A Large-scale Temporal Measurement of Android Malicious Apps: Persistence, Migration, and Lessons Learned
Yun Shen, Pierre-Antoine Vervier, Gianluca Stringhini

TL;DR
This study analyzes the long-term behavior of malicious Android apps, revealing that they often persist for weeks despite detection and removal efforts, and migrate across marketplaces, highlighting gaps in current security defenses.
Contribution
It provides the first large-scale, temporal analysis of Android PHAs, exposing delays in removal and migration patterns, and discusses implications for improving mobile security defenses.
Findings
PHAs persist on devices for an average of 24 days after detection.
There is an average delay of 77 days before PHAs are removed from Google Play.
PHAs migrate to other marketplaces after removal from original sources.
Abstract
We study the temporal dynamics of potentially harmful apps (PHAs) on Android by leveraging 8.8M daily on-device detections collected among 11.7M customers of a popular mobile security product between 2019 and 2020. We show that the current security model of Android, which limits security products to run as regular apps and prevents them from automatically removing malicious apps opens a significant window of opportunity for attackers. Such apps warn users about the newly discovered threats, but users do not promptly act on this information, allowing PHAs to persist on their device for an average of 24 days after they are detected. We also find that while app markets remove PHAs after these become known, there is a significant delay between when PHAs are identified and when they are removed: PHAs persist on Google Play for 77 days on average and 34 days on third party marketplaces.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · Spam and Phishing Detection
