【WWW 2020】Mobile App Squatting

[WWW2020 Best Student Paper] Mobile App Squatting

移动APP蹲?

一、主要内容

In this paper, we explore the presence of squatting attacks in the mobile app ecosystem.In “App Squatting”, attackers release apps with identifiers (e.g.,app name or package name) that are confusingly similar to those of popular apps or well-known Internet brands.

提出了一种新型的攻击模式“APP蹲”。攻击者发布的应用程序的标识符(例如,应用程序名或包名)与流行应用程序或知名互联网品牌的标识符极为相似。

(印象中这种“蹲”模式的类似攻击模式有很多种)

二、相关定义

We define App Squatting as a type of squatting behavior where attackers release apps with identifiers that are confusingly similar
to those belonging to popular apps or large Internet brands.

我们将应用程序App Squatting 定义为一种抢占行为,攻击者释放的应用程序的标识符与流行应用程序或大型互联网品牌的标识符非常相似。

Based on the target of the squatting, we classify apps into app name squatting and package name squatting. 

根据抢占目标类型,我们将App Squatting分为应用名称蹲安装包名称蹲

(1) Fake Apps: Apps with an identical app or package name to legitimate apps, but with different developer signatures.
(2) Squatting Apps: Apps whose app or package name is confusingly similar (but unidentical) to the legitimate app.

三、模型算法

Thanks to our preliminary investigation,we have identified 11 squatting generation models for app identifiers.

(是在之前工作的基础上,将App Squatting分为11种类型)

As shown in Figure 2, these models can be classified  into two categories: (1) mutation-based squatting generation models,
and (2) combosquatting generation models.

 

  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 2
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值