Hey, You, Get Off of My Market: Detecting Malicious Apps in Official and Alternative Android Markets

Hey, You, Get Off of My Market: Detecting Malicious Apps in Official and Alternative Android Markets
复制标题

DOI:
--
复制
发表时间:
2012
期刊:
--
影响因子:
--
通讯作者:
Yajin Zhou;Zhi Wang;Wu Zhou;Xuxian Jiang
Yajin Zhou;Zhi Wang;Wu Zhou;Xuxian Jiang
中科院分区:
其他
文献类型:
--
作者:
Yajin Zhou;Zhi Wang;Wu Zhou;Xuxian Jiang

文献摘要

被引文献

相似文献

In this paper, we present a systematic study for the detection of malicious applications (or apps) on popular Android Markets. To this end, we first propose a permissionbased behavioral footprinting scheme to detect new samples of known Android malware families. Then we apply a heuristics-based filtering scheme to identify certain inherent behaviors of unknown malicious families. We implemented both schemes in a system called DroidRanger. The experiments with 204, 040 apps collected from five different Android Markets in May-June 2011 reveal 211 malicious ones: 32 from the official Android Market (0.02% infection rate) and 179 from alternative marketplaces (infection rates ranging from 0.20% to 0.47%). Among those malicious apps, our system also uncovered two zero-day malware (in 40 apps): one from the official Android Market and the other from alternative marketplaces. The results show that current marketplaces are functional and relatively healthy. However, there is also a clear need for a rigorous policing process, especially for non-regulated alternative marketplaces.