Paper published in a journal (Scientific congresses, symposiums and conference proceedings)
Dissecting APKs from Google Play: Trends, Insights and Security Implications
RUIZ JIMÉNEZ, Pedro Jesús; SAMHI, Jordan; BISSYANDE, Tegawendé François d Assise et al.
2025In IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)
Peer reviewed
 

Files


Full Text
2024402096.pdf
Author preprint (383.82 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Abstract :
[en] Researchers generally look for specific files within Android application packages (APKs) during their analysis, focusing on common files such as Dalvik bytecode or the Android manifest. However, Android apps are complex archive files containing various types of files. Failing to account for all files during analyses can compromise end-user security, and despite the wealth of existing techniques to analyze Android apps, only a few studies explore the diversity of files within apps. To bridge this gap, we propose the first large-scale empirical study that dissects the content of Android apps from Google Play. In our study, we explore the different file types and their usage trends. We enhance our analysis by exploring compressed files and the files they contain. We finally investigate to which extent developers use disguised files, i.e., files whose extension is conventionally associated with a file type different than its own (e.g., a Dalvik dex file with the extension “.png”), and study if they are a hint of maliciousness. Our results show that: ❶ Android apps comprise diverse file types, with over 15 000 distinct file extensions and more than 1000 unique file types found in our dataset containing over 400 000 APKs; and ❷ we found many cases where developers use a wrong relation between the file type and its extension to load malicious code at runtime.
Disciplines :
Computer science
Author, co-author :
RUIZ JIMÉNEZ, Pedro Jesús  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
SAMHI, Jordan  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
BISSYANDE, Tegawendé François d Assise  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KLEIN, Jacques  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
External co-authors :
no
Language :
English
Title :
Dissecting APKs from Google Play: Trends, Insights and Security Implications
Publication date :
2025
Event name :
SANER 2025
Event place :
Montréal, Canada
Event date :
from 4 to 7 March 2025
Journal title :
IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)
Peer reviewed :
Peer reviewed
Available on ORBilu :
since 06 January 2025

Statistics


Number of views
192 (13 by Unilu)
Number of downloads
179 (5 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
OpenAlex citations
 
0

Bibliography


Similar publications



Contact ORBilu