论文标题

镜头下的安全应用程序:Android安全应用程序的经验分析

Security Apps under the Looking Glass: An Empirical Analysis of Android Security Apps

论文作者

Yao, Weixian, Li, Yexuan, Lin, Weiye, Hu, Tianhui, Chowdhury, Imran, Masood, Rahat, Seneviratne, Suranga

论文摘要

第三方安全应用程序是Android应用程序生态系统的组成部分。许多用户将它们作为对其设备的额外保护层安装。在Google Play商店中,有数百个此类安全应用程序,包括免费和付款,其中一些已下载了数百万次。通过安装安全应用程序,智能手机用户对开发这些应用程序的安全公司提供了大量信任,因为功能齐全的移动安全应用需要访问许多智能手机资源,例如存储,文本消息和电子邮件,浏览器历史记录以及有关其他已安装应用程序的信息。这些资源通常包含高度敏感的个人信息。因此,必须了解移动安全应用程序生态系统,以评估安装它们是否确实有益。为此,在本文中,我们介绍了对Android安全应用程序的首次实证研究。我们分析了来自元数据,静态分析和动态分析等多个方面的100个Android安全应用程序,并为其操作和行为提供了见解。我们的结果表明,我们研究的20%的安全应用程序可能会将收集的数据从智能手机转售给第三方;在某些情况下,即使未经用户同意。另外,我们的实验表明,大约50%的安全应用程序无法识别智能手机上安装的恶意软件。

Third-party security apps are an integral part of the Android app ecosystem. Many users install them as an extra layer of protection for their devices. There are hundreds of such security apps, both free and paid in Google Play Store and some of them are downloaded millions of times. By installing security apps, the smartphone users place a significant amount of trust towards the security companies who developed these apps, because a fully functional mobile security app requires access to many smartphone resources such as the storage, text messages and email, browser history, and information about other installed applications. Often these resources contain highly sensitive personal information. As such, it is essential to understand the mobile security apps ecosystem to assess whether is it indeed beneficial to install them. To this end, in this paper, we present the first empirical study of Android security apps. We analyse 100 Android security apps from multiple aspects such as metadata, static analysis, and dynamic analysis and presents insights to their operations and behaviours. Our results show that 20% of the security apps we studied potentially resell the data they collect from smartphones to third parties; in some cases, even without the user consent. Also, our experiments show that around 50% of the security apps fail to identify malware installed on a smartphone.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源