Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile Apps

Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile Apps
复制标题

DOI:
10.1109/sp.2019.00009
复制
发表时间:
2019-04
期刊:
2019 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Chaoshun Zuo;Zhiqiang Lin;Yinqian Zhang
Chaoshun Zuo;Zhiqiang Lin;Yinqian Zhang
中科院分区:
其他
文献类型:
--
作者:
Chaoshun Zuo;Zhiqiang Lin;Yinqian Zhang

文献摘要

被引文献

相似文献

越来越多的移动应用程序(简称应用程序)使用云作为后端,尤其是云API,用于数据存储,数据分析,消息通知和监视。不幸的是,我们最近目睹了云的大量数据泄漏,从个人身份信息到公司秘密。在本文中,我们试图理解为什么会发生如此重大的泄漏以及设计自动识别它们的工具。令我们惊讶的是,我们的研究表明,在身份验证中缺乏身份验证,滥用各种密钥(例如,普通用户键和超级用户键),或者对用户权限的授权权限进行错误配置是根本原因。然后,我们设计了一组自动化程序分析技术,包括混淆 - 弹性云API标识和字符串值分析,并在称为LeakScope的工具中实现它们,以根据云API的使用方式来识别移动应用程序的潜在数据泄漏漏洞。我们对来自Google Play商店的160万个移动应用程序的评估已经发现了15,098个由主流云提供商(例如亚马逊,Google和Microsoft)管理的应用程序服务器,这些服务器受到数据泄漏攻击的影响。我们已经对每个云服务提供商进行了负责任的披露,他们都确认了我们已经确定的漏洞,并正在与移动应用程序开发人员积极合作以修补其脆弱服务。
Increasingly, more and more mobile applications (apps for short) are using the cloud as the back-end, in particular the cloud APIs, for data storage, data analytics, message notification, and monitoring. Unfortunately, we have recently witnessed massive data leaks from the cloud, ranging from personally identifiable information to corporate secrets. In this paper, we seek to understand why such significant leaks occur and design tools to automatically identify them. To our surprise, our study reveals that lack of authentication, misuse of various keys (e.g., normal user keys and superuser keys) in authentication, or misconfiguration of user permissions in authorization are the root causes. Then, we design a set of automated program analysis techniques including obfuscation-resilient cloud API identification and string value analysis, and implement them in a tool called LeakScope to identify the potential data leakage vulnerabilities from mobile apps based on how the cloud APIs are used. Our evaluation with over 1.6 million mobile apps from the Google Play Store has uncovered 15, 098 app servers managed by mainstream cloud providers such as Amazon, Google, and Microsoft that are subject to data leakage attacks. We have made responsible disclosure to each of the cloud service providers, and they have all confirmed the vulnerabilities we have identified and are actively working with the mobile app developers to patch their vulnerable services.