Duet: Library integrity verification for android applications

Wenhui Hu, Damien Octeau, Patrick Drew McDaniel, Peng Liu

Research output: Chapter in Book/Report/Conference proceedingConference contribution

21 Scopus citations

Abstract

In recent years, the Android operating system has had an explosive growth in the number of applications containing third-party libraries for different purposes. In this paper, we identify three library-centric threats in the real-world Android application markets: (i) the library modification threat, (ii) the masquerading threat and (iii) the aggressive library threat. These three threats cannot effectively be fully addressed by existing defense mechanisms such as software analysis, anti-virus software and anti-repackaging techniques. To mitigate these threats, we propose Duet, a library integrity verification tool for Android applications at application stores. This is non-trivial because the Android application build process merges library code and application-specific logic into a single binary file. Our approach uses reverse-engineering to achieve integrity verification. We implemented a full working prototype of Duet. In a dataset with 100,000 Android applications downloaded from Google Play between February 2012 and September 2013, we verify integrity of 15 libraries. On average, 80.50% of libraries can pass the integrity verification. In-depth analysis indicates that code insertion, obfuscation, and optimization on libraries by application developers are the primary reasons for not passing integrity verification. The evaluation results not only indicate that Duet is an effective tool to mitigate library-centric attacks, but also provide empirical insight into the library integrity situation in the wild.

Original languageEnglish (US)
Title of host publicationWiSec 2014 - Proceedings of the 7th ACM Conference on Security and Privacy in Wireless and Mobile Networks
PublisherAssociation for Computing Machinery
Pages141-152
Number of pages12
ISBN (Print)9781450329729
DOIs
StatePublished - 2014
Event7th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2014 - Oxford, United Kingdom
Duration: Jul 23 2014Jul 25 2014

Publication series

NameWiSec 2014 - Proceedings of the 7th ACM Conference on Security and Privacy in Wireless and Mobile Networks

Other

Other7th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2014
Country/TerritoryUnited Kingdom
CityOxford
Period7/23/147/25/14

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Duet: Library integrity verification for android applications'. Together they form a unique fingerprint.

Cite this