Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Macneto: Obfuscation Resilient Search through Executable Classification

Data collection

We collect android APKs from fdroid

Concepts

Macneto contains two major modules: program (executable) analysis and machine learning, including PCA and deep learning. To demonstrate the capability of Macneto, we attempt to search for programs, mapping a program obfuscated by an obfucator back to its original version. To deobfuscate programs, Macneto needs to learn the difference between original binary and its obfuscated version. Thus, we need to program-analyze both versions of binary. From step 1 to step 6, you will need to run them on both of your original apk and obfuscated apk (or jars).

To facilitate the analysis, you can create a directory for analyzing your original binaries and create another directory for analyzing your obfuscated binaries. For learning the mapping between an executable and its obfuscated counterpart, we use sklearn, tensorflow and keras. For installing these frameworks, please check out the details on their websites.

Steps

Step 0: Compilation

Our program analyzer is java based. For compiling our program analyzer, you will need to install Maven. Simply use the following command for compliation: mvn clean package

Step 1: Create database

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.db.DocManager

This command will create a database db/macneto.db. You will have to create both databases for your original binaries and your obfuscated binaries. This means that you will have n + 1 databases, where n is the number of your obfuscators.

Step 2: Generate call graphs

For computing the call graph for each apk, we leverage FlowDroid. The set-up of FlowDroid can be found on their github repo.

python macneto_container_v2/graph_gen.py -a YOUR_APKBASE -g callgraphs -e macneto_container_v2/macneto-inst-analysis-0.0.1-SNAPSHOT.jar -f android/platforms -t 16 -ext jar

For details of these options, please refer to graph_gen.py. Again, this command needs to run on both original apks and obfuscated apks/jars. -a can specify the directory of your apks. -g can specify where you want to store your callgraphs. We usually keep it as ./callgraphs. -t can specify the thread number. -ext can specify which types of binary you want to analyze.

Step 3: Compute instruction distribution

java -cp macneto-inst-analysis-0.0.1-SNAPSHOT.jar edu.columbia.cs.psl.macneto.inst.MachineCodeDriver -c your/apk/location

This step computes the instruction distribution of each method in all of your apks. Again, this step needs to run on both original and obfuscated apks.

Step 4: Learning phase

python macneto_learn.py -d ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -t 32 -i 10000 -a deep

-t specifies how many principal components you want; -i specifies how many iterations you want; you can leave -a as it is. This step first compute PCA from the original executables, use it label the obfuscated counterparts and then learn the mapping through ANN.

Step 5: Search phase

python macneto_search.py -o ORIGINAL/db/macneto.db -b OBFUSCATED/db/macneto.db -m 7

-m specifies the experiment (fold) number (m + 1). In our paper, we conduct k-fold analysis, where k = 8.

License

This software is released under the MIT license.

Copyright (c) 2018, by The Trustees of Columbia University in the City of New York.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Acknowledgements

The authors of this software are Fang-Hsiang (Mike) Su, Jonathan Bell, Gail Kaiser and Baishakhi Ray. This work is funded in part by NSF CNS-1563555.

About

No description, website, or topics provided.

Resources

Stars

11 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages