Falcarin, P;
Venerba, M;
De Giorgi, M;
Sarro, F;
(2025)
Detection of Reverse Engineering Activities before the Attack.
In:
Proceedings 10th IEEE European Symposium on Security and Privacy Workshops Euro S and Pw 2025.
(pp. pp. 703-710).
IEEE: Venice, Italy.
Preview |
Text
Sarro_android.pdf - Accepted Version Download (566kB) | Preview |
Abstract
In typical cybersecurity scenarios, one aims at detecting attacks after the fact: in this work, we aim at applying an active defence, by detecting activities of attackers trying to analyse and reverse engineer the code of an Android app, before they will be able to perform an attack by tampering with the application code. We instrumented an app to collect various runtime data before and after deployment, in normal behaviour and under malicious analysis. We introduce the concept of partial execution paths as subsets of a program trace suddenly interrupted, as possible indicators of debugging activities. Such clues, along with system calls sequences and delays between them, stack information, and sensors data, are all data that are collected to help our system in deciding whether our app is under analysis and its device has to be considered compromised.
Type: | Proceedings paper |
---|---|
Title: | Detection of Reverse Engineering Activities before the Attack |
Event: | 2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) |
Dates: | 30 Jun 2025 - 4 Jul 2025 |
Open access status: | An open access version is available from UCL Discovery |
DOI: | 10.1109/EuroSPW67616.2025.00085 |
Publisher version: | https://doi.org/10.1109/eurospw67616.2025.00085 |
Language: | English |
Additional information: | This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions. |
Keywords: | Reverse Engineering, Mobile Apps Monitoring, Anomaly Detection, Software Protection, Anti-Piracy |
UCL classification: | UCL UCL > Provost and Vice Provost Offices > UCL BEAMS UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science |
URI: | https://discovery.ucl.ac.uk/id/eprint/10215473 |
Archive Staff Only
![]() |
View Item |