Mobile Application Web API Reconnaissance: Web-to-Mobile Inconsistencies & Vulnerabilities

Mobile Application Web API Reconnaissance: Web-to-Mobile Inconsistencies & Vulnerabilities
复制标题

DOI:
10.1109/sp.2018.00039
复制
发表时间:
2018-04
期刊:
2018 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Abner Mendoza;G. Gu
Abner Mendoza;G. Gu
中科院分区:
其他
文献类型:
--
作者:
Abner Mendoza;G. Gu

文献摘要

被引文献

相似文献

现代移动的应用程序使用基于HTTP的云托管API服务,并严重依赖互联网基础设施进行数据通信和存储。为了提高性能并利用移动终端的能力,通常在移动的客户端上实现与web API服务对接所需的输入验证和其他业务逻辑。然而,当Web服务实现无法完全复制输入验证时,就会产生不一致性,这可能导致可能危及用户安全和隐私的攻击。开发自动审计Web API安全性的方法仍然具有挑战性。在本文中,我们提出了一种新的方法,用于自动分析移动的应用程序到Web API通信,以检测应用程序及其各自的Web API服务之间的输入验证逻辑的不一致性。我们提出了我们的系统,WARDroid,它实现了一个基于静态分析的Web API侦察方法,以发现真实的世界中的API服务,可能会导致攻击的严重后果,潜在的数百万用户在世界各地的不一致。我们的系统利用程序分析技术,自动提取HTTP通信模板从Android应用程序编码的输入验证约束的应用程序对传出的Web请求的Web API服务。WARDroid还增强了服务器验证逻辑的黑盒测试,以识别可能导致攻击的不一致性。我们在Google Play商店的10,000个流行免费应用程序上评估了我们的系统。我们在4,000多个应用程序中使用的API中检测到有问题的逻辑,其中包括1,743个使用未加密HTTP通信的应用程序。我们进一步测试了1,000个应用程序,以验证可能导致用户隐私和安全受到潜在危害的Web API劫持漏洞,并发现数百万用户可能受到我们测试应用程序样本集的影响。
Modern mobile apps use cloud-hosted HTTP-based API services and heavily rely on the Internet infrastructure for data communication and storage. To improve performance and leverage the power of the mobile device, input validation and other business logic required for interfacing with web API services are typically implemented on the mobile client. However, when a web service implementation fails to thoroughly replicate input validation, it gives rise to inconsistencies that could lead to attacks that can compromise user security and privacy. Developing automatic methods of auditing web APIs for security remains challenging. In this paper, we present a novel approach for automatically analyzing mobile app-to-web API communication to detect inconsistencies in input validation logic between apps and their respective web API services. We present our system, WARDroid, which implements a static analysis-based web API reconnaissance approach to uncover inconsistencies on real world API services that can lead to attacks with severe consequences for potentially millions of users throughout the world. Our system utilizes program analysis techniques to automatically extract HTTP communication templates from Android apps that encode the input validation constraints imposed by the apps on outgoing web requests to web API services. WARDroid is also enhanced with blackbox testing of server validation logic to identify inconsistencies that can lead to attacks. We evaluated our system on a set of 10,000 popular free apps from the Google Play Store. We detected problematic logic in APIs used in over 4,000 apps, including 1,743 apps that use unencrypted HTTP communication. We further tested 1,000 apps to validate web API hijacking vulnerabilities that can lead to potential compromise of user privacy and security and found that millions of users are potentially affected from our sample set of tested apps.