FairPlay: Fraud and Malware Detection in Google Play
نویسندگان
چکیده
Fraudulent behaviors in Google’s Android app market fuel search rank abuse and malware proliferation. We present FairPlay, a novel system that uncovers both malware and search rank fraud apps, by picking out trails that fraudsters leave behind. To identify suspicious apps, FairPlay’s PCF algorithm correlates review activities and uniquely combines detected review relations with linguistic and behavioral signals gleaned from longitudinal Google Play app data. We contribute a new longitudinal app dataset to the community, which consists of over 87K apps, 2.9M reviews, and 2.4M reviewers, collected over half a year. FairPlay achieves over 95% accuracy in classifying gold standard datasets of malware, fraudulent and legitimate apps. We show that 75% of the identified malware apps engage in search rank fraud. FairPlay discovers hundreds of fraudulent apps that currently evade Google Bouncer’s detection technology, and reveals a new type of attack campaign, where users are harassed into writing positive reviews, and install and review other apps.
منابع مشابه
Evaluating Malware Mitigation by Android Market Operators
All Android markets are confronted with malicious apps, but they differ in how effective they deal with them. In this study, we evaluate the mitigation efforts of Google Play and four third-party markets. We define three metrics and measure how sensitive they are to different detection results from anti-virus vendors. Malware presence in three third-party markets – Liqucn, eoeMarket and Mumayi ...
متن کاملFinding Unknown Malice in 10 Seconds: Mass Vetting for New Threats at the Google-Play Scale
An app market’s vetting process is expected to be scalable and effective. However, today’s vetting mechanisms are slow and less capable of catching new threats. In our research, we found that a more powerful solution can be found by exploiting the way Android malware is constructed and disseminated, which is typically through repackaging legitimate apps with similar malicious components. As a r...
متن کاملStudy of the effect of internal control weaknesses on fraudulent financial reporting risk with considering the moderating role of CEO characteristics
Internal controls play a vital role in prevention of fraud. Internal controls reduce the opportunities for committing fraud. According to information symmetry theory, internal control disclosure the solution is to examine the role of management accountability. To investigate the subject, based on the probit regression model the data related to the variables is analyzed the period from 2013 to ...
متن کاملAutomatically Learning Android Malware Signatures from Few Samples
We propose a new technique for Android malware detection that combines the respective strengths of learningand signature-based approaches. Our approach uses a new learning algorithm based on Maximum Satisfiability (MaxSAT) to automatically synthesize semantic malware signatures from very few instances of a malware family. Our key insight is that the common functionality of a malware family can ...
متن کاملPresenting a Model for Financial Reporting Fraud Detection using Genetic Algorithm
both academic and auditing firms have been searching for ways to detect corporate fraud. The main objective of this study was to present a model to detect financial reporting fraud by companies listed on Tehran Stock Exchange (TSE) using genetic algorithm. For this purpose, consistent with theoretical foundations, 21 variables were selected to predict fraud in financial reporting that finally, ...
متن کامل