发表机构
Vietnamese-German University(越南德国大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出CLoader框架,通过统一运行时控制层协调网络、时间与代码层面的动态规避策略,结合随机端口、代码混淆和完整性检查,在移动安全环境中实现90%的挂钩工具检测绕过率。
AI 中文摘要
我们提出了一种隐蔽框架,通过将静态配置替换为动态规避策略,消除在安全移动环境中对Frida和Xposed等挂钩工具的检测。与现有方法独立应用这些技术不同,该框架引入了一个统一的运行时控制层,系统性地协调网络、时间和代码层面的规避性变换。该解决方案集成了随机端口分配、运行时代码混淆、延迟执行触发器和自完整性检查,以破坏基于签名的扫描、时间启发式检测和篡改尝试。一个定制的Android加载器CLoader强制执行这些机制,将挂钩活动与安全监控隔离,同时保持完整的拦截和修改能力。在企业反恶意软件系统、加固应用和设备管理平台上的验证表明,在我们的评估矩阵中,绕过率达到90%。这种方法通过掩盖网络、时间和代码层面的指纹,无需架构性改造,即可在锁定移动生态系统中实现可靠的渗透测试和恶意软件分析。
英文摘要
We propose a stealth framework that eliminates detection of hooking tools such as Frida and Xposed in secured mobile environments by replacing static configurations with dynamic evasion tactics. In contrast to existing approaches that apply these techniques independently, the framework introduces a unified runtime control layer that systematically coordinates network, temporal, and code-level evasive transformations. The solution integrates randomized port allocation, runtime code obfuscation, delayed execution triggers, and self-integrity checks to disrupt signature-based scans, timing heuristics, and tampering attempts. A custom Android loader, CLoader, enforces these mechanisms to isolate hooking activities from security monitors while maintaining complete interception and modification capabilities. Validation across enterprise anti malware systems, hardened applications, and device management platforms demonstrates a 90% bypass rate in our evaluation matrix. This approach enables reliable penetration testing and malware analysis in locked-down mobile ecosystems by masking network, temporal, and code-level fingerprints without architectural overhauls.
CommentsThis paper has been accepted at the International Conference on Multidisciplinary Research (ICMR 2025)