This article discusses detecting malicious Facebook applications. It presents FRAppE, a tool that can detect malicious apps with 99.5% accuracy. Key points:
- 13% of over 111,000 observed Facebook apps were found to be malicious. Malicious apps often share names and request fewer permissions than benign apps.
- Malicious and benign app profiles differ significantly. Malicious apps exhibit "laziness" - many use the same names. FRAppE uses on-demand and aggregated data to profile apps.
- Apps collude on a massive scale to promote each other. Over 1,500 apps promoted over 3,700 other apps. Well-organized "app-nets" control many malicious apps