The increasing popularity of Android devices gives birth to a large amount of feature-rich applications (or apps) in various Android markets. Since adversaries can easily repackage mali- cious code into benign apps ...The increasing popularity of Android devices gives birth to a large amount of feature-rich applications (or apps) in various Android markets. Since adversaries can easily repackage mali- cious code into benign apps and spread them, it is urgent to detect the repackaged apps to maintain healthy Android mar- kets. In this paper we propose an efficient detection scheme based on twice context triggered piecewise hash (T-CTPH), in which CTPH process is called twice so as to generate two fin- gerprints for each app to detect the repackaged Android appli- cations. We also optimize the similarity calculation algorithm to improve the matching efficiency. Experimental results show that there are about 5% repackaged apps in pre- collected 6438 samples of 4 different types. The proposed scheme im- proves the detection accuracy of the repackaged apps and has positive and practical significance for the ecological system of the Android markets.展开更多
基金supported by ZTE Industry-Academia-Research Cooperation Funds
文摘The increasing popularity of Android devices gives birth to a large amount of feature-rich applications (or apps) in various Android markets. Since adversaries can easily repackage mali- cious code into benign apps and spread them, it is urgent to detect the repackaged apps to maintain healthy Android mar- kets. In this paper we propose an efficient detection scheme based on twice context triggered piecewise hash (T-CTPH), in which CTPH process is called twice so as to generate two fin- gerprints for each app to detect the repackaged Android appli- cations. We also optimize the similarity calculation algorithm to improve the matching efficiency. Experimental results show that there are about 5% repackaged apps in pre- collected 6438 samples of 4 different types. The proposed scheme im- proves the detection accuracy of the repackaged apps and has positive and practical significance for the ecological system of the Android markets.