Lie to Me: Abusing the Mobile Content Sharing Service for Fun and Profit

Lie to Me: Abusing the Mobile Content Sharing Service for Fun and Profit
复制标题

DOI:
10.1145/3485447.3512151
复制
发表时间:
2022-04
期刊:
Proceedings of the ACM Web Conference 2022
影响因子:
--
通讯作者:
Guosheng Xu;Siyi Li;Hao Zhou;Shujie Liu;Yutian Tang;Li Li-Li;Xiapu Luo;Xusheng Xiao;Guoai Xu;Haoyu Wang
Guosheng Xu;Siyi Li;Hao Zhou;Shujie Liu;Yutian Tang;Li Li-Li;Xiapu Luo;Xusheng Xiao;Guoai Xu;Haoyu Wang
中科院分区:
其他
文献类型:
--
作者:
Guosheng Xu;Siyi Li;Hao Zhou;Shujie Liu;Yutian Tang;Li Li-Li;Xiapu Luo;Xusheng Xiao;Guoai Xu;Haoyu Wang

文献摘要

相似文献

在线内容分享是Android应用程序中广泛使用的一项功能。在本文中,我们观察到了一种新的虚假分享攻击,攻击者可以利用现有的内容共享服务来操纵共享内容的显示来源,从而绕过目标在线社交应用程序(OSA)的内容审查,并诱导用户点击共享的欺诈性内容。我们发现,7种流行的内容分享服务(包括微信、支付宝和KakaoTalk)都容易受到这样的攻击。为了检测这种攻击,并探索攻击者是否在野外利用了这种攻击,我们提出了一种包括静态分析和动态验证的多粒度检测工具DeFash。广泛的实验室和野外实验表明,DeFash在检测此类攻击方面是有效的。我们已经确认了51个涉及虚假分享攻击的真实应用程序。我们进一步收集了超过24K的共享身份信息(SIIS),这些信息可能会被攻击者滥用。因此,我们的社会迫切需要采取行动来发现和减少这种攻击。
Online content sharing is a widely used feature in Android apps. In this paper, we observe a new Fake-Share attack that adversaries can abuse existing content sharing services to manipulate the displayed source of shared content to bypass the content review of targeted Online Social Apps (OSAs) and induce users to click on the shared fraudulent content. We show that seven popular content-sharing services (including WeChat, AliPay, and KakaoTalk) are vulnerable to such an attack. To detect this kind of attack and explore whether adversaries have leveraged it in the wild, we propose DeFash, a multi-granularity detection tool including static analysis and dynamic verification. The extensive in-the-lab and in-the-wild experiments demonstrate that DeFash is effective in detecting such attacks. We have identified 51 real-world apps involved in Fake-Share attacks. We have further harvested over 24K Sharing Identification Information (SIIs) that can be abused by attackers. It is hence urgent for our community to take actions to detect and mitigate this kind of attack.