Towards Attribution in Mobile Markets: Identifying Developer Account Polymorphism


연구 분야: Strategies



학회: CCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security


초록

Malicious developers may succeed at publishing their apps in mobile markets, including the official ones. If reported, the apps will be taken down and the developer accounts possibly be banned. Unfortunately, such take-downs do not prevent the attackers to use other developer accounts to publish variations of their malicious apps. This work presents a novel approach for identifying developer accounts, and other indicators of compromise (IOCs) in mobile markets, that belong to the same operation, i.e., to the same owners. Given a set of seed IOCs, our approach explores app and version metadata to identify new IOCs that belong to the same operation. It outputs an attribution graph, which details the attribution inferences, so that they can be reviewed. We have implemented our approach into Retriever, a tool that supports multiple mobile markets including the official GooglePlay and AppleStore. We have evaluated Retriever on 17 rogueware and adware operations. In 94% of the operations, Retriever discovers at least one previously unknown developer account. Furthermore, Retriever reveals that operations that look dead still have active developer accounts.


Author Profile
Silvia Sebastian

IMDEA Software Institute & Universidad Politécnica de Madrid Madrid Spain

Germany
Author Profile
Juan Caballero

IMDEA Software Institute Madrid Spain

Spain

📄 논문 정보

발행 연도 2020년
인용수 12
출판 국가 Spain, Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (74건)