Do Not Give a Dog Bread Every Time He Wags His Tail: Stealing Passwords through Content Queries (CONQUER) Attacks

Do Not Give a Dog Bread Every Time He Wags His Tail: Stealing Passwords through Content Queries (CONQUER) Attacks
复制标题

DOI:
10.14722/ndss.2023.24005
复制
发表时间:
2023
期刊:
Proceedings 2023 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Chongqing Lei;Zhen Ling;Yue Zhang;K. Dong;Kaizheng Liu;Junzhou Luo;Xinwen Fu
Chongqing Lei;Zhen Ling;Yue Zhang;K. Dong;Kaizheng Liu;Junzhou Luo;Xinwen Fu
中科院分区:
其他
文献类型:
--
作者:
Chongqing Lei;Zhen Ling;Yue Zhang;K. Dong;Kaizheng Liu;Junzhou Luo;Xinwen Fu

文献摘要

相似文献

-Android辅助功能服务旨在帮助残疾人士使用Android设备。然而,由于设计缺陷,它已被攻击者利用来窃取用户密码。谷歌已经实施了各种对策,使这些类型的攻击很难在现代Android设备上成功。在本文中,我们提出了一种新型的侧信道攻击称为内容查询(C ONQUER),可以绕过这些防御。我们发现,Android无法阻止辅助功能服务查询密码的内容,从而允许启用此服务的恶意软件枚举内容的组合以暴力破解密码。虽然这种攻击似乎很容易执行,但为了成功地针对真实世界的应用程序启动它,必须解决几个挑战。其中包括使用惰性查询来区分目标密码字符串、使用主动查询来确定攻击的正确时机,以及使用基于时间和状态的辅助通道来推断区分大小写的密码。我们的评估结果表明,C ONQUER攻击是有效的窃取密码,平均一次性成功率为64.91%。该攻击还对4.1到12的所有Android版本构成威胁,并可用于攻击数万个应用程序。此外,我们分析了C ONQUER攻击的根本原因,并讨论了几种对策,以减轻其带来的潜在安全风险。
—Android accessibility service was designed to assist individuals with disabilities in using Android devices. However, it has been exploited by attackers to steal user passwords due to design shortcomings. Google has implemented various countermeasures to make it difficult for these types of attacks to be successful on modern Android devices. In this paper, we present a new type of side channel attack called content queries (C ONQUER ) that can bypass these defenses. We discovered that Android does not prevent the content of passwords from being queried by the accessibility service, allowing malware with this service enabled to enumerate the combinations of content to brute force the password. While this attack seems simple to execute, there are several challenges that must be addressed in order to successfully launch it against real-world apps. These include the use of lazy query to differentiate targeted password strings, active query to determine the right timing for the attack, and timing-and state-based side channels to infer case-sensitive passwords. Our evaluation results demonstrate that the C ONQUER attack is effective at stealing passwords, with an average one-time success rate of 64.91%. This attack also poses a threat to all Android versions from 4.1 to 12, and can be used against tens of thousands of apps. In addition, we analyzed the root cause of the C ONQUER attack and discussed several countermeasures to mitigate the potential security risks it poses.