Skip to main content

2017 | OriginalPaper | Buchkapitel

A Large-Scale Analysis of Download Portals and Freeware Installers

verfasst von : Alberto Geniola, Markku Antikainen, Tuomas Aura

Erschienen in: Secure IT Systems

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

We present a large-scale study of Windows freeware installers. In particular, we look for potentially unwanted programs (PUP) and other potentially unwanted modifications to the target system made by freeware installers. The analysis is based on almost 800 installers gathered from eight popular software download portals. We measure how many of them drop PUP, such as browser plugins, or make other modifications to the system. In addition to these results, we find that most installers that download executable files over the network are vulnerable to man-in-the-middle attacks, which in the worst cases may be used to execute arbitrary code with elevated privileges on the target system. Moreover, serious man-in-the-middle vulnerabilities are found in application managers provided by download portals.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
1
Potentially Unwanted Application (PUA) is another often used term.
 
Literatur
1.
Zurück zum Zitat Böhme, R., Köpsell, S.: Trained to accept? A field experiment on consent dialogs. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI 2010, pp. 2403–2406. ACM, New York (2010) Böhme, R., Köpsell, S.: Trained to accept? A field experiment on consent dialogs. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI 2010, pp. 2403–2406. ACM, New York (2010)
2.
Zurück zum Zitat Boldt, M., Carlsson, B.: Privacy-invasive software and preventive mechanisms. In: International Conference on Systems and Networks Communications, ICSNC 2006, p. 21, October 2006 Boldt, M., Carlsson, B.: Privacy-invasive software and preventive mechanisms. In: International Conference on Systems and Networks Communications, ICSNC 2006, p. 21, October 2006
3.
Zurück zum Zitat Bruce, J.: Defining rules for acceptable adware. In: Proceedings of the Fifteenth Virus Bulletin Conference (2005) Bruce, J.: Defining rules for acceptable adware. In: Proceedings of the Fifteenth Virus Bulletin Conference (2005)
4.
Zurück zum Zitat Caballero, J., Grier, C., Kreibich, C., Paxson, V.: Measuring pay-per-install: the commoditization of malware distribution. In: Proceedings of the 20th USENIX Conference on Security, SEC 2011, USENIX Association, Berkeley (2011) Caballero, J., Grier, C., Kreibich, C., Paxson, V.: Measuring pay-per-install: the commoditization of malware distribution. In: Proceedings of the 20th USENIX Conference on Security, SEC 2011, USENIX Association, Berkeley (2011)
7.
Zurück zum Zitat Good, N., Dhamija, R., Grossklags, J., Thaw, D., Aronowitz, S., Mulligan, D., Konstan, J.: Stopping spyware at the gate: a user study of privacy, notice and spyware. In: Proceedings of the 2005 Symposium on Usable Privacy and Security, SOUPS 2005, pp. 43–52. ACM, New York (2005) Good, N., Dhamija, R., Grossklags, J., Thaw, D., Aronowitz, S., Mulligan, D., Konstan, J.: Stopping spyware at the gate: a user study of privacy, notice and spyware. In: Proceedings of the 2005 Symposium on Usable Privacy and Security, SOUPS 2005, pp. 43–52. ACM, New York (2005)
8.
Zurück zum Zitat Goretsky, A.: Problematic, unloved and argumentative: what is a potentially unwanted application (PUA)? Technical report, November 2011. Accessed 03 June 2016 Goretsky, A.: Problematic, unloved and argumentative: what is a potentially unwanted application (PUA)? Technical report, November 2011. Accessed 03 June 2016
11.
Zurück zum Zitat Kotzias, P., Bilge, L., Caballero, J.: Measuring PUP prevalence and PUP distribution through Pay-Per-Install services. In: Proceedings of the USENIX Security Symposium (2016) Kotzias, P., Bilge, L., Caballero, J.: Measuring PUP prevalence and PUP distribution through Pay-Per-Install services. In: Proceedings of the USENIX Security Symposium (2016)
12.
Zurück zum Zitat Kotzias, P., Matic, S., Rivera, R., Caballero, J.: Certified PUP: abuse in authenticode code signing. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 465–478. ACM (2015) Kotzias, P., Matic, S., Rivera, R., Caballero, J.: Certified PUP: abuse in authenticode code signing. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 465–478. ACM (2015)
13.
Zurück zum Zitat McFedries, P.: Technically speaking: the spyware nightmare. IEEE Spectr. 42(8), 72–72 (2005)CrossRef McFedries, P.: Technically speaking: the spyware nightmare. IEEE Spectr. 42(8), 72–72 (2005)CrossRef
16.
Zurück zum Zitat Microsoft: Run, RunOnce, RunServices, RunServicesOnce and Startup, November 2006. Accessed 08 Dec 2016 Microsoft: Run, RunOnce, RunServices, RunServicesOnce and Startup, November 2006. Accessed 08 Dec 2016
17.
Zurück zum Zitat Motiee, S., Hawkey, K., Beznosov, K.: Do windows users follow the principle of least privilege? Investigating user account control practices. In: Proceedings of the Sixth Symposium on Usable Privacy and Security, p. 1. ACM (2010) Motiee, S., Hawkey, K., Beznosov, K.: Do windows users follow the principle of least privilege? Investigating user account control practices. In: Proceedings of the Sixth Symposium on Usable Privacy and Security, p. 1. ACM (2010)
20.
Zurück zum Zitat Thomas, K., Crespo, J.A.E., et al.: Investigating commercial pay-per-install and the distribution of unwanted software. In: 25th USENIX Security Symposium (USENIX Security 2016), pp. 721–739. USENIX Association, Austin, August 2016 Thomas, K., Crespo, J.A.E., et al.: Investigating commercial pay-per-install and the distribution of unwanted software. In: 25th USENIX Security Symposium (USENIX Security 2016), pp. 721–739. USENIX Association, Austin, August 2016
21.
Zurück zum Zitat Wood, P., Nahorney, B., Chandrasekar, K., Wallace, S., Haley, K., et al.: Symantec internet security threat report trends for 2016. Technical report, April 2016 Wood, P., Nahorney, B., Chandrasekar, K., Wallace, S., Haley, K., et al.: Symantec internet security threat report trends for 2016. Technical report, April 2016
Metadaten
Titel
A Large-Scale Analysis of Download Portals and Freeware Installers
verfasst von
Alberto Geniola
Markku Antikainen
Tuomas Aura
Copyright-Jahr
2017
DOI
https://doi.org/10.1007/978-3-319-70290-2_13