
基于流量相似度的Android二次打包应用的检测技术研究 被引量:2

Based-on Network Traffic's Similarity to Detect Android Repackaged Applications
摘要 近年来,智能手机普及的同时也诞生了各种各样的应用.除了官方市场,许多三方市场也提供应用下载.对三方市场进行研究后发现:许多三方市场应用是将官方市场合法应用二次打包后投放到三方市场上的.此现象给用户和市场提供者都带来一定的安全隐患.如何检测这种二次打包应用成了急需解决的问题.本文提出基于流量相似度的Android二次打包应用的检测技术.它捕获应用的流量并对其进行解析、分类,以得到应用特征——功能流图与广告流图.最后计算特征的相似度来判定二次打包应用.实验结果显示三方市场上4.06%到10.18%的应用是二次打包的,并发现插入新广告或替换已存在的广告来赚取广告收入是二次打包的通用手段.此外,二次打包应用还会消耗更多的流量. Recent years have witnessed incredible adoption of smartphones, which is accompanied by large amount and wide variety of feature-rich smartphone applications. Besides the official market, some third-party markets have also been created to host apps. In this paper, we perform a systematic study on third-party markets. Among them, we find a common practice of repackaging legitimate apps from the official market and distributing repackaged ones via third-party markets, which brings certain security problems to the user and market provider. How to detect the repackaged applications becomes an urgent problem. This paper presents a technology to detect Android repackaged applications based on network traffic's similarity. It analyses and classifies an app's network traffic, so as to obtain its features--function flow graph and advertisement flow graph. And then it calculates apps' similarity between the third-party market and official market. The experiments show a worrisome fact that 4.06% to 10. 18% of apps hosted on these studied marketplaces are repackaged. Future manual investigation indicates that these repackaged apps are mainly used to embed a new advertisement or replace existing in-app to earn ad revenues, or even implant malicious payloads.
出处 《小型微型计算机系统》 CSCD 北大核心 2015年第5期954-958,共5页 Journal of Chinese Computer Systems
基金 国家重点基础研究发展计划项目(2012CB315805)资助 国家自然科学基金项目(61173167)资助
关键词 ANDROID应用 二次打包 流量解析 相似度 Android app repackaged network traffic analyze similarity
  • 相关文献


  • 1News ZOL Inc. Android mobile phone sales [ EB/OL]. http:// news. zol. com. cn/320/3204201, html,2013.
  • 2Kaspersky Lab. First SMS trojan detected for smartphones rurmingAndroid EB/OL ]. http://www, kaspersky, com/about/news/vi- rus/2010/First_SMS _Trojan detected for _smartphones _running _ Android, May 17,2011.
  • 3Zhou Ya-jin, Jiang Xu-xian. Detecting passive content leaks and pollution in Android applications [ C ]. Proc of the 20th Annual Symposium on Network and Distributed System Security, San Die- go: Internet Society, 2013:434 -443.
  • 4Jiang Xu-xian. Security Alert:new sophisticated Android malware droid kung fu found in alternative Chinese app markets[ EB/OL ]. http ://www. csc. ncsu. edu/faculty/jiang/DroidKungFu, html, Sep 17,2011.
  • 5Finance news Inc. The repackaged app is spreading in application markets [ EB/OL ]. http://finance, eastmoney, corn/news/1363, 20130729310278217. html, 2014.
  • 6Zhou Wu, Zhou Ya-jin, Jiang Xu-xian, et at. Detecting repackaged smartphone applications in third-party Android marketplaces [ C ]. Proceedings of the Second ACM Conference on Data and Applica- tion Security and Privacy,2012:317-326.
  • 7Jonathan Crussell, Clint Gibler, Hao Chen. Attack of the clones : de- tecting cloned applications on Android markets[ C]. In Sara Fores- ti,Moti Yung, and Fabio Martinelli, editors, Computer Security ( as ESORICS) 2012,volume 7459 of Lecture Notes in Computer Sci- ence, Springer Berlin Heidelberg ,2012:37-54.
  • 8Huang He-qing,Zhu Sen-cun,Liu Peng,et al. A framework for e- valuating mobile app repackaging detection algorithms[ C ]. In Pro- ceedings of the 6th International Conference on Trust & Trustworthy Computing ( TRUST 2013 ) ,2013 : 169 -186.
  • 9Lookout Inc. App genome report: February 2011 [ EB/OL]. ht- tps://www, mylookout, com/appgenome/. Online; Accessed at Dec 1,2011,.
  • 10Enck W, Gilbert P, Chun B G, et al. Taintdroid: an information- flow tracking system for realtime privacy monitoring on smartpho- nes [ C ]. 9th USENIX Symposium on Operating Systems Design and Implementation(OSDI'10) ,2010.











使用帮助 返回顶部