{"id":"https://openalex.org/W2951413859","doi":"https://doi.org/10.1145/3307334.3326094","title":"Understanding and Detecting Overlay-based Android Malware at Market Scales","display_name":"Understanding and Detecting Overlay-based Android Malware at Market Scales","publication_year":2019,"publication_date":"2019-06-12","ids":{"openalex":"https://openalex.org/W2951413859","doi":"https://doi.org/10.1145/3307334.3326094","mag":"2951413859"},"language":"en","primary_location":{"id":"doi:10.1145/3307334.3326094","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3307334.3326094","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 17th Annual International Conference on Mobile Systems, Applications, and Services","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5010768718","display_name":"Yuxuan Yan","orcid":"https://orcid.org/0009-0004-2803-738X"},"institutions":[{"id":"https://openalex.org/I2250653659","display_name":"Tencent (China)","ror":"https://ror.org/00hhjss72","country_code":"CN","type":"company","lineage":["https://openalex.org/I2250653659"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yuxuan Yan","raw_affiliation_strings":["Tsinghua University &amp; Tencent Mobile Security, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University &amp; Tencent Mobile Security, Beijing, China","institution_ids":["https://openalex.org/I99065089","https://openalex.org/I2250653659"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100357922","display_name":"Zhenhua Li","orcid":"https://orcid.org/0000-0001-7286-122X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhenhua Li","raw_affiliation_strings":["Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063270515","display_name":"Qi Alfred Chen","orcid":"https://orcid.org/0000-0003-0316-9285"},"institutions":[{"id":"https://openalex.org/I204250578","display_name":"University of California, Irvine","ror":"https://ror.org/04gyf1771","country_code":"US","type":"education","lineage":["https://openalex.org/I204250578"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qi Alfred Chen","raw_affiliation_strings":["University of California, Irvine, Irvine, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Irvine, Irvine, CA, USA","institution_ids":["https://openalex.org/I204250578"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072703507","display_name":"Christo Wilson","orcid":"https://orcid.org/0000-0002-5268-004X"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Christo Wilson","raw_affiliation_strings":["Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027605695","display_name":"Tianyin Xu","orcid":"https://orcid.org/0000-0003-4443-8170"},"institutions":[{"id":"https://openalex.org/I157725225","display_name":"University of Illinois Urbana-Champaign","ror":"https://ror.org/047426m28","country_code":"US","type":"education","lineage":["https://openalex.org/I157725225"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tianyin Xu","raw_affiliation_strings":["UIUC, Urbana-Champaign, IL, USA"],"affiliations":[{"raw_affiliation_string":"UIUC, Urbana-Champaign, IL, USA","institution_ids":["https://openalex.org/I157725225"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103040133","display_name":"Ennan Zhai","orcid":"https://orcid.org/0000-0003-4352-7497"},"institutions":[{"id":"https://openalex.org/I4210095624","display_name":"Alibaba Group (United States)","ror":"https://ror.org/00rn0m335","country_code":"US","type":"company","lineage":["https://openalex.org/I4210095624","https://openalex.org/I45928872"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ennan Zhai","raw_affiliation_strings":["Alibaba Group, Seattle, WA, USA"],"affiliations":[{"raw_affiliation_string":"Alibaba Group, Seattle, WA, USA","institution_ids":["https://openalex.org/I4210095624"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100355277","display_name":"Yong Li","orcid":"https://orcid.org/0000-0001-5617-1659"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yong Li","raw_affiliation_strings":["Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101877971","display_name":"Yunhao Liu","orcid":"https://orcid.org/0000-0002-6262-3313"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yunhao Liu","raw_affiliation_strings":["Michigan State University &amp; Tsinghua University, East Lansing, MI, USA"],"affiliations":[{"raw_affiliation_string":"Michigan State University &amp; Tsinghua University, East Lansing, MI, USA","institution_ids":["https://openalex.org/I87216513"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5010768718"],"corresponding_institution_ids":["https://openalex.org/I2250653659","https://openalex.org/I99065089"],"apc_list":null,"apc_paid":null,"fwci":2.322,"has_fulltext":false,"cited_by_count":35,"citation_normalized_percentile":{"value":0.89198478,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"168","last_page":"179"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9886999726295471,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9771999716758728,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/overlay","display_name":"Overlay","score":0.8844901919364929},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8062560558319092},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7912953495979309},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.6408891677856445},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.44784748554229736},{"id":"https://openalex.org/keywords/overlay-network","display_name":"Overlay