A measurement study of google play

A measurement study of google play
复制标题

DOI:
10.1145/2591971.2592003
复制
发表时间:
2014-06
期刊:
--
影响因子:
--
通讯作者:
N. Viennot;Edward Garcia;Jason Nieh
N. Viennot;Edward Garcia;Jason Nieh
中科院分区:
其他
文献类型:
--
作者:
N. Viennot;Edward Garcia;Jason Nieh

文献摘要

被引文献

相似文献

尽管有数百万用户从Google Play商店下载和使用第三方Android应用程序,但对这些应用程序的总体信息知之甚少。我们已经构建了PlayDrone,第一个可扩展的Google Play商店爬虫,并使用它每天索引和分析Google Play商店中超过1,100,000个应用程序,这是Android应用程序的最大索引。PlayDrone利用各种黑客技术来绕过谷歌索引Google Play商店内容的障碍,并提供专有应用程序源代码,包括超过880,000个免费应用程序的源代码。我们通过探索四个以前未解决的问题来证明PlayDrone在反编译和分析应用程序内容方面的有用性:大规模Google Play应用程序内容的特征及其随时间的演变,应用程序中的库使用及其对应用程序可移植性的影响,Google Play中重复的应用程序内容,OAuth和相关服务身份验证机制的无效性导致恶意用户能够轻松获得对Amazon Web Services上的用户数据和资源的未经授权的访问,Facebook.
Although millions of users download and use third-party Android applications from the Google Play store, little information is known on an aggregated level about these applications. We have built PlayDrone, the first scalable Google Play store crawler, and used it to index and analyze over 1,100,000 applications in the Google Play store on a daily basis, the largest such index of Android applications. PlayDrone leverages various hacking techniques to circumvent Google's roadblocks for indexing Google Play store content, and makes proprietary application sources available, including source code for over 880,000 free applications. We demonstrate the usefulness of PlayDrone in decompiling and analyzing application content by exploring four previously unaddressed issues: the characterization of Google Play application content at large scale and its evolution over time, library usage in applications and its impact on application portability, duplicative application content in Google Play, and the ineffectiveness of OAuth and related service authentication mechanisms resulting in malicious users being able to easily gain unauthorized access to user data and resources on Amazon Web Services and Facebook.