作者: Siegfried Rasthofer , Steven Arzt , Max Kolhagen , Brian Pfretzschner , Stephan Huber
关键词:
摘要: The Android platform now features more than a million apps from thousands of developers. This abundance is convenient, as it caters to almost every need. But users and researchers also worry about the security trustworthiness these apps. While precise program-analysis tools are helpful in this context, unfortunately they do not scale large number present current app stores. In work we thus DroidSearch, search engine that aids multi-staged analysis which fast pre-filtering techniques allow experts quickly retrieve candidate applications should be subjected further automated and/or manual analysis. DroidSearch supported by DroidBase, middleware back-end database associates with metadata results lightweight analyses on bytecode configuration files DroidBase automatically manages executes. Experiments 235,000 six different application stores including Google Play reveal many interesting findings. For instance, identifies 40 known malware detects over 35,000 use both http https connections for accessing same resources, effectively rendering protection ineffective. It reveals 11,995 providing access potentially sensitive data through unprotected content providers.