%0 Conference Proceedings %T FSquaDRA: Fast Detection of Repackaged Applications %+ Università degli Studi di Trento = University of Trento (UNITN) %+ University of Luxembourg [Luxembourg] %A Zhauniarovich, Yury %A Gadyatskaya, Olga %A Crispo, Bruno %A La Spina, Francesco %A Moser, Ermanno %< avec comité de lecture %( Lecture Notes in Computer Science %B 28th IFIP Annual Conference on Data and Applications Security and Privacy (DBSec) %C Vienna, Austria %Y David Hutchison %Y Takeo Kanade %Y Bernhard Steffen %Y Demetri Terzopoulos %Y Doug Tygar %Y Gerhard Weikum %Y Vijay Atluri %Y Günther Pernul %Y Josef Kittler %Y Jon M. Kleinberg %Y Alfred Kobsa %Y Friedemann Mattern %Y John C. Mitchell %Y Moni Naor %Y Oscar Nierstrasz %Y C. Pandu Rangan %I Springer %3 Data and Applications Security and Privacy XXVIII %V LNCS-8566 %P 130-145 %8 2014-07-14 %D 2014 %R 10.1007/978-3-662-43936-4_9 %K Smartphones %K Repackaging %K Mobile applications %Z Computer Science [cs]Conference papers %X The ease of Android applications repackaging and proliferation of application clones in Google Play and other markets call for new effective techniques to detect repackaged code and combat distribution of cloned applications. Today all existing techniques for repackaging detection are based on code similarity or feature (e.g., permission set) similarity evaluation. We propose a new approach to detect repackaging based on the resource files available in application packages. Our tool called FSquaDRA performs a quick pairwise application comparison (full pairwise comparison for 55,000 applications in just 80 hours on a laptop), as it measures how many identical resources are present inside both packages under analysis. The intuition behind our approach is that malicious repackaged applications still need to maintain the “look and feel” of the originals by including the same images and other resource files, even though they might have additional code included or some of the original code removed.To evaluate the reliability of our approach we perform a comparison of the FSquaDRA similarity scores with the code-based similarity scores of AndroGuard for a dataset of randomly selected application pairs, and our results demonstrate strong positive correlation of the FSquaDRA resource-based score with the code-based similarity score. %G English %Z TC 11 %Z WG 11.3 %2 https://inria.hal.science/hal-01285035/document %2 https://inria.hal.science/hal-01285035/file/978-3-662-43936-4_9_Chapter.pdf %L hal-01285035 %U https://inria.hal.science/hal-01285035 %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-WG %~ IFIP-TC11 %~ IFIP-LNCS-8566 %~ IFIP-WG11-3