A study on a feasible no-root approach on Android

A study on a feasible no-root approach on Android
复制标题

DOI:
10.3233/jcs-16866
复制
发表时间:
2017
期刊:
J. Comput. Secur.
影响因子:
--
通讯作者:
Yao Cheng;Yingjiu Li;R. Deng;Lingyun Ying;W. He
Yao Cheng;Yingjiu Li;R. Deng;Lingyun Ying;W. He
中科院分区:
其他
文献类型:
--
作者:
Yao Cheng;Yingjiu Li;R. Deng;Lingyun Ying;W. He

文献摘要

相似文献

Root是Android上的管理权限,但在现有的Android设备上无法访问。由于对特权功能的渴望和不愿让他们的设备扎根,Android用户寻求无根用户方法,这种方法为用户提供部分根权限,而不需要让他们的设备扎根。现有的无根目录方法要求用户通过Android设备上的Android Debug Bridge(ADB)启动单独的服务,该服务将执行用户想要的任务。然而,第三方Android应用程序通过套接字与单独的原生服务一起工作是不寻常的,这需要应用程序开发人员在应用程序开发方面拥有额外的知识,如Linux编程。在本文中,我们提出了一种可行的无根方法,该方法基于Android添加的新功能,该方法不创建单独的服务,而是创建ADB环回。为了确保这种无根方法不会以主动而不是被动的方式被滥用,我们检查了它的阴暗面。我们发现,虽然这种方法使非根应用程序很容易工作,但它可能会导致“权限爆炸”,这使得任何第三方应用程序都可以获得超出其已授予权限的外壳权限。权限爆炸可能进一步导致攻击,包括隐私泄露、帐户接管、应用程序UID滥用和用户输入推断。为了评估现实世界中的情况,进行了一项实际实验,结果表明,来自Google Play和四个第三方应用市场的许多现实世界应用确实容易受到这些攻击。为了减轻新的无根方法的阴暗面,使其更适合用户采用,我们确定了利用漏洞的原因,并提出了基于权限的解决方案。我们还向应用程序开发人员和应用程序市场提供了有关如何防止这些漏洞利用的建议。
Root is the administrative privilege on Android, which is however inaccessible on stock Android devices. Due to the desire for privileged functionalities and the reluctance of rooting their devices, Android users seek for no-root approaches, which provide users with part of root privileges without rooting their devices. Existing no-root approaches require users to launch a separate service via Android Debug Bridge (ADB) on an Android device, which would perform user-desired tasks. However, it is unusual for a third-party Android application to work with a separate native service via sockets, and it requires the application developers to have extra knowledge such as Linux programming in application development. In this paper, we propose a feasible no-root approach based on new functionalities added on Android, which creates no separate service but an ADB loopback. To ensure such no-root approach is not misused in a proactive instead of reactive manner, we examine its dark side. We find out that while this approach makes it easy for no-root applications to work, it may lead to a “permission explosion,” which enables any third-party application to attain shell permissions beyond its granted permissions. The permission explosion can further lead to exploits including privacy leakage, account takeover, application UID abuse, and user input inference. A practical experiment is carried out to evaluate the situation in the real world, which shows that many real-world applications from Google Play and four third-party application markets are indeed vulnerable to these exploits. To mitigate the dark side of the new no-root approach and make it more suitable for users to adopt, we identify the causes of the exploits, and propose a permission-based solution. We also provide suggestions to application developers and application markets on how to prevent these exploits.