Do Bruto ao Brilho: Compactação Semântica com Preservação de Proveniência para Traços Dinâmicos de Malware Android
Resumo
A interpretação sequencial de logs de análise dinâmica de malware Android é custosa, pois a comparação entre execuções e verificação manual envolve correlação de dados massivos. Neste trabalho, apresenta-se SELENE, uma camada de organização semântica pós-coleta para gerar uma hierarquia auditável composta por eventos comportamentais, sinais de ciclo de vida target-aware, grafos de execução e pacotes de contexto com proveniência até o dado bruto. Foram avaliadas mais de 70 mil execuções (em Android 10 e 14), mostrando que a versão do Android altera a superfície comportamental observável e que pode-se alcançar compactação de mais de duas ordens de magnitude no tamanho dos traços e F1 médio de 0,983 frente a um oráculo independente.
Referências
Bhat, P., Behal, S., and Dutta, K. (2023). A system call-based android malware detection approach with homogeneous & heterogeneous ensemble machine learning. Computers & Security, 130:103277.
Botacin, M., Ceschin, F., Sun, R., Oliveira, D., and Gregio, A. (2021). Challenges and pitfalls in malware research. Computers & Security, 106:102287.
Burguera, I., Zurutuza, U., and Nadjm-Tehrani, S. (2011). Crowdroid: Behavior-based malware detection system for android. In Proceedings of the 1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, pages 15–26. ACM.
Canfora, G., Mercaldo, F., Visaggio, C. A., Martinelli, F., and Santone, D. (2015). Detecting android malware using sequences of system calls. In Proceedings of the 3rd International Workshop on Software Development Lifecycle for Mobile, pages 13–20. ACM.
Hassan, W. U., Noureddine, M. A., Datta, P., and Bates, A. (2020). Omegalog: High-fidelity attack investigation via transparent multi-layer log analysis. In Proceedings of the Network and Distributed System Security Symposium (NDSS).
He, P., Zhu, J., Zheng, Z., and Lyu, M. R. (2017). Drain: An online log parsing approach with fixed depth tree. In Proceedings of the IEEE International Conference on Web Services, pages 33–40.
Hurier, M., Suarez-Tangil, G., Dash, S. K., Bissyandé, T. F., Traon, Y. L., Klein, J., and Cavallaro, L. (2017). Euphony: Harmonious unification of cacophonous anti-virus vendor labels for android malware. In Proceedings of the 14th International Conference on Mining Software Repositories, pages 425–435. IEEE Press.
Júnior, C. T., Filho, D. F., Pincovscy, J., and Grégio, A. (2025). Artemis: Uma plataforma modular para execução, monitoração e investigação de aplicativos android suspeitos. In Anais do XXV Simpósio Brasileiro de Cibersegurança, pages 147–162, Porto Alegre, RS, Brasil. SBC.
Kumar, S., Mishra, D., Panda, B., and Shukla, S. K. (2023). Inviseal: A stealthy dynamic analysis framework for android systems. ACM Transactions on Privacy and Security, 26(3).
Li, T., Liu, X., Qiao, W., Zhu, X., Shen, Y., and Ma, J. (2024). T-trace: Efficiently constructing attack provenance graphs from syslogs and firewall logs against advanced persistent threats. IEEE Transactions on Dependable and Secure Computing, 21(3):1179–1195.
Liu, J., Zhu, J., He, S., He, P., Zheng, Z., and Lyu, M. R. (2019). Logzip: Extracting hidden structures via iterative clustering for log compression. In Proceedings of the 34th IEEE/ACM International Conference on Automated Software Engineering. IEEE/ACM.
Malik, S., Singh, N., and Tripathy, S. (2026). Semantic characterization of android malware through runtime system call analysis. Journal of Information Security and Applications, 98:104406.
Miranda, T. C., Gimenez, P.-F., Lalande, J.-F., Tong, V. V. T., and Wilke, P. (2022). Debiasing android malware datasets: How can i trust your results if your dataset is biased? IEEE Transactions on Information Forensics and Security, 17:2182–2197.
Pendlebury, F., Pierazzi, F., Jordaney, R., Kinder, J., and Cavallaro, L. (2018). Tesseract: Eliminating experimental bias in malware classification across space and time. arXiv preprint arXiv:1807.07838.
Quark Engine Project (2026). Quark-engine: Obfuscation-neglect android malware scoring system. [link]. Documentação oficial; ferramenta de análise estática e mapeamento de comportamentos em nível de API/Dalvik.
Suo, D., Xue, L., Huang, W., Tan, R., and Sun, G. (2025). Assessing the capability of android dynamic analysis tools to combat anti-runtime analysis techniques. arXiv preprint arXiv:2512.12551.
Sutter, T., Kehrer, T., Rennhard, M., Tellenbach, B., and Klein, J. (2024). Dynamic security analysis on android: A systematic literature review. IEEE Access, 12:57261–57287.
Tam, K., Feizollah, A., Anuar, N. B., Salleh, R., and Cavallaro, L. (2015). Copperdroid: Automatic reconstruction of android malware behaviors. In Proceedings of the Network and Distributed System Security Symposium (NDSS).
Veuskens, F., Cassee, N., and Demeyer, S. (2023). Valb: Variable-aware log benchmarking to evaluate log parsers for generated and real logs. In 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE).
Vyšniūnas, T., Čeponis, D., Goranin, N., and Čenys, A. (2024). Risk-based system-call sequence grouping method for malware intrusion detection. Electronics, 13(1):206.
Wei, J., Zhang, G., Wang, Y., Liu, Z., Zhu, Z., Chen, J., Sun, T., and Zhou, Q. (2021). On the feasibility of parser-based log compression in large-scale cloud systems. In 19th USENIX Conference on File and Storage Technologies, pages 249–264. USENIX Association.
Yan, L.-K. and Yin, H. (2012). Droidscope: Seamlessly reconstructing the os and dalvik semantic views for dynamic android malware analysis. In Proceedings of the 21st USENIX Security Symposium, pages 569–584.
Yu, S., Wu, Y., Xu, J., Fu, Y., Wang, N., Liu, M., Jiang, P., Zhang, X., Jia, T., He, P., and Li, Y. (2026). Delog: An efficient log compression framework with pattern signature synthesis. arXiv preprint arXiv:2601.15084.
