What the App is That? Deception and Countermeasures in the Android User Interface

What the App is That? Deception and Countermeasures in the Android User Interface
复制标题

DOI:
10.1109/sp.2015.62
复制
发表时间:
2015-05
期刊:
2015 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
中科院分区:
其他
文献类型:
--
作者:
Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna

文献摘要

被引文献

相似文献

移动应用程序是数十亿人日常生活的一部分,他们经常将敏感信息托付给它们。这些用户仅通过视觉外观来识别当前关注的应用程序,因为最流行的移动操作系统的 GUI 不会显示任何有关应用程序来源的可信指示。在本文中,我们详细分析了 Android 用户可能被误认为应用程序的多种方式,例如,被欺骗向恶意应用程序提供敏感信息。我们对 Android 平台 API 的分析,在自动状态探索工具的辅助下,识别并分类了各种攻击向量(一些是以前已知的,另一些是新颖的,例如不可逃避的全屏覆盖),这些攻击向量允许恶意应用程序秘密地替换或模仿其他应用程序的 GUI,并发起网络钓鱼和点击劫持攻击。系统 GUI 的限制使得这些攻击比在台式机上更难以注意到,从而使用户完全无法防御它们。为了减轻 GUI 攻击,我们开发了两层防御。为了检测市场层面的恶意应用程序,我们开发了一种工具,使用静态分析来识别可能发起 GUI 混淆攻击的代码。我们展示了该工具如何检测可能发起 GUI 攻击的应用程序,例如勒索软件程序。由于这些攻击旨在迷惑人类,因此我们还设计并实现了设备上的防御,以解决 Android GUI 中缺乏安全指示器的根本问题。我们将这样的指示器添加到系统导航栏,该指示器安全地告知用户与其交互的应用程序的来源(例如,Pay Pal 应用程序由“Pay Pal, Inc.”支持)。我们通过一项涉及 308 名人类受试者的用户研究证明了我们的攻击和拟议的设备上防御的有效性,当使用配备我们防御的系统时,他们检测攻击的能力显着提高。
Mobile applications are part of the everyday lives of billions of people, who often trust them with sensitive information. These users identify the currently focused app solely by its visual appearance, since the GUIs of the most popular mobile OSes do not show any trusted indication of the app origin. In this paper, we analyze in detail the many ways in which Android users can be confused into misidentifying an app, thus, for instance, being deceived into giving sensitive information to a malicious app. Our analysis of the Android platform APIs, assisted by an automated state-exploration tool, led us to identify and categorize a variety of attack vectors (some previously known, others novel, such as a non-escapable full screen overlay) that allow a malicious app to surreptitiously replace or mimic the GUI of other apps and mount phishing and click-jacking attacks. Limitations in the system GUI make these attacks significantly harder to notice than on a desktop machine, leaving users completely defenseless against them. To mitigate GUI attacks, we have developed a two-layer defense. To detect malicious apps at the market level, we developed a tool that uses static analysis to identify code that could launch GUI confusion attacks. We show how this tool detects apps that might launch GUI attacks, such as ransom ware programs. Since these attacks are meant to confuse humans, we have also designed and implemented an on-device defense that addresses the underlying issue of the lack of a security indicator in the Android GUI. We add such an indicator to the system navigation bar, this indicator securely informs users about the origin of the app with which they are interacting (e.g., The Pay Pal app is backed by "Pay Pal, Inc."). We demonstrate the effectiveness of our attacks and the proposed on-device defense with a user study involving 308 human subjects, whose ability to detect the attacks increased significantly when using a system equipped with our defense.