SafetyNOT: on the usage of the SafetyNet attestation API in Android

SafetyNOT: on the usage of the SafetyNet attestation API in Android
复制标题

DOI:
10.1145/3458864.3466627
复制
发表时间:
2021-06
期刊:
Proceedings of the 19th Annual International Conference on Mobile Systems, Applications, and Services
影响因子:
--
通讯作者:
Muhammad Ibrahim;A. Imran;Antonio Bianchi
Muhammad Ibrahim;A. Imran;Antonio Bianchi
中科院分区:
其他
文献类型:
--
作者:
Muhammad Ibrahim;A. Imran;Antonio Bianchi

文献摘要

被引文献

相似文献

许多执行安全敏感任务(例如在线银行)的应用程序都会尝试验证其运行设备的完整性以及自身代码的完整性。为了实现这一目标,Android 提供了一个 API,称为 SafetyNet Attestation API,可用于检测运行应用程序的设备是否处于“安全”状态(例如,未 root)以及应用程序的代码是否未被修改(例如,使用应用程序重新打包)。在本文中,我们对 SafetyNet API 的使用进行了首次大规模系统分析。我们的研究发现了应用程序开发人员在尝试使用此 API 时犯的许多常见错误。具体来说,我们对该 API 可能的误用进行了系统分类,并分析了每种误用的频率。例如,我们的结果表明,超过一半的分析应用程序在本地检查 SafetyNet 结果(而不是使用远程可信服务器),从而使它们的检查很容易被绕过。更令人惊讶的是,我们发现没有一个调用 SafetyNet API 的分析应用程序以完全正确的方式使用它。
Many apps performing security-sensitive tasks (e.g., online banking) attempt to verify the integrity of the device they are running in and the integrity of their own code. To ease this goal, Android provides an API, called the SafetyNet Attestation API, that can be used to detect if the device an app is running in is in a "safe" state (e.g., non-rooted) and if the app's code has not been modified (using, for instance, app repackaging). In this paper, we perform the first large-scale systematic analysis of the usage of the SafetyNet API. Our study identifies many common mistakes that app developers make when attempting to use this API. Specifically, we provide a systematic categorization of the possible misusages of this API, and we analyze how frequent each misuse is. Our results show that, for instance, more than half of the analyzed apps check SafetyNet results locally (as opposed to using a remote trusted server), rendering their checks trivially bypassable. Even more surprisingly, we found that none of the analyzed apps invoking the SafetyNet API uses it in a fully correct way.