Zenodo.org will be unavailable for 2 hours on September 29th from 06:00-08:00 UTC. See announcement.

Journal article Open Access

Costly Freeware: A Systematic Analysis of Abuse in Download Portals

Richard Rivera; Platon Kotzias; Avinash Sudhodanan; Juan Caballero

MARC21 XML Export

<?xml version='1.0' encoding='UTF-8'?>
<record xmlns="http://www.loc.gov/MARC21/slim">
  <datafield tag="041" ind1=" " ind2=" ">
    <subfield code="a">eng</subfield>
  <controlfield tag="005">20200120160504.0</controlfield>
  <controlfield tag="001">1295566</controlfield>
  <datafield tag="700" ind1=" " ind2=" ">
    <subfield code="u">IMDEA Software Institute</subfield>
    <subfield code="a">Platon Kotzias</subfield>
  <datafield tag="700" ind1=" " ind2=" ">
    <subfield code="u">IMDEA Software Institute</subfield>
    <subfield code="a">Avinash Sudhodanan</subfield>
  <datafield tag="700" ind1=" " ind2=" ">
    <subfield code="u">IMDEA Software Institute</subfield>
    <subfield code="a">Juan Caballero</subfield>
  <datafield tag="856" ind1="4" ind2=" ">
    <subfield code="s">751987</subfield>
    <subfield code="z">md5:e20cfd9a6fa307cf3306293aa644b5a5</subfield>
    <subfield code="u">https://zenodo.org/record/1295566/files/IET-IFS.2017.0585.pdf</subfield>
  <datafield tag="542" ind1=" " ind2=" ">
    <subfield code="l">open</subfield>
  <datafield tag="260" ind1=" " ind2=" ">
    <subfield code="c">2018-06-06</subfield>
  <datafield tag="909" ind1="C" ind2="O">
    <subfield code="p">openaire</subfield>
    <subfield code="p">user-elastest</subfield>
    <subfield code="o">oai:zenodo.org:1295566</subfield>
  <datafield tag="100" ind1=" " ind2=" ">
    <subfield code="u">IMDEA Software Institute</subfield>
    <subfield code="a">Richard Rivera</subfield>
  <datafield tag="245" ind1=" " ind2=" ">
    <subfield code="a">Costly Freeware: A Systematic Analysis of Abuse in Download Portals</subfield>
  <datafield tag="980" ind1=" " ind2=" ">
    <subfield code="a">user-elastest</subfield>
  <datafield tag="536" ind1=" " ind2=" ">
    <subfield code="c">731535</subfield>
    <subfield code="a">ElasTest: an elastic platform for testing complex distributed large software systems</subfield>
  <datafield tag="540" ind1=" " ind2=" ">
    <subfield code="u">https://creativecommons.org/licenses/by/4.0/legalcode</subfield>
    <subfield code="a">Creative Commons Attribution 4.0 International</subfield>
  <datafield tag="650" ind1="1" ind2="7">
    <subfield code="a">cc-by</subfield>
    <subfield code="2">opendefinition.org</subfield>
  <datafield tag="520" ind1=" " ind2=" ">
    <subfield code="a">&lt;p&gt;Freeware is proprietary software that can be used free of charge. A popular vector for distributing freeware are download&lt;br&gt;
portals, i.e., websites that index, categorize, and host programs. Download portals can be abused to distribute potentially unwanted&lt;br&gt;
programs (PUP) and malware. The abuse can be due to PUP and malware authors uploading their ware, by benign freeware&lt;br&gt;
authors joining as affiliate publishers of PPI services and other affiliate programs, or by malicious download portal owners. In this&lt;br&gt;
work, we perform a systematic study of abuse in download portals. We build a platform to crawl download portals and apply it to&lt;br&gt;
download 191K Windows freeware installers from 20 download portals. We analyze the collected installers and execute them in a&lt;br&gt;
sandbox to monitor their installation. We measure an overall ratio of PUP and malware between 8% (conservative estimate) and&lt;br&gt;
26% (lax estimate). In 18 of the 20 download portals examined the amount of PUP and malware is below 9%. But, we also find&lt;br&gt;
two download portals exclusively used to distribute PPI downloaders. Finally, we detail different abusive behaviors that authors of&lt;br&gt;
undesirable programs use to distribute their programs through download portals.&lt;/p&gt;</subfield>
  <datafield tag="024" ind1=" " ind2=" ">
    <subfield code="a">10.1049/iet-ifs.2017.0585</subfield>
    <subfield code="2">doi</subfield>
  <datafield tag="980" ind1=" " ind2=" ">
    <subfield code="a">publication</subfield>
    <subfield code="b">article</subfield>
Views 164
Downloads 136
Data volume 102.3 MB
Unique views 160
Unique downloads 135


Cite as