Abstract
We present a large-scale study of Windows freeware installers. In particular, we look for potentially unwanted programs (PUP) and other potentially unwanted modifications to the target system made by freeware installers. The analysis is based on almost 800 installers gathered from eight popular software download portals. We measure how many of them drop PUP, such as browser plugins, or make other modifications to the system. In addition to these results, we find that most installers that download executable files over the network are vulnerable to man-in-the-middle attacks, which in the worst cases may be used to execute arbitrary code with elevated privileges on the target system. Moreover, serious man-in-the-middle vulnerabilities are found in application managers provided by download portals.
Original language | English |
---|---|
Title of host publication | Secure IT Systems: 22nd Nordic Conference, NordSec 2017, Tartu, Estonia, November 8–10, 2017, Proceedings |
Editors | Helger Lipmaa, Aikaterini Mitrokotsa, Raimundas Matulevičius |
Place of Publication | Cham |
Publisher | Springer |
Pages | 209-225 |
Number of pages | 17 |
ISBN (Print) | 978-3-319-70290-2 |
DOIs | |
Publication status | Published - 2017 |
MoE publication type | A4 Conference publication |
Event | Nordic Conference on Secure IT Systems - Tartu, Estonia Duration: 8 Nov 2017 → 10 Nov 2017 Conference number: 22 |
Publication series
Name | Lecture Notes in Computer Science |
---|---|
Publisher | Springer |
Volume | 10674 |
ISSN (Print) | 0302-9743 |
ISSN (Electronic) | 1611-3349 |
Conference
Conference | Nordic Conference on Secure IT Systems |
---|---|
Abbreviated title | NordSec |
Country/Territory | Estonia |
City | Tartu |
Period | 08/11/2017 → 10/11/2017 |