AccessiLeaks: Investigating Privacy Leaks Exposed by the Android Accessibility Service

AccessiLeaks: Investigating Privacy Leaks Exposed by the Android Accessibility Service
复制标题

DOI:
10.2478/popets-2019-0031
复制
发表时间:
2019-04
影响因子:
--
通讯作者:
Mohammad Naseri;N. P. Borges;A. Zeller;Romain Rouvoy
Mohammad Naseri;N. P. Borges;A. Zeller;Romain Rouvoy
中科院分区:
--
文献类型:
--
作者:
Mohammad Naseri;N. P. Borges;A. Zeller;Romain Rouvoy

文献摘要

被引文献

相似文献

摘要支持残疾用户,根据Android开发人员指南,Android提供了可访问性服务开发人员可以免费使用此服务,而无需任何限制,赋予他们关键的特权,例如监视用户输入或屏幕内容以捕获敏感信息,我们表明,可以启用可访问性服务,使最高金融和72% 80%的社交媒体应用程序很容易受到窃听的攻击,漏洞的信息(例如登录和密码)可以减轻几种工具的组合我们还发现,在所有情况下,我们的修复程序都可以自动解决这些问题。服务; 50%的用户将遵循这些通知。
Abstract To support users with disabilities, Android provides the accessibility services, which implement means of navigating through an app. According to the Android developer’s guide: “Accessibility services should only be used to assist users with disabilities in using Android devices and apps”. However, developers are free to use this service without any restrictions, giving them critical privileges such as monitoring user input or screen content to capture sensitive information. In this paper, we show that simply enabling the accessibility service leaves 72 % of the top finance a nd 80 % of the top social media apps vulnerable to eavesdropping attacks, leaking sensitive information such as logins and passwords. A combination of several tools and recommendations could mitigate the privacy risks: We introduce an analysis technique that detects most of these issues automatically, e.g. in an app store. We also found that these issues can be automatically fixed in almost all cases; our fixes have b een accepted by 70 % of the surveyed developers. Finally, we designed a notification mechanism which would warn users against possible misuses of the accessibility services; 50 % of users would follow these notifications.