{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:55:19Z","timestamp":1742914519011,"version":"3.40.3"},"publisher-location":"Cham","reference-count":41,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030526825"},{"type":"electronic","value":"9783030526832"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-52683-2_10","type":"book-chapter","created":{"date-parts":[[2020,7,6]],"date-time":"2020-07-06T23:19:19Z","timestamp":1594077559000},"page":"192-214","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["On the Security of Application Installers and Online Software Repositories"],"prefix":"10.1007","author":[{"given":"Marcus","family":"Botacin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Bert\u00e3o","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paulo","family":"de Geus","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andr\u00e9","family":"Gr\u00e9gio","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,7,7]]},"reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"Al-Subaihin, A., et al.: App store mining and analysis. In: DeMobile. ACM (2015)","DOI":"10.1145\/2804345.2804346"},{"key":"10_CR2","unstructured":"Alexa: Top sites (2019). \nhttps:\/\/www.alexa.com\/topsites"},{"key":"10_CR3","doi-asserted-by":"crossref","unstructured":"Ali, M., Joorabchi, M.E., Mesbah, A.: Same app, different app stores: a comparative study. In: MOBILESoft. IEEE (2017)","DOI":"10.1109\/MOBILESoft.2017.3"},{"key":"10_CR4","doi-asserted-by":"crossref","unstructured":"Allix, K., Bissyand\u00e9, T.F., Klein, J., Le Traon, Y.: Androzoo: collecting millions of android apps for the research community. In: MSR. ACM (2016)","DOI":"10.1145\/2901739.2903508"},{"key":"10_CR5","unstructured":"Auto-it: Auto-it (2019). \nhttps:\/\/www.autoitscript.com"},{"key":"10_CR6","unstructured":"Bacchus, A., Porst, S., Mutchler, P.: Expanding bug bounties on google play. \nhttps:\/\/security.googleblog.com\/2019\/08\/expanding-bug-bounties-on-google-play.html\n\n (2019)"},{"issue":"1","key":"10_CR7","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/s11416-017-0292-8","volume":"14","author":"MF Botacin","year":"2017","unstructured":"Botacin, M.F., de Geus, P.L., Gr\u00e9gio, A.R.A.: The other guys: automated analysis of marginalized malware. J. Comput. Virol. Hack. Tech. 14(1), 87\u201398 (2017). \nhttps:\/\/doi.org\/10.1007\/s11416-017-0292-8","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"Bronchain, O., Dassy, L., Faust, S., Standaert, F.X.: Implementing trojan-resilient hardware from (mostly) untrusted components designed by colluding manufacturers. In: ASHES. ACM (2018)","DOI":"10.1145\/3266444.3266447"},{"key":"10_CR9","unstructured":"Cimpanu, C.: Malware found in arch linux aur package repository (2018). \nhttps:\/\/www.bleepingcomputer.com\/news\/security\/malware-found-in-arch-linux-aur-package-repository\/"},{"key":"10_CR10","unstructured":"Cnet: Cnet (2019). \nhttps:\/\/www.cnet.com\/"},{"key":"10_CR11","unstructured":"FileHippo: Filehippo (2019). \nhttps:\/\/www.filehippo.com"},{"key":"10_CR12","unstructured":"FileHorse: Filehorse (2019). \nhttps:\/\/www.filehorse.com"},{"key":"10_CR13","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1016\/j.cose.2018.03.010","volume":"77","author":"A Geniola","year":"2018","unstructured":"Geniola, A., Antikainen, M., Aura, T.: Automated analysis of freeware installers promoted by download portals. Comput. Secur. 77, 209\u2013225 (2018)","journal-title":"Comput. Secur."},{"key":"10_CR14","unstructured":"Google: Release updates from the chrome team (2019). \nhttps:\/\/chromereleases.googleblog.com\/"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"Gousios, G., Kalliamvakou, E., Spinellis, D.: Measuring developer contribution from software repository data. In: MSR. ACM (2008)","DOI":"10.1145\/1370750.1370781"},{"issue":"10","key":"10_CR16","doi-asserted-by":"publisher","first-page":"2758","DOI":"10.1093\/comjnl\/bxv047","volume":"58","author":"ARA Gr\u00e9gio","year":"2015","unstructured":"Gr\u00e9gio, A.R.A., Afonso, V.M., Filho, D.S.F., de Geus, P.L., Jino, M.: Toward a taxonomy of malware behaviors. Comput. J. 58(10), 2758\u20132777 (2015)","journal-title":"Comput. J."},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"Han, J., Chung, T., Kim, S., Kwon, T.T., Kim, H.C., Choi, Y.: How prevalent is content bundling in bittorrent. In: SIGMETRICS. ACM (2011)","DOI":"10.1145\/1993744.1993789"},{"key":"10_CR18","unstructured":"Hoffman, C.: Warning: Don\u2019t download software from sourceforge if you can help it [updated] (2018). \nhttps:\/\/www.howtogeek.com\/218764\/warning-don%E2%80%99t-download-software-from-sourceforge-if-you-can-help-it\/"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Kahved\u017ei\u0107, D., Kechadi, T.: On the persistence of deleted windows registry data structures. In: SAC. ACM (2009)","DOI":"10.15394\/jdfsl.2009.1057"},{"key":"10_CR20","unstructured":"Khandelwal, S.: New malware replaced legit android apps with fake ones on 25 m devices (2019). \nhttps:\/\/thehackernews.com\/2019\/07\/whatsapp-android-malware.html"},{"key":"10_CR21","doi-asserted-by":"crossref","unstructured":"Kim, D., Kim, Y., Moon, J., Cho, S.J., Woo, J., You, I.: Identifying windows installer package files for detection of pirated software. In: ICIMISUComp (2014)","DOI":"10.1109\/IMIS.2014.36"},{"key":"10_CR22","doi-asserted-by":"publisher","DOI":"10.1002\/9781119183525","volume-title":"The