Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps' Native Code

Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps' Native Code
复制标题

DOI:
10.1109/icse43902.2021.00122
复制
发表时间:
2021-05
期刊:
2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE)
影响因子:
--
通讯作者:
Sumaya Almanee;Arda Ünal;Mathias Payer;Joshua Garcia
Sumaya Almanee;Arda Ünal;Mathias Payer;Joshua Garcia
中科院分区:
其他
文献类型:
--
作者:
Sumaya Almanee;Arda Ünal;Mathias Payer;Joshua Garcia

文献摘要

相似文献

Android应用包含第三方原生库,以提高性能和重用功能。原生代码通过Java原生接口或Android原生开发工具包直接从应用执行。Android开发人员将预编译的原生库添加到他们的项目中,以启用它们的使用。不幸的是,开发人员经常努力或干脆忽视及时更新这些库。这导致在补丁可用多年后,仍继续使用过时的本机库,这些本机库具有未修补的安全漏洞。为了进一步了解这种现象,我们研究了9月1日起Google Play上最受欢迎的200款免费应用程序中原生库的安全更新2013年至2020年5月。我们在这项研究中面临的一个核心困难是图书馆及其版本的识别。开发人员经常重命名或修改库,使其识别具有挑战性。我们创建了一种名为LibRARIAN(LibRAry veRsion IdentificAtioN)的方法,该方法基于我们新颖的相似性度量bin 2sim准确识别Android应用中的原生库及其版本。LibRARIAN利用了基于元数据从库中提取的不同特征,并在只读部分中识别字符串。我们发现,在2009年9月20日至2011年9月30日期间,200个流行应用程序中有53个(26.5%)存在已知CVE的易受攻击版本。2013年和2020年5月,其中14个应用程序仍然存在漏洞。我们发现,应用程序开发人员平均需要528.71±40.20天来应用安全补丁,而库开发人员在54.59 ± 8.12天后发布安全补丁-更新速度慢了10倍。
Android apps include third-party native libraries to increase performance and to reuse functionality. Native code is directly executed from apps through the Java Native Interface or the Android Native Development Kit. Android developers add precompiled native libraries to their projects, enabling their use. Unfortunately, developers often struggle or simply neglect to update these libraries in a timely manner. This results in the continuous use of outdated native libraries with unpatched security vulnerabilities years after patches became available. To further understand such phenomena, we study the security updates in native libraries in the most popular 200 free apps on Google Play from Sept. 2013 to May 2020. A core difficulty we face in this study is the identification of libraries and their versions. Developers often rename or modify libraries, making their identification challenging. We create an approach called LibRARIAN (LibRAry veRsion IdentificAtioN) that accurately identifies native libraries and their versions as found in Android apps based on our novel similarity metric bin2sim. LibRARIAN leverages different features extracted from libraries based on their metadata and identifying strings in read-only sections. We discovered 53/200 popular apps (26.5%) with vulnerable versions with known CVEs between Sept. 2013 and May 2020, with 14 of those apps remaining vulnerable. We find that app developers took, on average, 528.71±40.20 days to apply security patches, while library developers release a security patch after 54.59 ± 8.12 days-a 10 times slower rate of update.