BridgeTaint: A Bi-Directional Dynamic Taint Tracking Method for JavaScript Bridges in Android Hybrid Applications

BridgeTaint: A Bi-Directional Dynamic Taint Tracking Method for JavaScript Bridges in Android Hybrid Applications
复制标题

BridgeTaint:Android 混合应用程序中 JavaScript 桥的双向动态污点跟踪方法

DOI:
10.1109/tifs.2018.2855650
复制
发表时间:
2019-03-01
影响因子:
6.8
通讯作者:
Pan, Yi
Pan, Yi
中科院分区:
计算机科学1区
文献类型:
--
作者:
Bai, Junyang;Wang, Weiping;Pan, Yi

文献摘要

被引文献

相似文献

混合应用程序(app)由于其跨平台功能和高性能而变得越来越受欢迎。这些应用程序使用JavaScript (JS)桥接通信方案在本地代码和Web代码之间进行互操作。虽然通过支持跨语言调用并使其更加强大,极大地扩展了混合应用程序的功能,但桥接通信方案也可能导致一些新的安全问题,例如跨语言代码注入攻击和隐私泄露。在本文中,我们提出了BRIDGETAINT,一种双向动态污点跟踪方法,可以检测混合应用程序中的桥安全问题。BRIDGETAINT使用了一种不同于现有的方法来跟踪污染数据:它在数据通过桥接器传输时记录敏感数据的污染信息,并使用跨语言的污染映射方法来恢复相应数据的污染标签。这种新颖的设计使BRIDGETAINT能够在应用程序执行期间动态跟踪受污染的数据,并分析使用框架开发的混合应用程序,这是基于静态代码分析的现有解决方案无法完成的。基于BRIDGETAINT,我们实现了BRIDGEINSPECTOR工具来检测使用JS桥接的混合应用中的跨语言隐私泄露和代码注入攻击。此外,还开发了桥接通信安全测试基准BRIDGEBENCH。在BRIDGEBENCH和Android市场1172个应用程序上的实验结果表明,BRIDGEINSPECTOR可以有效地检测使用桥接通信的混合应用程序中潜在的隐私泄露和跨语言代码注入攻击。
Hybrid applications (apps) are becoming more and more popular due to their cross-platform capabilities and high performance. These apps use the JavaScript (JS) bridge communication scheme to interoperate between native code and Web code. Although greatly extending the functionalities of hybrid apps by enabling cross-language invocations and making them more powerful, the bridge communication scheme might also cause some new security issues, e.g., cross-language code injection attacks and privacy leaks. In this paper, we propose BRIDGETAINT, a bi-directional dynamic taint tracking method that can detect bridge security issues in hybrid apps. BRIDGETAINT uses a method different from existing ones to track tainted data: it records the taint information of sensitive data when the data are transmitted through the bridge, and uses a cross-language taint mapping method to restore the taint tags of corresponding data. Such a novel design enables BRIDGETAINT to dynamically track tainted data during the execution of the app and analyze hybrid apps developed using frameworks, which cannot be done with existing solutions based on static code analyses. Based on BRIDGETAINT, we implement the BRIDGEINSPECTOR tool to detect cross-language privacy leaks and code injection attacks in hybrid apps using JS bridges. A benchmark called BRIDGEBENCH is also developed for bridge communication security test. The experimental results on BRIDGEBENCH and 1172 apps from Android market demonstrate that BRIDGEINSPECTOR can effectively detect potential privacy leaks and cross-language code injection attacks in hybrid apps using bridge communications.