Rotten apples spoil the bunch: an anatomy of Google Play malware


연구 분야: Strategies



학회: ICSE '22: Proceedings of the 44th International Conference on Software Engineering


초록

This paper provides an in-depth analysis of Android malware that bypassed the strictest defenses of the Google Play application store and penetrated the official Android market between January 2016 and July 2021. We systematically identified 1,238 such malicious applications, grouped them into 134 families, and manually analyzed one application from 105 distinct families. During our manual analysis, we identified malicious payloads the applications execute, conditions guarding execution of the payloads, hiding techniques applications employ to evade detection by the user, and other implementation-level properties relevant for automated malware detection. As most applications in our dataset contain multiple payloads, each triggered via its own complex activation logic, we also contribute a graph-based representation showing activation paths for all application payloads in form of a control- and data-flow graph. Furthermore, we discuss the capabilities of existing malware detection tools, put them in context of the properties observed in the analyzed malware, and identify gaps and future research directions. We believe that our detailed analysis of the recent, evasive malware will be of interest to researchers and practitioners and will help further improve malware detection tools.


Author Profile
Michael Cao

Univ. of British Columbia Canada

Canada
Author Profile
Khaled Ahmed

Univ. of British Columbia Canada

Canada
Author Profile
Julia Rubin

Univ. of British Columbia Canada

Canada

📄 논문 정보

발행 연도 2022년
인용수 9
출판 국가 Canada
사이트 ACM
좋아요 수 0

연관 논문 목록 (92건)