network","score":0.44473928213119507},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.23696482181549072},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.21126660704612732},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.0911514163017273}],"concepts":[{"id":"https://openalex.org/C136085584","wikidata":"https://www.wikidata.org/wiki/Q910289","display_name":"Overlay","level":2,"score":0.8844901919364929},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8062560558319092},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7912953495979309},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.6408891677856445},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.44784748554229736},{"id":"https://openalex.org/C169851745","wikidata":"https://www.wikidata.org/wiki/Q1331985","display_name":"Overlay network","level":3,"score":0.44473928213119507},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.23696482181549072},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.21126660704612732},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.0911514163017273}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3307334.3326094","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3307334.3326094","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 17th Annual International Conference on Mobile Systems, Applications, and Services","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":38,"referenced_works":["https://openalex.org/W59191864","https://openalex.org/W1450860479","https://openalex.org/W1486263771","https://openalex.org/W1522250664","https://openalex.org/W1582716752","https://openalex.org/W1744020988","https://openalex.org/W1943233084","https://openalex.org/W2013735525","https://openalex.org/W2016216904","https://openalex.org/W2025721496","https://openalex.org/W2032616120","https://openalex.org/W2038304148","https://openalex.org/W2090465075","https://openalex.org/W2099468260","https://openalex.org/W2101800210","https://openalex.org/W2102012364","https://openalex.org/W2148519244","https://openalex.org/W2158874007","https://openalex.org/W2163643194","https://openalex.org/W2167661907","https://openalex.org/W2324464293","https://openalex.org/W2330820318","https://openalex.org/W2399891510","https://openalex.org/W2400528202","https://openalex.org/W2407386804","https://openalex.org/W2589988760","https://openalex.org/W2616594753","https://openalex.org/W2700054830","https://openalex.org/W2734718887","https://openalex.org/W2805843504","https://openalex.org/W2888121333","https://openalex.org/W2890078096","https://openalex.org/W2904287723","https://openalex.org/W2911964244","https://openalex.org/W2949464457","https://openalex.org/W3085162807","https://openalex.org/W4256148631","https://openalex.org/W6843735874"],"related_works":["https://openalex.org/W89955905","https://openalex.org/W2717179875","https://openalex.org/W4249118297","https://openalex.org/W1691715735","https://openalex.org/W1637847238","https://openalex.org/W2042060105","https://openalex.org/W2126533264","https://openalex.org/W2122565901","https://openalex.org/W2041341978","https://openalex.org/W2749656779"],"abstract_inverted_index":{"As":[0],"a":[1,86,172,197,247],"key":[2],"UI":[3],"feature":[4],"of":[5,24,62,78,96,114,129,134,136,156,174,183,216],"Android,":[6],"overlay":[7,157,176],"enables":[8],"one":[9,215],"app":[10,101,106,221],"to":[11,48,75,91,202,223],"draw":[12],"over":[13],"other":[14],"apps":[15,35,46,163,229],"by":[16,44,72,190,214],"creating":[17],"an":[18],"extra":[19],"View":[20],"layer":[21],"on":[22,58],"top":[23],"the":[25,37,60,65,76,93,100,105,112,125,140,151,181,191,217],"host":[26],"View.":[27],"While":[28],"greatly":[29],"facilitating":[30],"user":[31],"interactions":[32],"with":[33,180],"multiple":[34],"at":[36,64,99,207],"same":[38],"time,":[39],"it":[40],"is":[41,90,200],"often":[42],"exploited":[43],"malicious":[45,137,162],"(malware)":[47],"attack":[49],"users.":[50],"To":[51,82,142],"combat":[52],"this":[53,84,130,144,147],"threat,":[54],"prior":[55],"countermeasures":[56],"concentrate":[57],"restricting":[59],"capabilities":[61,113],"overlays":[63,115,138],"OS":[66],"level,":[67],"while":[68],"barely":[69],"seeing":[70],"adoption":[71],"Android":[73,220],"due":[74],"concern":[77],"sacrificing":[79],"overlays'":[80],"usability.":[81],"address":[83],"dilemma,":[85],"more":[87],"pragmatic":[88],"approach":[89,131],"enable":[92],"early":[94],"detection":[95],"overlay-based":[97,205,244],"malware":[98,206,245],"market":[102,208],"level":[103],"during":[104],"review":[107],"process,":[108],"so":[109],"that":[110,199],"all":[111,242],"can":[116,233],"stay":[117],"unchanged.":[118],"Unfortunately,":[119],"little":[120],"has":[121,211],"been":[122,212],"known":[123],"about":[124],"feasibility":[126],"and":[127,161,166],"effectiveness":[128],"for":[132],"lack":[133],"understanding":[135],"in":[139,146,159],"wild.":[141],"fill":[143],"gap,":[145],"paper":[148],"we":[149,194],"perform":[150],"first":[152],"large-scale":[153],"comparative":[154],"study":[155,192],"characteristics":[158],"benign":[160],"using":[164,246],"static":[165],"dynamic":[167],"analyses.":[168],"Our":[169],"results":[170],"reveal":[171],"set":[173],"suspicious":[175],"properties":[177],"strongly":[178],"correlated":[179],"malice":[182],"apps,":[184],"including":[185],"several":[186],"novel":[187],"features.":[188],"Guided":[189],"insights,":[193],"build":[195],"OverlayChecker,":[196],"system":[198],"able":[201],"automatically":[203],"detect":[204,240],"scales.":[209],"OverlayChecker":[210],"adopted":[213],"world's":[218],"largest":[219],"stores":[222],"check":[224],"around":[225],"10K":[226],"newly":[227],"submitted":[228],"per":[230,238],"day.":[231],"It":[232],"efficiently":[234],"(within":[235],"2":[236],"minutes":[237],"app)":[239],"nearly":[241],"(96%)":[243],"single":[248],"commodity":[249],"server.":[250]},"counts_by_year":[{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":6},{"year":2012,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
