Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification Systems

Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification Systems
复制标题

DOI:
10.1109/dsn58367.2023.00017
复制
发表时间:
2023-06
期刊:
2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Jiadong Lou;Xiaohan Zhang;Yihe Zhang;Xinghua Li;Xu Yuan;Ning Zhang
Jiadong Lou;Xiaohan Zhang;Yihe Zhang;Xinghua Li;Xu Yuan;Ning Zhang
中科院分区:
其他
文献类型:
--
作者:
Jiadong Lou;Xiaohan Zhang;Yihe Zhang;Xinghua Li;Xu Yuan;Ning Zhang

文献摘要

相似文献

见证了推送通知在移动设备上的蓬勃发展,这种新的消息传递模式已经在不同的应用程序中普及。随着它的广泛采用,潜在的安全风险和隐私暴露问题引发了公众对其巨大社会影响的担忧。本文对移动通知生态系统的开发进行了首次尝试。通过剖析其结构要素和实施过程,对移动通知从平台注册到消息传递的整个流程进行了全面的脆弱性分析。同时,对于隐私暴露,我们首先通过提出三级检查方法来检查隐私政策合规性的执行情况,以指导我们的分析。然后,我们自上而下的方法从文档分析、应用网络流量研究到静态分析,揭露了发布应用中的非法数据收集行为。此外,我们还发现了通知监听可能导致的隐私推断。为了支持我们的分析,我们对12个最受欢迎的通知平台进行了实证研究,并对30,000多个申请进行了静态分析。我们发现:1)6个平台要么提供模棱两可的关键命名规则,要么提供易受攻击的消息传递API;2)隐私策略合规实现要么在文档阶段停滞不前(12个平台中的8个),要么从未在应用程序中实现,导致数十亿用户遭受隐私暴露;3)一些应用程序可以秘密监控发送到其他应用程序的通知消息,可能会引发用户隐私推理风险。我们的研究提出了更好地规范移动通知部署的迫切需求。
Witnessing the blooming adoption of push notifications on mobile devices, this new message delivery paradigm has become pervasive in diverse applications. Accompanying with its broad adoption, the potential security risks and privacy exposure issues raise public concerns regarding its great social impacts. This paper conducts the first attempt to exploit the mobile notification ecosystem. By dissecting its structural elements and implementation process, a comprehensive vulnerability analysis is conducted towards the complete flow of mobile notification from platform enrollment to messaging. Meanwhile, for privacy exposure, we first examine the implementation of privacy policy compliance by proposing a three-level inspection approach to guide our analysis. Then, our top-down methods from documentation analysis, application network traffic study, to static analysis expose the illicit data collection behaviors in released applications. In addition, we uncover the potential privacy inference resulted from the notification monitoring. To support our analysis, we conduct empirical studies on 12 most popular notification platforms and perform static analysis over 30,000+ applications. We discover: 1) six platforms either provide ambiguous KEY naming rules or offer vulnerable messaging APIs; 2) privacy policy compliance implementations are either stagnated at the documentation stages (8 of 12 platforms) or never implemented in apps, resulting in billions of users suffering from privacy exposure; and 3) some apps can stealthily monitor notification messages delivering to other apps, potentially incurring user privacy inference risks. Our study raises the urgent demand for better regulations of mobile notification deployment.