Full text
Preview |
PDF
- Requires a PDF viewer, such as GSview, Xpdf or Adobe Acrobat Reader
Download (350kB) | Preview |
Kotzias, Platon Pantelis and Bilge, Leyla and Caballero Pérez, Juan (2016). Measuring PUP Prevalence and PUP Distribution through Pay-Per-Install Services. In: "25th USENIX Security Symposium", 10/08/2016-12/08/2016, Austin, Texas, EE.UU.. ISBN 978-1-931971-32-4. pp. 739-756.
Title: | Measuring PUP Prevalence and PUP Distribution through Pay-Per-Install Services |
---|---|
Author/s: |
|
Item Type: | Presentation at Congress or Conference (Article) |
Event Title: | 25th USENIX Security Symposium |
Event Dates: | 10/08/2016-12/08/2016 |
Event Location: | Austin, Texas, EE.UU. |
Title of Book: | Proceedings of the 25th USENIX Security Symposium |
Date: | 2016 |
ISBN: | 978-1-931971-32-4 |
Subjects: | |
Faculty: | E.T.S.I. de Sistemas Informáticos (UPM) |
Department: | Otro |
Creative Commons Licenses: | Recognition - No derivative works - Non commercial |
Preview |
PDF
- Requires a PDF viewer, such as GSview, Xpdf or Adobe Acrobat Reader
Download (350kB) | Preview |
Potentially unwanted programs (PUP) such as adware and rogueware, while not outright malicious, exhibit intrusive behavior that generates user complaints and makes security vendors flag them as undesirable. PUP has been little studied in the research literature despite recent indications that its prevalence may have surpassed that of malware. In this work we perform the first systematic study of PUP prevalence and its distribution through pay-perinstall (PPI) services, which link advertisers that want to promote their programs with affiliate publishers willing to bundle their programs with offers for other software. Using AV telemetry information comprising of 8 billion events on 3.9 million real hosts during a 19 month period, we discover that over half (54%) of the examined hosts have PUP installed. PUP publishers are highly popular, e.g., the top two PUP publishers rank 15 and 24 amongst all software publishers (benign and PUP). Furthermore, we analyze the who-installs-who relationships, finding that 65% of PUP downloads are performed by other PUP and that 24 PPI services distribute over a quarter of all PUP. We also examine the top advertiser programs distributed by the PPI services, observing that they are dominated by adware running in the browser (e.g., toolbars, extensions) and rogueware. Finally, we investigate the PUP-malware relationships in the form of malware installations by PUP and PUP installations by malware. We conclude that while such events exist, PUP distribution is largely disjoint from malware distribution.
Item ID: | 55065 |
---|---|
DC Identifier: | https://oa.upm.es/55065/ |
OAI Identifier: | oai:oa.upm.es:55065 |
Official URL: | https://www.usenix.org/conference/usenixsecurity16... |
Deposited by: | Memoria Investigacion |
Deposited on: | 29 Jan 2020 11:51 |
Last Modified: | 30 Nov 2022 09:00 |