Evaluation of Resource-Based App Repackaging Detection in Android

被引:17
|
作者
Gadyatskaya, Olga [1 ]
Lezza, Andra-Lidia [1 ]
Zhauniarovich, Yury
机构
[1] Univ Luxembourg, SnT, Luxembourg, Luxembourg
来源
关键词
Android security; Repackaging; Resource files;
D O I
10.1007/978-3-319-47560-8_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Android app repackaging threatens the health of application markets, as repackaged apps, besides stealing revenue for honest developers, are also a source of malware distribution. Techniques that rely on visual similarity of Android apps recently emerged as a way to tackle the repackaging detection problem, as code-based detection techniques often fail in terms of efficiency, and effectiveness when obfuscation is applied [19,21]. Among such techniques, the resource-based repackaging detection approach that compares sets of files included in apks has arguably the best performance [10,17,20]. Yet, this approach has not been previously validated on a dataset of repackaged apps. In this paper we report on our evaluation of the approach, and present substantial improvements to it. Our experiments show that the state-of-art tools applying this technique rely on too restrictive thresholds. Indeed, we demonstrate that a very low proportion of identical resource files in two apps is a reliable evidence for repackaging. Furthermore, we have shown that the Overlap similarity score performs better than the Jaccard similarity coefficient used in previous works. By applying machine learning techniques, we give evidence that considering separately the included resource file types significantly improves the detection accuracy of the method. Experimenting with a balanced dataset of more than 2700 app pairs, we show that with our enhancements it is possible to achieve the F-measure of 0.9919.
引用
收藏
页码:135 / 151
页数:17
相关论文
共 50 条
  • [1] A Scalable Cloud-Based Android App Repackaging Detection Framework
    Li, Jinghua
    Liu, Xiaoyan
    Zhang, Huixiang
    Mu, Dejun
    GREEN, PERVASIVE, AND CLOUD COMPUTING, 2016, 9663 : 113 - 125
  • [2] Measuring Android App Repackaging Prevalence based on the Permissions of App
    Rastogi, Sajal
    Bhushan, Kriti
    Gupta, B. B.
    INTERNATIONAL CONFERENCE ON EMERGING TRENDS IN ENGINEERING, SCIENCE AND TECHNOLOGY (ICETEST - 2015), 2016, 24 : 1436 - 1444
  • [3] Scalable and Obfuscation-Resilient Android App Repackaging Detection Based on Behavior Birthmark
    Yuan, Cangzhou
    Wei, Shenhong
    Zhou, Chengjian
    Guo, Jiangtao
    Xiang, Hongyue
    2017 24TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2017), 2017, : 476 - 485
  • [4] A Fast and Resource-Based Detection Approach of Similar Android Application
    Zhang P.
    Niu S.-Z.
    Huang R.-Q.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2019, 47 (09): : 1913 - 1918
  • [5] CHALLENGES IN EMULATING SENSOR AND RESOURCE-BASED STATE CHANGES FOR ANDROID MALWARE DETECTION
    Boomgaarden, J.
    Corney, J.
    Whittaker, H.
    Dinolt, G.
    McEachen, J.
    2015 9TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION SYSTEMS (ICSPCS), 2015,
  • [6] Android Applications Repackaging Detection Techniques for Smartphone Devices
    Rastogi, Sajal
    Bhushan, Kriti
    Gupta, B. B.
    1ST INTERNATIONAL CONFERENCE ON INFORMATION SECURITY & PRIVACY 2015, 2016, 78 : 26 - 32
  • [7] Enhanced Android App-Repackaging Attack on In-Vehicle Network
    Lee, Yousik
    Woo, Samuel
    Lee, Jungho
    Song, Yunkeun
    Moon, Heeseok
    Lee, Dong Hoon
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2019, 2019
  • [8] RepDroid: An Automated Tool for Android Application Repackaging Detection
    Yue, Shengtao
    Feng, Weizan
    Ma, Jun
    Jiang, Yanyan
    Tao, Xianping
    Xu, Chang
    Lu, Jian
    2017 IEEE/ACM 25TH INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION (ICPC), 2017, : 132 - 142
  • [9] A Rapid and Scalable Method for Android Application Repackaging Detection
    Jiao, Sibei
    Cheng, Yao
    Ying, Lingyun
    Su, Purui
    Feng, Dengguo
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, ISPEC 2015, 2015, 9065 : 349 - 364
  • [10] Evaluation of the Core Competence of Resource-based Enterprises
    Ke, Xiaoling
    Yang, Changming
    Zhu, Kejun
    EIGHTH WUHAN INTERNATIONAL CONFERENCE ON E-BUSINESS, VOLS I-III, 2009, : 818 - 823