Please use this identifier to cite or link to this item: http://riu.ufam.edu.br/handle/prefix/9937
metadata.dc.type: Trabalho de Conclusão de Curso
Title: Antivírus para Android e malware inédito via Repackaging: um experimento de detectabilidade
metadata.dc.creator: Souza, Arthur Douglas
metadata.dc.contributor.advisor1: Feitosa, Eduardo Luzeiro
metadata.dc.description.resumo: Este trabalho avalia empiricamente a capacidade de detecção de antivírus de consumo para Android quando confrontados com malware inédito e não catalogado. Utilizando uma metodologia de diferencial controlado, o autor criou uma versão trojanizada do navegador DuckDuckGo via repackaging (injeção de payload malicioso) e a submeteu a varredura multi-engine (VirusTotal com 66 motores) e a seis produtos antivírus instalados em dispositivo físico. Principais achados: A amostra inédita não foi detectada por nenhum motor de assinatura (0/66 no VirusTotal) e permaneceu invisível a todos os antivírus testados Amostras de malware conhecidas (AhMyth, Anubis) foram amplamente reconhecidas, comprovando que as ferramentas estavam operantes O diferencial controlado confirmou que a mera introdução do payload novo foi suficiente para evadir detecção baseada em assinatura A única barreira efetiva foi a verificação do Google no momento da instalação — mecanismo proativo externo aos antivírus O scan nativo da Xiaomi falhou até mesmo diante de malware catalogado Conclusão: A pesquisa demonstra empiricamente a limitação reativa das técnicas baseadas em assinatura e reforça a necessidade de defesa em profundidade, não exclusivamente dependente do antivírus.
Abstract: Android devices concentrate sensitive data and constitute a priority target for malicious software, with threat detection falling primarily on consumer antivirus applications. However, the majority of techniques employed by these solutions are reactive, dependent on prior knowledge of the threat, raising questions about their effectiveness against novel, previously unknown samples. This work evaluates comparatively the detection capability of consumer antivirus tools for Android when confronted with a new, undocumented threat, constructed through malicious payload injection via repackaging of the official DuckDuckGo browser client. A controlled differential design was employed — the legitimate application version compared against its trojanzed variant, which differs from it essentially by the payload — complemented by benign controls and known malware samples. The evaluation was conducted along two dimensions: multi-engine scanning via VirusTotal and testing on a physical device with six consumer solutions. Results showed that the novel sample was not detected by any signature-based mechanism, remaining indistinguishable from a legitimate application (0 of 66 engines on VirusTotal and negative verdicts in all installed products), whereas known samples were widely recognized. The only effective barrier was Google's verification at installation time, while the manufacturer's native scan failed to detect even already-catalogued malware. We conclude that the introduction of a novel payload is sufficient to evade signature-based detection, empirically evidencing its reactive limitation and reinforcing the need for a defense-in-depth posture that does not rely exclusively on antivirus
Keywords: Segurança em Android
Detecção de malware
Antivírus
Repackaging
Malware inédito
Ameaças zero-day
Assinatura de código
Defesa em profundidade
Android security
Malware detection
Antivirus
Repackaging
Zero-day threats
metadata.dc.subject.cnpq: CIENCIAS EXATAS E DA TERRA: CIENCIA DA COMPUTACAO:SISTEMAS DE COMPUTACAO
metadata.dc.language: por
metadata.dc.publisher.country: Brasil
metadata.dc.publisher.department: ICOMP - Instituto de Computação
metadata.dc.publisher.course: Engenharia de Software - Bacharelado - Manaus
metadata.dc.rights: Acesso Aberto
metadata.dc.rights.uri: https://creativecommons.org/licenses/by-nc-nd/4.0/
URI: http://riu.ufam.edu.br/handle/prefix/9937
metadata.dc.contributor.grupo-pesquisa: GICA - Grupo de Pesquisa em Gestão da Informação e do Conhecimento na Amazônia
Appears in Collections:Trabalho de Conclusão de Curso - Graduação - Engenharias

Files in This Item:
File Description SizeFormat 
TCC_ArthurSouza.pdf374,88 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.