FOAP: Fine-Grained Open-World Android App Fingerprinting

FOAP: Fine-Grained Open-World Android App Fingerprinting
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Jianfeng Li;Hao Zhou;Shuohan Wu;Xiapu Luo;Ting Wang;Xian Zhan;Xiaobo Ma
Jianfeng Li;Hao Zhou;Shuohan Wu;Xiapu Luo;Ting Wang;Xian Zhan;Xiaobo Ma
中科院分区:
其他
文献类型:
--
作者:
Jianfeng Li;Hao Zhou;Shuohan Wu;Xiapu Luo;Ting Wang;Xian Zhan;Xiaobo Ma

文献摘要

相似文献

尽管移动的应用程序广泛采用加密通信,但攻击者仍然可以通过应用程序指纹(AF)攻击从加密的移动的流量中识别应用程序或推断出选定的用户感兴趣的活动。然而,大多数现有的AF技术仅在封闭世界假设下工作,因此当面对模型训练期间看不到的应用程序时,可能会出现精度下降。此外,当用户进行一些敏感操作时,往往会发生严重的隐私泄露,这些操作与特定的UI组件密切相关。不幸的是,现有的AF技术过于粗粒度,无法获取如此细粒度的敏感信息。在本文中,我们采取了第一步来识别开放世界环境中Android应用程序的方法级细粒度用户操作,并提出了一个系统的解决方案,称为FOAP,以解决上述限制。首先,为了有效地降低开放世界环境中的误报风险,我们提出了一种新的度量标准,称为结构相似性,以自适应地过滤出与感兴趣的应用程序无关的流量段。其次,FOAP通过综合流量和二进制分析来实现细粒度的用户动作识别。具体来说,FOAP通过推断与特定UI组件相关的入口点方法来识别用户对它们的操作。广泛的评估和案例研究表明,FOAP不仅相当准确,而且在细粒度用户活动推断和用户隐私分析方面也很实用。
Despite the widespread adoption of encrypted communication for mobile apps, adversaries can still identify apps or infer selected user activities of interest from encrypted mobile traffic via app fingerprinting (AF) attacks. However, most existing AF techniques only work under the closed-world as-sumption, thereby suffering potential precision decline when faced with apps unseen during model training. Moreover, serious privacy leakage often occurs when users conduct some sensitive operations, which are closely associated with specific UI components. Unfortunately, existing AF techniques are too coarse-grained to acquire such fine-grained sensitive information. In this paper, we take the first step to identify method-level fine-grained user action of Android apps in the open-world setting and present a systematic solution, dubbed FOAP, to address the above limitations. First, to effectively reduce false positive risks in the open-world setting, we propose a novel metric, named structural similarity, to adaptively filter out traffic segments irrelevant to the app of interest. Second, FOAP achieves fine-grained user action identification via synthesizing traffic and binary analysis. Specifically, FOAP identifies user actions on specific UI components through inferring entry point methods correlated with them. Extensive evaluations and case studies demonstrate that FOAP is not only reasonably accurate but also practical in fine-grained user activity inference and user privacy analysis.