Google Reveals How It Finds Malware When Your Device Isn't Verifying Apps

Advertisement
By Shubham Verma | Updated: 18 January 2017 19:06 IST
Highlights
  • Google has explained how it spots the malicious apps
  • The Verify Apps sometimes stops checking malware on your phone
  • Google, then, takes another route to verify such apps

On Android platform, each app has to go through a verification process where Google analyses it for virus and malware with the help of its security solution called Verify Apps. As a standard procedure, Verify Apps actively scans for the Potentially Harmful Apps (PHA) on the device, but what happens when it stops working? There could be a number of reasons behind it and Google has explained them along with the solution where it deploys various methods to identify security-related reasons behind your device not verifying apps.

On its Developers blog on Tuesday, Google detailed how it performs in such a situation where device is not checking with Verify Apps for security verifications of the apps. In such cases, there could be non-security reasons like buying a fresh mobile phone, but for more-concerning security-related reasons, Google steps in with its solutions to determine the exact cause. As per Google, when a device stops checking up with Verify Apps, it falls under the category of considered Dead or Insecure (DOI) devices.

Advertisement

"An app with a high enough percentage of DOI devices downloading it, is considered a DOI app. We use the DOI metric, along with the other security systems to help determine if an app is a PHA to protect Android users," reads the blog, which further explains how Google segregates between potentially insecure apps and devices. Additionally, when Google discovers any vulnerabilities, a patch for Android devices is released with the security update system.

The process of flagging a DOI app is more of a mathematical equation where a certain score decides if that particular app is DOI or not. The Android Security team has to correlate the app install attempts and DOI devices to find apps that harm the device in order to protect the users. If a device keeps reporting app installs and their verification through Verify Apps, it is said to be 'retained' and considered safe thereafter. But if a device doesn't do that, it's considered potentially dead or insecure (DOI).

Advertisement

Google mentioned that 'an app's retention rate is the percentage of all retained devices that downloaded the app in one day.' Considering retention as a strong indicator of device's health, Google tries to maximise that in all possible ways. And for that, Google follows a DOI scorer, which takes the value as assumption that all apps should have a similar device retention rate.

The app retention rate is calculated using the following formula, where Z is the DOI score, N is number of devices that downloaded the app, x represents number of retained devices that downloaded the app, and p stands for the probability of a device downloading any app will be retained.

Advertisement

In Google's words, "If an app's retention rate is a couple of standard deviations lower than average, the DOI scorer flags it." It further explains that "the DOI score indicates an app has a statistically significant lower retention rate if the Z-score is much less than -3.7. This means that if the null hypothesis is true, there is much less than a 0.01% chance the magnitude of the Z-score being as high. In this case, the null hypothesis means the app accidentally correlated with lower retention rate independent of what the app does."

Advertisement

After the DOI score calculation, Google comes into action to bring offending apps to the top of DOI list. Following that, Google uses Verify Apps to remove existing installs of the app and prevent future installs of the app. The company added to this saying that is has used this method to identify apps that contained Hummingbird, Ghost Posh, and Gooligan malware. Affected devices are usually factory reset or permanently abandoned. This helps Google to discover PHAs and block them before they go on a spree to kill further Android devices.

Without this rigorous process, Google said it may have missed many apps that should otherwise have been suppressed. Google has shared that over 25,000 apps have been identified using this method.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Google Brings Agentic Experiences Across Apps With Gemini Spark
  2. Lenovo Legion Y70 (2026) With 8,000mAh Battery Arrives at This Price
  3. Google IO 2026: Google Brings Gemini Spark to Apple's Mac
  4. Motorola Razr Fold Goes on Sale in India With These Offers
  5. Google IO 2026: Here's Everything That Was Announced During the Event
  6. Google Is Rebuilding Search Around AI, Agents, and Gemini
  7. Samsung Galaxy S27 Pro Tipped to Launch With Compact Design, Ultra Features
  8. Google's Android XR Glasses With Gemini AI to Launch Later This Fall
  9. Here's How the Oppo Reno 16 Series Will Look
  10. Redmi Turbo 5 India Launch Timeline, Key Features Leaked
  1. Pritam and Pedro OTT Release Date: When and Where to Watch Rajkumar Hirani's Online?
  2. Redmi Turbo 6 Max Leak Hints at a Significant Battery Upgrade and a Larger Display: Expected Specifications
  3. Acer Aspire 5 AI Laptop With Up to Intel Core Ultra 7 CPU Launched in India: Price, Features
  4. Apple's New Chief Hardware Officer Restructures Leadership to Speed Up Product Development: Report
  5. The Super Mario Galaxy Movie Now Available for Rent on Prime Video: What You Need to Know
  6. Lenovo Legion Y900 2026 Launched With 144Hz Display, Dimensity 9500s SoC: Price, Specifications
  7. Google Brings C2PA to Gemini App, OpenAI Adds SynthID to AI Images as Industry Pushes for Transparency
  8. Google IO 2026: Gemini App for macOS Gets Spark Upgrade, Bringing Agentic Capabilities to Apple’s Mac
  9. Motorola Razr Fold Goes on Sale in India With Snapdragon 8 Gen 5 SoC, Triple 50-Megapixel Cameras: Price, Offers
  10. Xbox Launches Player Voice Feedback Portal, Fans Say Bring Back Xbox Exclusives
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.