Android Container Malicious Code Analysis via Picocell Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Android malicious code analysis methods face inefficiencies due to the need for costly real device analysis, difficulty in automating pre- and post-analysis processes, and limited expandability and flexibility, especially when dealing with emulator bypass techniques and rooted environments.
Innovation Solution
A mobile device and system utilizing a container platform with a container agent generating Android containers for dynamic analysis, an analysis agent detecting kernel-related malicious code behavior, and a private picocell network for monitoring and managing Android containers, eliminating the need for hardware virtualization and enabling flexible and efficient analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real device with automation tools is used for malicious code analysis, then analysis reliability is improved, but productivity deteriorates due to degraded efficiency
Solution Approach 1:
The patent creates virtual copies (containers) of real mobile device environments that replicate hardware characteristics and sensor behaviors. These containers can be rapidly instantiated and destroyed, providing the reliability of real device analysis without the efficiency penalties of physical device handling. The containerization technology allows multiple isolated analysis environments to run simultaneously on shared hardware.
Solution Approach 2:
The system dynamically adjusts container parameters such as hardware identification strings, sensor response characteristics, and system configuration to match various real device profiles. This allows the same physical infrastructure to emulate multiple different device types, maintaining analysis reliability across diverse targets while improving productivity through parameter-based flexibility rather than physical reconfiguration.
2Productivity
If QEMU-based emulator is used for malicious code analysis, then productivity is improved through virtualization, but reliability deteriorates due to anti-emulator detection
Solution Approach 1:
The patent introduces containers as an intermediary layer between the malicious code and the virtualization infrastructure. The containers present themselves as genuine mobile operating system environments to the analyzed applications, hiding the underlying QEMU virtualization. This intermediary layer blocks anti-emulator detection mechanisms while maintaining the productivity benefits of virtualized execution.
Solution Approach 2:
The system extracts and isolates the critical characteristics of real mobile devices (hardware identifiers, sensor behaviors, system calls) into container configurations, separating these essential authenticity features from the virtualized execution environment. This extraction allows the container to present a realistic interface to malicious code while the underlying infrastructure remains virtualized for efficiency.
3Adaptability or versatility
If Intel-based Android version is used for malicious code analysis, then adaptability is improved for cross-platform analysis, but reliability deteriorates due to emulator environment detection
Solution Approach 1:
The container platform provides a universal execution environment that can be configured to emulate various Android device types and configurations. A single containerized system can adapt to analyze malicious code targeting different device profiles while maintaining the appearance of authentic hardware to the analyzed applications, thus achieving both cross-platform adaptability and analysis reliability.
Data Source
AI summary
A mobile device having a system for analyzing malicious code is provided. The mobile device includes a container agent generating at least one Android container executing Android malicious code for dynamic analysis in response to a request received from a cloud controller and checking a state of the at least one Android container, a Linux host, a hardware module containing an operating system (OS) for the Linux host, and an analysis agent detecting a problem occurring upon an operation of the Android malicious code in the at least one Android container through the Linux host, and transmitting information of kernel-related malicious code behavior to an analysis server.


