his documen , I w o e he pe mission analyze sec ions o chap e s 4, 5, 6 and 9.
We also di ided chap e 3, sec ion 1.4 and he abs ac equally. I also w o e my
co esponding sec ion o chap e 8 and sec ions 1.1 and 1.3. Las ly, I was in cha ge o
co ec ly ci ing he bibliog aphy.
To conclude, my main con ibu ions in his p ojec ocus on he analysis o applica ions
me ada a, he esea ch o And oid pe missions and in ela ion o he ex ac ion o in o ma ion
om he apps and he analysis o pe missions, elabo a ing he unc ional and logic design as
well as hei use in e ace design and i s co esponding implemen a ion.
8.2 José Ignacio Dague e Ga ido
I c ea ed he local da abase wi h i s wo ables o malwa e signa u es and exis ing And oid
pe missions, which is essen ial o pe o m he s a ic analysis. I was in cha ge o c ea ing an
EC2 ins ance o AWS o be able o moni o he logs sen om an And oid de ice in o de o
elimina e he cos o doing i locally. I was also in cha ge o es ablishing a connec ion
be ween his ins ance and a TCP se e , which connec ed emo ely wi h he applica ion
de eloped in And oid S udio.
On he o he hand, I ha e pa icipa ed in he implemen a ion o he C yp og aphic Signa u e
Analysis agmen s, being one o he h ee undamen al pilla s ha make up he whole
applica ion.
Rega ding his documen , I w o e he signa u e analyze sec ions o chap e s 4, 5, 6 and 9.
We also di ided chap e 3, sec ion 1.4 and he abs ac equally. I also w o e my
co esponding sec ion o chap e 8 and sec ion 1.2. Alongside Ramón, we w o e chap e 2.
I ha e been able o unde s and no only he in e nal s uc u e o And oid applica ions bu
also how Linux is composed and he secu i y se ices and s uc u e ha And oid p o ides.
Despi e he lack o knowledge o he And oid S udio ool due o i s complex s uc u e and
use, hanks o his p ojec I ha e been able o deal wi h his ool and clea ly unde s and i s
usabili y, as well as disco e ing he bene i s and implemen a ions ha can be applied o he
de elopmen o And oid applica ions. As And oid S udio is p og ammed in Ja a, I ha e been
able o s eng hen my Ja a p og amming skills and become mo e luen .
I ha e also lea ned how o make connec ions be ween AWS ins ances and mobile de ices
h ough a TCP se e using socke s. I ha e ound Spa k S eaming eally exci ing, which is
esponsible o p ocessing da a in eal ime, in ou case he logs o an And oid de ice. I is
going o be help ul o implemen applica ions ha o e g ea e e iciency and pe o mance.
I is undoub edly he case ha we li e in an age when people a e unawa e o he secu i y
and s uc u e o hei mobile de ice and he isks in ol ed. Wha I ha e lea n is ha being
knowledgeable abou how applica ion pe missions wo k gi es you a ce ain basic
unde s anding o how o deal wi h malwa e.
153