CADDroid: an efficient android app collusion dataset to instigate the development of modern malware detection methodologies
摘要
The ubiquity of Android devices has made them a prime target for malicious activities, ranging from traditional malware to sophisticated colluding apps. Colluding apps collaborate to exploit permissions and thereby pose significant security risks. The development of advanced detection methodologies targeting the app collusions involve complications as: (i) they constantly evolve; (ii) the relevant samples are lesser in numbers; and (iii) the available datasets are limited to the most prominent and familiar ways leaving few significant ones. Considering the same, in this paper, we aim to fill this void by creating a new dataset named “CADDroid” that focuses on AIDL, Unix Socket, Sticky Broadcast, and WebView. We believe that this dataset can be utilized to train/develop modern detection methodologies targeting them. To realize this, we have manually created 76 app pairs that exhibit collusion which include 24, 24, 26, and 2 app pairs exploiting AIDL, Unix Socket, Sticky Broadcast, and WebView respectively. As the created apps can extract 31 distinct types of sensitive information, we have also validated them by installing them on devices with various Android versions. Furthermore, on scanning the developed apps with VirusTotal and FlowDroid, we have noticed that they have not exposed any of the exhibited colluding behaviours. This highlights the capability of CADDroid in the current scenario and the potential of it to be considered for the development of modern malware detection methodologies. Besides, we have also discussed the potential attack vector space of the proposed work in real-life scenario.