Mobile App Squatting
Yangyu Hu, Haoyu Wang, Ren He, Li Li, Gareth Tyson, Ignacio Castro, Yao Guo, Lei Wu, Guoai Xu
摘要
Domain squatting, the adversarial tactic where attackers register domain names that mimic popular ones, has been observed for decades. However, there has been growing anecdotal evidence that this style of attack has spread to other domains. In this paper, we explore the presence of squatting attacks in the mobile app ecosystem. In "App Squatting", attackers release apps with identifiers (e.g., app name or package name) that are confusingly similar to those of popular apps or well-known Internet brands. This paper presents the first in-depth measurement study of app squatting showing its prevalence and implications. We first identify 11 common deformation approaches of app squatters and propose "AppCrazy", a tool for automatically generating variations of app identifiers. We have applied AppCrazy to the top-500 most popular apps in Google Play, generating 224,322 deformation keywords which we then use to test for app squatters on popular markets. Through this, we confirm the scale of the problem, identifying 10,553 squatting apps (an average of over 20 squatting apps for each legitimate one). Our investigation reveals that more than 51% of the squatting apps are malicious, with some being extremely popular (up to 10 million downloads). Meanwhile, we also find that mobile app markets have not been successful in identifying and eliminating squatting apps. Our findings demonstrate the urgency to identify and prevent app squatting abuses. To this end, we have publicly released all the identified squatting apps, as well as our tool AppCrazy. CCS CONCEPTS • Security and privacy → Software and application security; • Human-centered computing → Empirical studies in ubiquitous and mobile computing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Demystifying Illegal Mobile Gambling AppsYuhao Gao, Haoyu Wang, Li Li, Xiapu Luo 等WWW 2021 · 被引用 30 次
- CHAMP: Characterizing Undesired App Behaviors from User Comments based on Market PoliciesYangyu Hu, Haoyu Wang, Tiantong Ji, Xusheng Xiao 等ICSE 2021 · 被引用 19 次
- Not Seen, Not Heard in the Digital World! Measuring Privacy Practices in Children's AppsRuoxi Sun, Minhui Xue, Gareth Tyson, Shuo Wang 等WWW 2023 · 被引用 15 次
- LoneNeuron: A Highly-Effective Feature-Domain Neural Trojan Using Invisible and Polymorphic WatermarksZeyan Liu, Fengjun Li, Zhu Li, Bo LuoCCS 2022 · 被引用 12 次
- The Imitation Game: Exploring Brand Impersonation Attacks on Social Media PlatformsBhupendra Acharya, Dario Lazzaro, Efrén López-Morales, Adam Oest 等USENIX Security 2024 · 被引用 7 次
它引用的顶会 Paper3
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen 等CCS 2017 · 被引用 166 次
- Investigating Commercial Pay-Per-Install and the Distribution of Unwanted SoftwareKurt Thomas, Juan A. Elices Crespo, Ryan Rasti, Jean-Michel Picod 等USENIX Security 2016 · 被引用 77 次
- DeepIntent: Deep Icon-Behavior Learning for Detecting Intention-Behavior Discrepancy in Mobile AppsShengqu Xi, Shao Yang, Xusheng Xiao, Yuan Yao 等CCS 2019 · 被引用 74 次
相关 Paper
- Measuring and Mitigating the Risk of IP Reuse on Public CloudsEric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke 等S&P 2022 · 被引用 22 次
- The Many Kinds of Creepware Used for Interpersonal AttacksKevin A. Roundy, Paula Barmaimon Mendelberg, Nicola Dell, Damon McCoy 等S&P 2020 · 被引用 46 次
- Exploring the Unchartered Space of Container Registry TyposquattingGuannan Liu, Xing Gao, Haining Wang, Kun SunUSENIX Security 2022
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo 等FSE 2020 · 被引用 22 次
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang 等CCS 2017 · 被引用 60 次
