FairPlay: Fraud and malware detection in Google Play Conference

Rahman, M, Rahman, M, Carbunar, B et al. (2016). FairPlay: Fraud and malware detection in Google Play . 99-107. 10.1137/1.9781611974348.12

cited authors

  • Rahman, M; Rahman, M; Carbunar, B; Chau, DH

abstract

  • Fraudulent behaviors in Google's Android app market fuel search rank abuse and malware proliferation. We present FairPlay, a novel system that uncovers both malware and search rank fraud apps, by picking out trails that fraudsters leave behind. To identify suspicious apps, FairPlay's PCF algorithm correlates review activities and uniquely combines detected review relations with linguistic and behavioral signals gleaned from longitudinal Google Play app data. We contribute a new longitudinal app dataset to the community, which consists of over 87K apps, 2.9M reviews, and 2.4M reviewers, collected over half a year. FairPlay achieves over 95% accuracy in classifying gold standard datasets of malware, fraudulent and legitimate apps. We show that 75% of the identified malware apps engage in search rank fraud. FairPlay discovers hundreds of fraudulent apps that currently evade Google Bouncer's detection technology, and reveals a new type of attack campaign, where users are harassed into writing positive reviews, and install and review other apps.

publication date

  • January 1, 2016

Digital Object Identifier (DOI)

start page

  • 99

end page

  • 107