跳到主要导航 跳到搜索 跳到主要内容

An empirical study of potentially malicious third-party libraries in Android apps

  • Zicheng Zhang
  • , Wenrui Diao*
  • , Chengyu Hu
  • , Shanqing Guo
  • , Chaoshun Zuo
  • , Li Li
  • *此作品的通讯作者
  • Shandong University
  • Ohio State University
  • Monash University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The rapid development of Android apps primarily benefits from third-party libraries that provide well-encapsulated functionalities. On the other hand, more and more malicious libraries are discovered in the wild, which brings new security challenges. Despite some previous studies focusing on the malicious libraries, however, most of them only study specific types of libraries or individual cases. The security community still lacks a comprehensive understanding of potentially malicious libraries (PMLs) in the wild. In this paper, we systematically study the PMLs based on a large-scale APK dataset (over 500K samples), including extraction, identification, and comprehensive analysis. On the high-level, we conducted a two-stage study. In the first stage, to collect enough analyzing samples, we designed an automatic tool to extract libraries and identify PMLs. In the second stage, we conducted a comprehensive study of the obtained PMLs. Notably, we analyzed four representative aspects of PMLs: library repackaging, exposed behaviors, permissions, and developer connections. Several interesting facts were discovered. We believe our study will provide new knowledge of malicious libraries and help design targets defense solutions to mitigate the corresponding security risks.

源语言英语
主期刊名WiSec 2020 - Proceedings of the 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks
出版商Association for Computing Machinery
144-154
页数11
ISBN(电子版)9781450380065
DOI
出版状态已出版 - 8 7月 2020
已对外发布
活动13th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2020 - Linz, Virtual, 奥地利
期限: 8 7月 202010 7月 2020

出版系列

姓名WiSec 2020 - Proceedings of the 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks

会议

会议13th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2020
国家/地区奥地利
Linz, Virtual
时期8/07/2010/07/20

指纹

探究 'An empirical study of potentially malicious third-party libraries in Android apps' 的科研主题。它们共同构成独一无二的指纹。

引用此