Title
Search Rank Fraud and Malware Detection in Google Play.
Abstract
Fraudulent behaviors in Google Play, the most popular Android app market, fuel search rank abuse and malware proliferation. To identify malware, previous work has focused on app executable and permission analysis. In this paper, we introduce FairPlay, a novel system that discovers and leverages traces left behind by fraudsters, to detect both malware and apps subjected to search rank fraud. FairPlay correlates review activities and uniquely combines detected review relations with linguistic and behavioral signals gleaned from Google Play app data (87 K apps, 2.9 M reviews, and 2.4M reviewers, collected over half a year), in order to identify suspicious apps. FairPlay achieves over 95 percent accuracy in classifying gold standard datasets of malware, fraudulent and legitimate apps. We show that 75 percent of the identified malware apps engage in search rank fraud. FairPlay discovers hundreds of fraudulent apps that currently evade Google Bouncer's detection technology. FairPlay also helped the discovery of more than 1,000 reviews, reported for 193 apps, that reveal a new type of “coercive” review campaign: users are harassed into writing positive reviews, and install and review other apps.
Year
DOI
Venue
2017
10.1109/TKDE.2017.2667658
IEEE Trans. Knowl. Data Eng.
Keywords
Field
DocType
Malware,Google,Feature extraction,Androids,Humanoid robots,Pragmatics,Gold
Cryptovirology,Android app,Permission,Data mining,World Wide Web,Internet privacy,Computer science,Malware,Executable
Journal
Volume
Issue
ISSN
29
6
1041-4347
Citations 
PageRank 
References 
6
0.53
16
Authors
4
Name
Order
Citations
PageRank
Md. Mahmudur Rahman165250.91
Mizanur Rahman212920.97
Bogdan Carbunar369953.79
Duen Horng Chau4126086.87