2022
DOI: 10.1109/tdsc.2020.2982635
|View full text |Cite
|
Sign up to set email alerts
|

Eight Years of Rider Measurement in the Android Malware Ecosystem

Abstract: Despite the growing threat posed by Android malware, the research community is still lacking a comprehensive view of common behaviors and trends exposed by malware families active on the platform. Without such view, the researchers incur the risk of developing systems that only detect outdated threats, missing the most recent ones. In this paper, we conduct the largest measurement of Android malware behavior to date, analyzing over 1.2 million malware samples that belong to 1.2K families over a period of eight… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
42
0
3

Year Published

2024
2024
2024
2024

Publication Types

Select...
6
2
1

Relationship

1
8

Authors

Journals

citations
Cited by 46 publications
(45 citation statements)
references
References 41 publications
0
42
0
3
Order By: Relevance
“…As pointed out in [7], a number of critical vulnerabilities have been reported for Android platforms 3 . Particularly, the Android mediaserver has been repeatedly targeted recently through the Stagefright media playback engine.…”
Section: Dataset Used For Evaluationmentioning
confidence: 97%
“…As pointed out in [7], a number of critical vulnerabilities have been reported for Android platforms 3 . Particularly, the Android mediaserver has been repeatedly targeted recently through the Stagefright media playback engine.…”
Section: Dataset Used For Evaluationmentioning
confidence: 97%
“…Specifically, we rely on anti-virus scanners to flag malicious artifact. Concretely, DDM sends these non-image artifacts to VirusTotal [11], a free online service that integrates over 60 anti-virus engines, has been widely adopted by the research community [17,35,36,69]. Our prototype plugins implement detection schemes where, for each artifact that is sent to VirusTotal will be considered as ad devious content whenever at least three (3) anti-virus scanners flag it as suspicious.…”
Section: Other Devious Ad Content Groups Devious Ad Content For Othementioning
confidence: 99%
“…Also, reflection is a popular java feature in Android as it allows to get information about classes and components while an app is running and modify them. The reflection API java.lang.reflect includes classes and interfaces that can be used to dynamically load code at runtime [67]. The package java.lang.reflect was called in all benign apps except one.…”
Section: Benign Applicationsmentioning
confidence: 99%
“…This package includes features to keep track of phone data such as network type and connection state. Also, it can be indicative of evasion [67,70]. Figure 11 shows an example screenshots of one ransomware app (MD5: 77ADB4D5A4F8AF9B8A6D23676848C6) handling many function calls from this package.…”
Section: Ransomware Applicationsmentioning
confidence: 99%