HAL-Based Resource Manipulation Monitoring on AOSP

Joint Authors

Doan, Thien-Phuc
Park, Jungsoo
Jung, Souhwan

Source

Mobile Information Systems

Issue

Vol. 2020, Issue 2020 (31 Dec. 2020), pp.1-9, 9 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2020-12-02

Country of Publication

Egypt

No. of Pages

9

Main Subjects

Telecommunications Engineering

Abstract EN

Nowadays, Android malware uses sensitive APIs to manipulate an Android device’s resources frequently.

Conventional malware analysis uses hooking techniques to detect this harmful behavior.

However, this approach is facing many problems, such as low coverage rate and computational overhead.

To solve this problem, we proposed HALWatcher, an alternative technique to monitor resource manipulation on Android Open Source Project (AOSP).

By modifying Hardware Abstract Layer (HAL) resource accessing interfaces and their implementation, we can embed more monitoring functions at critical methods that are in charge of transferring data between the Hardware Driver and the Framework Layer.

Hence, HALWatcher provides a lightweight and high coverage rate system that can perform resource manipulation monitoring for Android OS.

In this paper, we prove that the hooking technique is limited in detecting resource manipulation attacks.

Besides that, HALWatcher shows an outperform detection rate with a low computational effort.

American Psychological Association (APA)

Doan, Thien-Phuc& Park, Jungsoo& Jung, Souhwan. 2020. HAL-Based Resource Manipulation Monitoring on AOSP. Mobile Information Systems،Vol. 2020, no. 2020, pp.1-9.
https://search.emarefa.net/detail/BIM-1192548

Modern Language Association (MLA)

Doan, Thien-Phuc…[et al.]. HAL-Based Resource Manipulation Monitoring on AOSP. Mobile Information Systems No. 2020 (2020), pp.1-9.
https://search.emarefa.net/detail/BIM-1192548

American Medical Association (AMA)

Doan, Thien-Phuc& Park, Jungsoo& Jung, Souhwan. HAL-Based Resource Manipulation Monitoring on AOSP. Mobile Information Systems. 2020. Vol. 2020, no. 2020, pp.1-9.
https://search.emarefa.net/detail/BIM-1192548

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1192548