How Did That Get In My Phone? Unwanted App Distribution on Android Devices

10/20/2020
by   Platon Kotzias, et al.
0

Android is the most popular operating system with billions of active devices. Unfortunately, its popularity and openness makes it attractive for unwanted apps, i.e., malware and potentially unwanted programs (PUP). In Android, app installations typically happen via the official and alternative markets, but also via other smaller and less understood alternative distribution vectors such as Web downloads, pay-per-install (PPI) services, backup restoration, bloatware, and IM tools. This work performs a thorough investigation on unwanted app distribution by quantifying and comparing distribution through different vectors. At the core of our measurements are reputation logs of a large security vendor, which include 7.9M apps observed in 12M devices between June and September 2019. As a first step, we measure that between 10 of users devices encounter at least one unwanted app, and compare the prevalence of malware and PUP. An analysis of the who-installs-who relationships between installers and child apps reveals that the Play market is the main app distribution vector, responsible for 87 of unwanted app installs, but it also has the best defenses against unwanted apps. Alternative markets distribute instead 5.7 unwanted apps. Bloatware is also a significant unwanted app distribution vector with 6 distribution vector that may even allow unwanted apps to survive users' phone replacement. We estimate unwanted app distribution via PPI to be smaller than on Windows. Finally, we observe that Web downloads are rare, but provide a riskier proposition even compared to alternative markets.

READ FULL TEXT

page 1

page 6

research
09/26/2018

Beyond Google Play: A Large-Scale Comparative Study of Chinese Android App Markets

China is one of the largest Android markets in the world. As Chinese use...
research
12/12/2017

Detecting Low Rating Android Apps Before They Have Reached the Market

Driven by the popularity of the Android system, Android app markets enjo...
research
01/18/2023

One Size Does not Fit All: Quantifying the Risk of Malicious App Encounters for Different Android User Profiles

Previous work has investigated the particularities of security practices...
research
05/23/2017

Predictive Analytics for Enhancing Travel Time Estimation in Navigation Apps of Apple, Google, and Microsoft

The explosive growth of the location-enabled devices coupled with the in...
research
11/20/2018

Rebooting Research on Detecting Repackaged Android Apps: Literature Review and Benchmark

Repackaging is a serious threat to the Android ecosystem as it deprives ...
research
09/19/2018

Divide and Conquer: Recovering Contextual Information of Behaviors in Android Apps around Limited-quantity Audit Logs

Android users are now suffering serious threats from various unwanted ap...
research
07/25/2023

A Pairwise Dataset for GUI Conversion and Retrieval between Android Phones and Tablets

With the popularity of smartphones and tablets, users have become accust...

Please sign up or login with your details

Forgot password? Click here to reset