Why Johnny Can't Make Money With His Contents: Pitfalls of Designing and Implementing Content Delivery Apps

Why Johnny Can't Make Money With His Contents: Pitfalls of Designing and Implementing Content Delivery Apps
复制标题

为什么约翰尼不能用他的内容赚钱:设计和实施内容交付应用程序的陷阱

DOI:
10.1145/3274694.3274752
复制
发表时间:
2018
期刊:
2018 Annual Computer Security Applications Conference (ACSAC ’18
影响因子:
--
通讯作者:
Li, Ninghui
Li, Ninghui
中科院分区:
--
文献类型:
--
作者:
Chau, Sze Yiu;Wang, Bincheng;Wang, Jianxiong;Chowdhury, Omar;Kate, Aniket;Li, Ninghui

文献摘要

参考文献

被引文献

相似文献

移动的设备正在成为多媒体内容消费的默认平台。这样一个蓬勃发展的商业生态系统吸引了内容分发商的兴趣,他们开发了能够接触到大量受众的应用程序。内容交付应用程序的业务优势关键在于能够有效地仲裁内容的购买和交付,并在大量消费者设备上根据使用控制策略管理内容的访问。移动的平台上的内容保护,尤其是在缺乏可信执行环境(TEE)的情况下,是一项具有挑战性的奋进,开发人员通常不得不求助于基于特定威慑的防御。这项工作评估了内容交付应用程序供应商所采用的内容保护机制的有效性,相对于具有不同现实能力的对手层次结构。我们对141个易受攻击的应用程序的分析发现,在许多情况下,由于开发人员对底层技术的不合理信任假设,攻击者可以未经授权和不受限制地访问应用程序的内容,有时甚至不需要对基于威慑的防御进行逆向工程。应用程序中的一些弱点也会严重影响应用程序用户的安全和隐私。我们的所有调查结果都已负责任地披露给相应的应用程序供应商。
Mobile devices are becoming the default platform for multimedia content consumption. Such a thriving business ecosystem has drawn interests from content distributors to develop apps that can reach a large number of audience. The business-edge of content delivery apps crucially relies on being able to effectively arbitrate the purchase and delivery of contents, and govern the access of contents with respect to usage control policies, on a plethora of consumer devices. Content protection on mobile platforms, especially in the absence of Trusted Execution Environment (TEE), is a challenging endeavor where developers often have to resort to ad-hoc deterrence-based defenses. This work evaluates the effectiveness of content protection mechanisms embraced by vendors of content delivery apps, with respect to a hierarchy of adversaries with varying real-world capabilities. Our analysis of 141 vulnerable apps uncovered that, in many cases, due to developers' unjustified trust assumptions about the underlying technologies, adversaries can obtain unauthorized and unrestricted access to contents of apps, sometimes without even needing to reverse engineer the deterrence-based defenses. Some weaknesses in the apps can also severely impact app users' security and privacy. All our findings have been responsibly disclosed to the corresponding app vendors.
DOI: 10.1007/11894063_16
发表时间: 2006-10
期刊: --
影响因子: --
作者:
Joseph Bonneau;Ilya Mironov
通讯作者: Joseph Bonneau;Ilya Mironov
高清晰度是一种天然的 DRM 吗?
DOI: --
发表时间: 2009
期刊: 2009 Proceedings of 18th International Conference on Computer Communications and Networks
影响因子: --
作者:
A. Blaich;A. Striegel
通讯作者: A. Striegel
“Kindle”密码的密码分析
DOI: --
发表时间: 2012
期刊: ACM Symposium on Applied Computing
影响因子: --
作者:
A. Biryukov;G. Leurent;Arnab Roy
通讯作者: Arnab Roy
DOI: --
发表时间: 1961
期刊: ACM National Meeting
影响因子: --
作者:
N. Johnson
通讯作者: N. Johnson
DOI: --
发表时间: 2004
期刊: Conference Record of the Thirty-Eighth Asilomar Conference on Signals, Systems and Computers, 2004.
影响因子: --
作者:
Jeffrey A Bloom;Christos Polyzois
通讯作者: Christos Polyzois