z-logo
open-access-imgOpen Access
Re-checking App Behavior against App Description in the Context of Third-party Libraries
Author(s) -
Chengpeng Zhang,
Haoyu Wang,
Ran Wang,
Yao Guo,
Guoai Xu
Publication year - 2018
Publication title -
proceedings/proceedings of the ... international conference on software engineering and knowledge engineering
Language(s) - English
Resource type - Conference proceedings
SCImago Journal Rank - 0.155
H-Index - 14
eISSN - 2325-9000
pISSN - 2325-9086
DOI - 10.18293/seke2018-180
Subject(s) - computer science , context (archaeology) , mobile apps , world wide web , smartphone app , third party , human–computer interaction , internet privacy , history , archaeology
Recent research suggested promising approaches that identify potential malware by checking the inconsistence between app description and actual behavior of the app. However, state-of-the-art approaches have ignored the impact of thirdparty libraries (TPLs) when detecting outliers, which could affect the detection results greatly in two folds. On one hand, most Android apps would not list the functionality of TPLs in app description, which could cause false positives, as many apps that use TPLs will be identified as outliers. On the other hand, it is important to separate TPLs from custom code when analyzing the sensitive behaviors, otherwise the malicious behaviors of custom code will be obscured by TPLs. In this paper, we revisit the study of checking app behavior against app description in the context of TPLs. Experiment results on more than 400K Android apps suggest that more than 54% of apps are no longer identified as outliers after filtering TPLs, and we could identify roughly 50% of new outliers. Furthermore, removing the impact of TPLs could help to identify malware and pinpoint the malicious behavior of custom code. Out results shed a light on applying the TPL analysis to enhance a variety of mobile app analysis tasks.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom