{"id":"https://openalex.org/W2008345765","doi":"https://doi.org/10.1145/2810103.2813648","title":"Hare Hunting in the Wild Android","display_name":"Hare Hunting in the Wild Android","publication_year":2015,"publication_date":"2015-10-06","ids":{"openalex":"https://openalex.org/W2008345765","doi":"https://doi.org/10.1145/2810103.2813648","mag":"2008345765"},"language":"en","primary_location":{"id":"doi:10.1145/2810103.2813648","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2810103.2813648","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5007570332","display_name":"Yousra Aafer","orcid":null},"institutions":[{"id":"https://openalex.org/I70983195","display_name":"Syracuse University","ror":"https://ror.org/025r5qe02","country_code":"US","type":"education","lineage":["https://openalex.org/I70983195"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yousra Aafer","raw_affiliation_strings":["Syracuse University, Syracuse, NY, USA"],"affiliations":[{"raw_affiliation_string":"Syracuse University, Syracuse, NY, USA","institution_ids":["https://openalex.org/I70983195"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100641132","display_name":"Nan Zhang","orcid":"https://orcid.org/0000-0001-9620-5665"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nan Zhang","raw_affiliation_strings":["Indiana University, Bloomington, Bloomington, IN, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University, Bloomington, Bloomington, IN, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101491801","display_name":"Zhongwen Zhang","orcid":"https://orcid.org/0000-0002-2029-5876"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhongwen Zhang","raw_affiliation_strings":["Chinese Academy of Sciences, Beijing, China","Chinese Academy of Sciences , Beijing, China"],"affiliations":[{"raw_affiliation_string":"Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I19820366"]},{"raw_affiliation_string":"Chinese Academy of Sciences , Beijing, China","institution_ids":["https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100320944","display_name":"Xiao Zhang","orcid":"https://orcid.org/0000-0003-3802-8300"},"institutions":[{"id":"https://openalex.org/I70983195","display_name":"Syracuse University","ror":"https://ror.org/025r5qe02","country_code":"US","type":"education","lineage":["https://openalex.org/I70983195"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiao Zhang","raw_affiliation_strings":["Syracuse University, Syracuse, NY, USA"],"affiliations":[{"raw_affiliation_string":"Syracuse University, Syracuse, NY, USA","institution_ids":["https://openalex.org/I70983195"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100438001","display_name":"Kai Chen","orcid":"https://orcid.org/0000-0003-2587-6028"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kai Chen","raw_affiliation_strings":["Chinese Academy of Sciences, Beijing, China","Chinese Academy of Sciences , Beijing, China"],"affiliations":[{"raw_affiliation_string":"Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I19820366"]},{"raw_affiliation_string":"Chinese Academy of Sciences , Beijing, China","institution_ids":["https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100333259","display_name":"Xiaofeng Wang","orcid":"https://orcid.org/0000-0003-0091-3865"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"XiaoFeng Wang","raw_affiliation_strings":["Indiana University, Bloomington, Bloomington, IN, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University, Bloomington, Bloomington, IN, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064246785","display_name":"Xiaoyong Zhou","orcid":"https://orcid.org/0000-0001-6083-1381"},"institutions":[{"id":"https://openalex.org/I4210101778","display_name":"Samsung (United States)","ror":"https://ror.org/01bfbvm65","country_code":"US","type":"company","lineage":["https://openalex.org/I2250650973","https://openalex.org/I4210101778"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiaoyong Zhou","raw_affiliation_strings":["Samsung Research America, Mountain View, CA, USA","Samsung Research America, Mountain View, CA, USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Samsung Research America, Mountain View, CA, USA","institution_ids":["https://openalex.org/I4210101778"]},{"raw_affiliation_string":"Samsung Research America, Mountain View, CA, USA#TAB#","institution_ids":["https://openalex.org/I4210101778"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047825382","display_name":"Wenliang Du","orcid":"https://orcid.org/0000-0002-9234-0912"},"institutions":[{"id":"https://openalex.org/I70983195","display_name":"Syracuse University","ror":"https://ror.org/025r5qe02","country_code":"US","type":"education","lineage":["https://openalex.org/I70983195"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wenliang Du","raw_affiliation_strings":["Syracuse University, Syracuse, NY, USA"],"affiliations":[{"raw_affiliation_string":"Syracuse University, Syracuse, NY, USA","institution_ids":["https://openalex.org/I70983195"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5112308489","display_name":"Michael Grace","orcid":null},"institutions":[{"id":"https://openalex.org/I4210101778","display_name":"Samsung (United States)","ror":"https://ror.org/01bfbvm65","country_code":"US","type":"company","lineage":["https://openalex.org/I2250650973","https://openalex.org/I4210101778"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michael Grace","raw_affiliation_strings":["Samsung Research America, Mountain View, CA, USA","Samsung Research America, Mountain View, CA, USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Samsung Research America, Mountain View, CA, USA","institution_ids":["https://openalex.org/I4210101778"]},{"raw_affiliation_string":"Samsung Research America, Mountain View, CA, USA#TAB#","institution_ids":["https://openalex.org/I4210101778"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5007570332"],"corresponding_institution_ids":["https://openalex.org/I70983195"],"apc_list":null,"apc_paid":null,"fwci":6.3182,"has_fulltext":false,"cited_by_count":45,"citation_normalized_percentile":{"value":0.97108209,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1248","last_page":"1259"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9961000084877014,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.8417317867279053},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7044618129730225},{"id":"https://openalex.org/keywords/personalization","display_name":"Personalization","score":0.66899573802948},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.6411274671554565},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.6380943059921265},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5543215870857239},{"id":"https://openalex.org/keywords/android-malware","display_name":"Android malware","score":0.5074529051780701},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.464263916015625},{"id":"https://openalex.org/keywords/interdependence","display_name":"Interdependence","score":0.4338854253292084},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.1645110845565796}],"concepts":[{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.8417317867279053},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7044618129730225},{"id":"https://openalex.org/C183003079","wikidata":"https://www.wikidata.org/wiki/Q1000371","display_name":"Personalization","level":2,"score":0.66899573802948},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.6411274671554565},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6380943059921265},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5543215870857239},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.5074529051780701},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.464263916015625},{"id":"https://openalex.org/C185874996","wikidata":"https://www.wikidata.org/wiki/Q269699","display_name":"Interdependence","level":2,"score":0.4338854253292084},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.1645110845565796},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/2810103.2813648","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2810103.2813648","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6899999976158142,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G2763279455","display_name":null,"funder_award_id":"1117106,1223477,1223495,1318814,1527141","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7641299044","display_name":null,"funder_award_id":"61100226","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":21,"referenced_works":["https://openalex.org/W69349185","https://openalex.org/W124941384","https://openalex.org/W1630356589","https://openalex.org/W1912565424","https://openalex.org/W1935358945","https://openalex.org/W1994588724","https://openalex.org/W2008810193","https://openalex.org/W2010395842","https://openalex.org/W2012813306","https://openalex.org/W2023446630","https://openalex.org/W2027538101","https://openalex.org/W2059278087","https://openalex.org/W2113115074","https://openalex.org/W2114275288","https://openalex.org/W2136954161","https://openalex.org/W2148009765","https://openalex.org/W2156858199","https://openalex.org/W2166743230","https://openalex.org/W2398484989","https://openalex.org/W2399891510","https://openalex.org/W2914982603"],"related_works":["https://openalex.org/W2782775281","https://openalex.org/W4312334973","https://openalex.org/W2560361988","https://openalex.org/W1963923654","https://openalex.org/W1974604873","https://openalex.org/W2507113366","https://openalex.org/W4327939473","https://openalex.org/W2085301524","https://openalex.org/W2717179875","https://openalex.org/W4249118297"],"abstract_inverted_index":{"Android":[0,56,78,86,113,177,260],"is":[1,51,133],"characterized":[2],"by":[3,24,158,227,249],"the":[4,18,66,75,82,92,139,151,162,165,179,187,192,207,236,253,269,273,277,286,296],"complicated":[5],"relations":[6,39],"among":[7,84],"its":[8,22,27],"components":[9,87],"and":[10,36,81,88,202,216,234,294],"apps,":[11],"through":[12],"which":[13,120],"one":[14],"party":[15,140],"interacts":[16],"with":[17,117,231],"other":[19],"(e.g.,":[20,129,248],"starting":[21],"activity)":[23],"referring":[25],"to":[26,53,58,65,91,153,185,238,241,288],"attributes":[28,229,240],"like":[29],"package,":[30],"activity,":[31],"service,":[32],"action":[33],"names,":[34],"authorities":[35],"permissions.":[37,212],"Such":[38],"can":[40,149,181],"be":[41],"easily":[42],"compromised":[43],"during":[44],"a":[45,59,99,130,136,146,219],"customization:":[46],"e.g.,":[47],"when":[48,126,302],"an":[49,55,127,282],"app":[50,67,148,283],"removed":[52],"fit":[54],"version":[57],"new":[60,220],"device":[61,137],"model,":[62],"while":[63],"references":[64,97,237],"remain":[68],"inside":[69],"that":[70,111,174],"OS.":[71],"This":[72],"conflict":[73],"between":[74],"decentralized,":[76],"unregulated":[77],"customization":[79],"process":[80],"interdependency":[83],"different":[85,292],"apps":[89],"leads":[90],"pervasiveness":[93],"of":[94,101,164,225,272],"hanging":[95],"attribute":[96,128],"(Hares),":[98],"type":[100],"vulnerabilities":[102],"never":[103],"investigated":[104],"before.":[105],"In":[106],"our":[107,172],"research,":[108],"we":[109,169,279],"show":[110],"popular":[112,259],"devices":[114,293],"are":[115],"riddled":[116],"such":[118],"flaws,":[119,267],"often":[121],"have":[122,245],"serious":[123],"security":[124],"implications:":[125],"package/authority/action":[131],"name)":[132],"used":[134],"on":[135,175,291],"but":[138],"defining":[141],"it":[142],"has":[143],"been":[144,246],"removed,":[145],"malicious":[147],"fill":[150],"gap":[152],"acquire":[154],"critical":[155],"system":[156],"capabilities,":[157],"simply":[159],"disguising":[160],"as":[161],"owner":[163],"attribute.":[166],"More":[167],"specifically,":[168],"discovered":[170,263],"in":[171],"research":[173],"various":[176],"devices,":[178,261],"malware":[180],"exploit":[182,289],"their":[183],"Hares":[184,226,290],"steal":[186],"user's":[188,208],"voice":[189],"notes,":[190],"control":[191],"screen":[193],"unlock":[194],"process,":[195],"replace":[196],"Google":[197],"Email's":[198],"account":[199],"settings":[200],"activity":[201],"collect":[203],"or":[204],"even":[205],"modify":[206],"contact":[209],"without":[210],"proper":[211],"We":[213],"further":[214,280],"designed":[215],"implemented":[217],"Harehunter,":[218],"tool":[221],"for":[222,256,284,298],"automatic":[223],"detection":[224],"comparing":[228],"defined":[230],"those":[232],"used,":[233],"analyzing":[235],"undefined":[239],"determine":[242],"whether":[243],"they":[244],"protected":[247],"signature":[250],"checking).":[251],"On":[252],"factory":[254],"images":[255],"97":[257],"most":[258],"Harehunter":[262],"21557":[264],"likely":[265],"Hare":[266],"demonstrating":[268],"significant":[270],"impacts":[271],"problem.":[274],"To":[275],"mitigate":[276],"hazards,":[278],"developed":[281],"detecting":[285],"attempts":[287],"provide":[295],"guidance":[297],"avoiding":[299],"this":[300],"pitfall":[301],"building":[303],"future":[304],"systems.":[305]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":6},{"year":2020,"cited_by_count":4},{"year":2019,"cited_by_count":4},{"year":2018,"cited_by_count":9},{"year":2017,"cited_by_count":6},{"year":2016,"cited_by_count":7}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
