Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Should You Consider Adware as Malware in Your Study?
GAO, Jun; Li, Li; KONG, Pingfan et al.
2019In 26th edition of the IEEE International Conference on Software Analysis, Evolution and Reengineering
Peer reviewed
 

Documents


Texte intégral
adware-paper-SANER-2019-submitted.pdf
Preprint Auteur (369.6 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Android; adware; malware
Résumé :
[en] Empirical validations of research approaches eventually require a curated ground truth. In studies related to Android malware, such a ground truth is built by leveraging Anti-Virus (AV) scanning reports which are often provided free through online services such as VirusTotal. Unfortunately, these reports do not offer precise information for appropriately and uniquely assigning classes to samples in app datasets: AV engines indeed do not have a consensus on specifying information in labels. Furthermore, labels often mix information related to families, types, etc. In particular, the notion of “adware” is currently blurry when it comes to maliciousness. There is thus a need to thoroughly investigate cases where adware samples can actually be associated with malware (e.g., because they are tagged as adware but could be considered as malware as well). In this work, we present a large-scale analytical study of Android adware samples to quantify to what extent “adware should be considered as malware”. Our analysis is based on the Androzoo repository of 5 million apps with associated AV labels and leverages a state-of-the-art label harmonization tool to infer the malicious type of apps before confronting it against the ad families that each adware app is associated with. We found that all adware families include samples that are actually known to implement specific malicious behavior types. Up to 50% of samples in an ad family could be flagged as malicious. Overall the study demonstrates that adware is not necessarily benign.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
GAO, Jun ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Li, Li;  Monash University > Faculty of Information Technology
KONG, Pingfan ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BISSYANDE, Tegawendé François D Assise  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
KLEIN, Jacques  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Computer Science and Communications Research Unit (CSC)
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Should You Consider Adware as Malware in Your Study?
Date de publication/diffusion :
24 février 2019
Nom de la manifestation :
26th edition of the IEEE International Conference on Software Analysis, Evolution and Reengineering
Lieu de la manifestation :
Hangzhou, Chine
Date de la manifestation :
from 24-2-2019 to 27-2-2019
Titre de l'ouvrage principal :
26th edition of the IEEE International Conference on Software Analysis, Evolution and Reengineering
Peer reviewed :
Peer reviewed
Focus Area :
Computational Sciences
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 11 mars 2019

Statistiques


Nombre de vues
244 (dont 20 Unilu)
Nombre de téléchargements
806 (dont 14 Unilu)

citations Scopus®
 
27
citations Scopus®
sans auto-citations
26

Bibliographie


Publications similaires



Contacter ORBilu