Reference : Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting
Scientific journals : Article
Engineering, computing & technology : Computer science
http://hdl.handle.net/10993/29474
Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting
English
Li, Li mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Li, Daoyuan mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Bissyande, Tegawendé François D Assise mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Klein, Jacques mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Computer Science and Communications Research Unit (CSC) >]
Le Traon, Yves mailto [University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC) >]
Lo, David []
Cavallaro, Lorenzo []
Jan-2017
IEEE Transactions on Information Forensics & Security
Yes
International
[en] The Android packaging model offers ample opportunities for malware writers to piggyback malicious code in popular apps, which can then be easily spread to a large user base. Although recent research has produced approaches and tools to identify piggybacked apps, the literature lacks a comprehensive investigation into such phenomenon. We fill this gap by 1) systematically building a large set of piggybacked and benign apps pairs, which we release to the community, 2) empirically studying the characteristics of malicious piggybacked apps in comparison with their benign counterparts, and 3) providing insights on piggybacking processes. Among several findings providing insights, analysis techniques should build upon to improve the overall detection and classification accuracy of piggybacked apps, we show that piggybacking operations not only concern app code but also extensively manipulates app resource files, largely contradicting common beliefs. We also find that piggybacking is done with little sophistication, in many cases automatically, and often via library code.
Researchers ; Professionals ; Students ; General public ; Others
http://hdl.handle.net/10993/29474

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
article.pdfAuthor preprint892.25 kBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.