The Betrayal At Cloud City: An Empirical Analysis Of Cloud-Based Mobile Backends

The Betrayal At Cloud City: An Empirical Analysis Of Cloud-Based Mobile Backends
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Omar Alrawi;Chaoshun Zuo;Ruian Duan;R. Kasturi;Zhiqiang Lin;Brendan Saltaformaggio
Omar Alrawi;Chaoshun Zuo;Ruian Duan;R. Kasturi;Zhiqiang Lin;Brendan Saltaformaggio
中科院分区:
其他
文献类型:
--
作者:
Omar Alrawi;Chaoshun Zuo;Ruian Duan;R. Kasturi;Zhiqiang Lin;Brendan Saltaformaggio

文献摘要

被引文献

相似文献

云后端为移动的应用生态系统提供基本功能,如内容交付、广告网络、分析等。不幸的是,应用程序开发人员在选择或管理这些服务时往往忽视或无法控制谨慎的安全实践。我们对前5,000个Google Play Store免费应用的初步研究发现,在云后端的软件层(操作系统、软件服务、通信和Web应用)中,有983个N-day漏洞和655个0-day漏洞。使用这些云后端的移动的应用程序每个安装量在100万到5亿之间,可能会影响数十万用户。此外,由于第三方SDK的广泛使用,应用程序开发人员通常不知道影响其应用程序的后端以及在哪里报告漏洞。本文介绍了SkyWalker,这是一个自动审查移动的应用程序联系的后端并提供可操作的补救措施的管道。对于输入APK,SkyWalker提取后端URL的枚举,使用远程审查技术来识别软件漏洞和责任方,并向应用程序开发人员报告缓解策略。我们的调查结果表明,开发人员和云提供商对移动的应用后端的责任和义务没有明确的理解,这使得许多漏洞暴露出来。
Cloud backends provide essential features to the mobile app ecosystem, such as content delivery, ad networks, analytics, and more. Unfortunately, app developers often disregard or have no control over prudent security practices when choosing or managing these services. Our preliminary study of the top 5,000 Google Play Store free apps identified 983 instances of N-day and 655 instances of 0-day vulnerabilities spanning across the software layers (OS, software services, communication, and web apps) of cloud backends. The mobile apps using these cloud backends represent between 1M and 500M installs each and can potentially affect hundreds of thousands of users. Further, due to the widespread use of third-party SDKs, app developers are often unaware of the backends affecting their apps and where to report vulnerabilities. This paper presents SkyWalker, a pipeline to automatically vet the backends that mobile apps contact and provide actionable remediation. For an input APK, SkyWalker extracts an enumeration of backend URLs, uses remote vetting techniques to identify software vulnerabilities and responsible parties, and reports mitigation strategies to the app developer. Our findings suggest that developers and cloud providers do not have a clear understanding of responsibilities and liabilities in regards to mobile app backends that leave many vulnerabilities exposed.