Antivirus Hacker\u2019s Handbook","author":"J Koret","year":"2015","unstructured":"Koret, J., Bachaalany, E.: The Antivirus Hacker\u2019s Handbook, 1st edn. Wiley, New York (2015)","edition":"1"},{"key":"10_CR23","doi-asserted-by":"crossref","unstructured":"Lee, J., Lee, Y., Jin, M., Kim, J., Hong, J.: Analysis of application installation logs on android systems. In: SAC 2019. ACM (2019)","DOI":"10.1145\/3297280.3297489"},{"key":"10_CR24","doi-asserted-by":"crossref","unstructured":"McNab, N., Bryan, A.: An implementation of the linux software repository model for other operating systems. In: HotSWUp 2009. ACM (2009)","DOI":"10.1145\/1656437.1656445"},{"key":"10_CR25","unstructured":"Pietrek, M.: Peering inside the PE: a tour of the win32 portable executable file format (1994). \nhttps:\/\/msdn.microsoft.com\/en-us\/library\/ms809762.aspx"},{"key":"10_CR26","unstructured":"Potter, B., Fleck, B.: 802.11 Security. O\u2019Reilly (2002)"},{"key":"10_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1007\/978-3-642-37300-8_3","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"C Rossow","year":"2013","unstructured":"Rossow, C., Dietrich, C., Bos, H.: Large-scale analysis of malware downloaders. In: Flegel, U., Markatos, E., Robertson, W. (eds.) DIMVA 2012. LNCS, vol. 7591, pp. 42\u201361. Springer, Heidelberg (2013). \nhttps:\/\/doi.org\/10.1007\/978-3-642-37300-8_3"},{"key":"10_CR28","unstructured":"Sans: Malware delivered via windows installer files (2018). \nhttps:\/\/isc.sans.edu\/forums\/diary\/Malware+Delivered+via+Windows+Installer+Files\/23349\/"},{"key":"10_CR29","unstructured":"Scrapy: Scrapy (2019). \nhttps:\/\/www.scrapy.org"},{"key":"10_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"230","DOI":"10.1007\/978-3-319-45719-2_11","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"M Sebasti\u00e1n","year":"2016","unstructured":"Sebasti\u00e1n, M., Rivera, R., Kotzias, P., Caballero, J.: AVclass: a tool for massive malware labeling. In: Monrose, F., Dacier, M., Blanc, G., Garcia-Alfaro, J. (eds.) RAID 2016. LNCS, vol. 9854, pp. 230\u2013253. Springer, Cham (2016). \nhttps:\/\/doi.org\/10.1007\/978-3-319-45719-2_11"},{"key":"10_CR31","volume-title":"Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software","author":"M Sikorski","year":"2012","unstructured":"Sikorski, M., Honig, A.: Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software, 1st edn. No Starch Press, San Francisco (2012)","edition":"1"},{"key":"10_CR32","unstructured":"Softpedia: Softpedia (2019). \nhttps:\/\/www.softpedia.com\/"},{"key":"10_CR33","unstructured":"Software, E.: Artemis trojan (2013). \nhttps:\/\/www.enigmasoftware.com\/artemistrojan-removal\/"},{"key":"10_CR34","unstructured":"SourceForge: Sourceforge (2019). \nhttps:\/\/www.sourceforge.net"},{"key":"10_CR35","unstructured":"Total, V.: Virus total (2019). \nhttps:\/\/www.virustotal.com"},{"key":"10_CR36","unstructured":"Vaughan-Nichols, S.J.: Why software development is lagging hardware improvements (2009). \nhttps:\/\/www.cio.com\/article\/2431061\/from-32-bit-to-64-bit-why-software-development-is-lagging-hardware-improvements.html"},{"key":"10_CR37","doi-asserted-by":"crossref","unstructured":"Wang, H., Li, H., Li, L., Guo, Y., Xu, G.: Why are android apps removed from google play?: A large-scale empirical study. In: MSR. ACM (2018)","DOI":"10.1145\/3196398.3196412"},{"key":"10_CR38","unstructured":"Whitwam, R.: Asus live update pushed malware to 1 million pcs (2019). \nhttps:\/\/www.extremetech.com\/internet\/288283-asus-update-servers-pushed-malware-to-hundreds-of-thousands-of-pcs"},{"key":"10_CR39","doi-asserted-by":"crossref","unstructured":"Willems, C., Freiling, F.C., Holz, T.: Using memory management to detect and extract illegitimate code for malware analysis. In: ACSAC. ACM (2012)","DOI":"10.1145\/2420950.2420979"},{"issue":"6","key":"10_CR40","doi-asserted-by":"publisher","first-page":"466","DOI":"10.1109\/TSE.2005.63","volume":"31","author":"CC Williams","year":"2005","unstructured":"Williams, C.C., Hollingsworth, J.K.: Automatic mining of source coderepositories to improve bug finding techniques. IEEE Trans. Software Eng. 31(6), 466\u2013480 (2005)","journal-title":"IEEE Trans. Software Eng."},{"key":"10_CR41","doi-asserted-by":"crossref","unstructured":"Zope, M.: Unattended installation and uninstallation of softwares remotely. In: ICWET. ACM (2010)","DOI":"10.1145\/1741906.1742178"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-52683-2_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,7,7]],"date-time":"2020-07-07T00:07:43Z","timestamp":1594080463000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-52683-2_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030526825","9783030526832"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-52683-2_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"7 July 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lisbon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 June 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 June 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva2020.campus.ciencias.ulisboa.pt\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Hotcrp","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"45","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"12","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held virtually due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}