Skip to main navigation Skip to search Skip to main content

Should You Consider Adware as Malware in Your Study?

  • Jun Gao
  • , Li Li
  • , Pingfan Kong
  • , Tegawende F. Bissyande
  • , Jacques Klein

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Empirical validations of research approaches eventually require a curated ground truth. In studies related to Android malware, such a ground truth is built by leveraging Anti-Virus (AV) scanning reports which are often provided free through online services such as VirusTotal. Unfortunately, these reports do not offer precise information for appropriately and uniquely assigning classes to samples in app datasets: AV engines indeed do not have a consensus on specifying information in labels. Furthermore, labels often mix information related to families, types, etc. In particular, the notion of 'adware' is currently blurry when it comes to maliciousness. There is thus a need to thoroughly investigate cases where adware samples can actually be associated with malware (e.g., because they are tagged as adware but could be considered as malware as well).In this work, we present a large-scale analytical study of Android adware samples to quantify to what extent 'adware should be considered as malware'. Our analysis is based on the Androzoo repository of 5 million apps with associated AV labels and leverages a state-of-The-Art label harmonization tool to infer the malicious type of apps before confronting it against the ad families that each adware app is associated with. We found that all adware families include samples that are actually known to implement specific malicious behavior types. Up to 50% of samples in an ad family could be flagged as malicious. Overall the study demonstrates that adware is not necessarily benign.

Original languageEnglish
Title of host publicationSANER 2019 - Proceedings of the 2019 IEEE 26th International Conference on Software Analysis, Evolution, and Reengineering
EditorsEmad Shihab, David Lo, Xinyu Wang
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages604-608
Number of pages5
ISBN (Electronic)9781728105918
DOIs
StatePublished - 15 Mar 2019
Externally publishedYes
Event26th IEEE International Conference on Software Analysis, Evolution, and Reengineering, SANER 2019 - Hangzhou, China
Duration: 24 Feb 201927 Feb 2019

Publication series

NameSANER 2019 - Proceedings of the 2019 IEEE 26th International Conference on Software Analysis, Evolution, and Reengineering

Conference

Conference26th IEEE International Conference on Software Analysis, Evolution, and Reengineering, SANER 2019
Country/TerritoryChina
CityHangzhou
Period24/02/1927/02/19

Keywords

  • adware
  • Android
  • malware

Fingerprint

Dive into the research topics of 'Should You Consider Adware as Malware in Your Study?'. Together they form a unique fingerprint.

Cite this