Computer Security - ESORICS 2022 - 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26-30, 2022, Proceedings, Part II

Computer Security - ESORICS 2022 - 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26-30, 2022, Proceedings, Part II
复制标题

计算机安全 - ESORICS 2022 - 第 27 届欧洲计算机安全研究研讨会,丹麦哥本哈根,2022 年 9 月 26-30 日,会议记录,第二部分

DOI:
10.1007/978-3-031-17146-8_12
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Aldoseri A
Aldoseri A
中科院分区:
--
文献类型:
--
作者:
Aldoseri A

文献摘要

相似文献

Android应用程序通过所谓的应用程序组件与其他应用程序交互和交换数据。之前的研究表明,应用程序组件可能会导致应用程序级别的漏洞,例如导致跨应用程序的数据泄漏。或者,应用程序可以(有意或无意地)将其权限(例如,相机和麦克风的权限)暴露给缺乏这些权限的其他应用程序。这导致了一个混乱的代理情况下,一个较低的特权应用程序暴露其应用程序组件,使用这些权限,受害者的应用程序。虽然以前的研究主要集中在这些问题上,很少有人注意到应用程序组件如何影响Android操作系统的安全和隐私保证。在本文中,我们展示了两个相应的漏洞,影响最近的Android版本。首先,我们展示了如何使用应用组件来泄漏数据,并在某些情况下完全控制其他Android用户配置文件,绕过专用的锁定屏幕。我们展示了此漏洞对主要Android供应商(三星,华为,谷歌和小米)的影响。其次,我们发现应用程序组件可能被间谍软件滥用,以访问后台的摄像头和麦克风等传感器,直到Android 10,绕过专门用于防止这种行为的缓解措施。使用两个应用程序的设置,我们发现应用程序组件可以被悄悄调用,例如定期在后台拍照和录音。最后,我们介绍了Four Gates Inspector,这是我们的开源静态分析工具,可以系统地检测大量具有复杂代码库的应用程序的此类问题。我们的工具成功识别了5,783个应用程序中的34个暴露的组件问题,每个应用程序的平均分析运行时间为4.3秒,并检测到已知的恶意软件样本和从F-Droid存储库下载的未知样本。我们负责任地向受影响的供应商披露了本文中提出的所有漏洞,导致Android 10及更早版本中出现了多个CVE记录和一个目前尚未解决的高严重性问题。
Android apps interact and exchange data with other apps through so-called app components. Previous research has shown that app components can cause application-level vulnerabilities, for example leading to data leakage across apps. Alternatively, apps can (intentionally or accidentally) expose their permissions (e.g. for camera and microphone) to other apps that lack these privileges. This causes a confused deputy situation, where a less privileged app exposes its app components, which use these permissions, to the victim app. While previous research mainly focused on these issues, less attention has been paid to how app components can affect the security and privacy guarantees of Android OS. In this paper, we demonstrate two according vulnerabilities, affecting recent Android versions. First, we show how app components can be used to leak data from and, in some cases, take full control of other Android user profiles, bypassing the dedicated lock screen. We demonstrate the impact of this vulnerability on major Android vendors (Samsung, Huawei, Google and Xiaomi). Secondly, we found that app components can be abused by spyware to access sensors like the camera and the microphone in the background up to Android 10, bypassing mitigations specifically designed to prevent this behaviour. Using a two-app setup, we find that app components can be invoked stealthily to e.g. periodically take pictures and audio recordings in the background. Finally, we present Four Gates Inspector, our open-source static analysis tool to systematically detect such issues for a large number of apps with complex codebases. Our tool successfully identified exposed components issues in 34 out 5,783 apps with average analysis runtime of 4.3 s per app and, detected both known malware samples and unknown samples downloaded from the F-Droid repository. We responsibly disclosed all vulnerabilities presented in this paper to the affected vendors, leading to several CVE records and a currently unresolved high-severity issue in Android 10 and earlier.