首页> 外文期刊>Computers & Security >Automated analysis of freeware installers promoted by download portals
【24h】

Automated analysis of freeware installers promoted by download portals

机译:自动分析下载门户网站推广的免费软件安装程序

获取原文
获取原文并翻译 | 示例
           

摘要

We present an analysis system for studying Windows application installers. The analysis system is fully automated from installer download to execution and data collection. The system emulates the behavior of a lazy user who wants to finish the installation dialogs with the default options and with as few clicks as possible. The UI automation makes use of image recognition techniques and heuristics. During the installation, the system collects data about the system modification and network access. The analysis system is scalable and can run on bare-metal hosts as well as in a data center. We use the system to analyze 792 freeware application installers obtained from popular download portals. In particular, we measure how many of them drop potentially unwanted programs (PUP) such as browser plugins or make other unwanted system modifications. We discover that most installers that download executable files over the network are vulnerable to man-in-the-middle attacks. We also find, that while popular download portals are not used for blatant malware distribution, nearly 10% of the analyzed installers come with a third-party browser or a browser extension. (C) 2018 The Author(s). Published by Elsevier Ltd.
机译:我们提供了一个用于研究Windows应用程序安装程序的分析系统。从安装程序下载到执行和数据收集,该分析系统是全自动的。系统模拟了一个懒惰用户的行为,该用户希望使用默认选项并尽可能少地单击以完成安装对话框。 UI自动化利用图像识别技术和启发式技术。在安装过程中,系统会收集有关系统修改和网络访问的数据。该分析系统具有可扩展性,可以在裸机主机以及数据中心中运行。我们使用该系统分析从流行的下载门户获得的792个免费软件应用程序安装程序。特别是,我们测量其中有多少个会丢弃潜在有害程序(PUP),例如浏览器插件或进行其他有害系统修改。我们发现大多数通过网络下载可执行文件的安装程序都容易受到中间人攻击。我们还发现,尽管不使用流行的下载门户来进行公然的恶意软件分发,但将近10%的被分析安装程序带有第三方浏览器或浏览器扩展。 (C)2018作者。由Elsevier Ltd.发布

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号