AnDarwin: Scalable Detection of Android Application Clones Based on Semantics

被引:41
作者
Crussell, Jonathan [1 ]
Gibler, Clint [1 ]
Chen, Hao [1 ]
机构
[1] Univ Calif Davis, Comp Sci, Davis, CA 95616 USA
基金
美国国家科学基金会;
关键词
Program analysis; clustering; plagiarism detection; mobile applications;
D O I
10.1109/TMC.2014.2381212
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smartphones rely on their vibrant application markets; however, plagiarism threatens the long-term health of these markets. We present a scalable approach to detecting similar Android apps based on their semantic information. We implement our approach in a tool called AnDarwin and evaluate it on 265,359 apps collected from 17 markets including Google Play and numerous third-party markets. In contrast to earlier approaches, AnDarwin has four advantages: it avoids comparing apps pairwise, thus greatly improving its scalability; it analyzes only the app code and does not rely on other information-such as the app's market, signature, or description-thus greatly increasing its reliability; it can detect both full and partial app similarity; and it can automatically detect library code and remove it from the similarity analysis. We present two use cases for AnDarwin: finding similar apps by different developers ("clones") and similar apps from the same developer ("rebranded"). In 10 hours, AnDarwin detected at least 4,295 apps that are the victims of cloning and 36,106 rebranded apps. Additionally, AnDarwin detects similar code that is injected into many apps, which may indicate the spread of malware. Our evaluation demonstrates AnDarwin's ability to accurately detect similar apps on a large scale.
引用
收藏
页码:2007 / 2019
页数:13
相关论文
共 27 条
  • [1] Andoni A, 2006, ANN IEEE SYMP FOUND, P459
  • [2] Androguard, 2012, ANDR MAN PROT ANDR A
  • [3] [Anonymous], 2012, INT C DETECTION INTR
  • [4] [Anonymous], 2013, PROCEEDING 11 ANN IN, DOI 10.1145/2462456.2464461
  • [5] [Anonymous], 2012, SLID ANDR COMM APPL
  • [6] [Anonymous], 2012, P 2 ACM C DATA APPL, DOI DOI 10.1145/2133601.2133640
  • [7] [Anonymous], 2012, Mining of massive datasets
  • [8] AppBrain, 2012, NUMB AV ANDR APPL
  • [9] BajaBob, 2012, SMALIHOOK KAVA FOUND
  • [10] BAKER BS, 1995, SECOND WORKING CONFERENCE ON REVERSE ENGINEERING, PROCEEDINGS, P86, DOI 10.1109/WCRE.1995.514697