Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile Applications

Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile Applications
复制标题

DOI:
10.1109/sp.2018.00043
复制
发表时间:
2018-05
期刊:
2018 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Guangliang Yang;Jeff Huang;G. Gu;Abner Mendoza
Guangliang Yang;Jeff Huang;G. Gu;Abner Mendoza
中科院分区:
其他
文献类型:
--
作者:
Guangliang Yang;Jeff Huang;G. Gu;Abner Mendoza

文献摘要

被引文献

相似文献

Postmessage在基于HTML5的Web应用程序中很受欢迎,可以允许不同起源之间的通信。随着移动应用程序中嵌入式浏览器(即WebView)的日益普及(即混合应用程序),Postmessage在这些应用程序中发现了实用程序。但是,与Web应用程序不同,Hybrid应用程序具有独特的要求,即其本机代码(例如,Android的Java)还需要与WebView中加载的Web代码交换消息。为了弥合差距,开发人员通常通过将本地上下文视为新框架,并允许新框架和Web框架之间的通信来扩展术后。我们在本文中称这种扩展后的后“混合后邮政邮记”。我们发现混合邮政在介绍了新的关键安全缺陷:在混合邮政邮政随机邮件中的消息传递过程中,消息的所有来源信息均未尊重甚至丢失。如果对手将恶意代码注入WebView,则恶意代码可能会利用这些缺陷来监视可能包含敏感信息的消息,或者主动将消息发送到任意消息接收器并访问其内部功能和数据。我们认为由混合后的后期“起源剥离脆弱性”(OSV)造成的新型安全问题(OSV)。在本文中,我们的贡献是四倍。首先,我们对OSV进行了首次系统研究。其次,我们提出了一种针对OSV的轻质检测工具,称为OSV猎人。第三,我们使用一组流行的应用程序评估OSV猎人。我们发现74个应用程序实施了混合后的邮件,并且所有这些应用程序都遭受了OSV的困扰,对手可能会利用这些应用程序来执行远程实时麦克风监控,数据竞赛,内部数据操纵,拒绝服务(DOS)攻击等。影响了几个流行的开发框架,库(例如Facebook React本地框架和Google Cloud Print Library)和应用程序(例如Adobe Reader和WPS Office)受到影响。最后,为了减轻根部的OSV,我们设计并实施了三个新的Postmessage API,称为无OSV。我们的评估表明,无OSV是安全和快速的,它对臭名昭著的Android碎片化问题是一般且有弹性的。我们还通过应用无OSV来硬化复杂的“ Facebook React Native”框架来证明无OSV易于使用。无OSV是开源的,其源代码以及更多实施和评估详细信息可在线获得。
postMessage is popular in HTML5 based web apps to allow the communication between different origins. With the increasing popularity of the embedded browser (i.e., WebView) in mobile apps (i.e., hybrid apps), postMessage has found utility in these apps. However, different from web apps, hybrid apps have a unique requirement that their native code (e.g., Java for Android) also needs to exchange messages with web code loaded in WebView. To bridge the gap, developers typically extend postMessage by treating the native context as a new frame, and allowing the communication between the new frame and the web frames. We term such extended postMessage "hybrid postMessage" in this paper. We find that hybrid postMessage introduces new critical security flaws: all origin information of a message is not respected or even lost during the message delivery in hybrid postMessage. If adversaries inject malicious code into WebView, the malicious code may leverage the flaws to passively monitor messages that may contain sensitive information, or actively send messages to arbitrary message receivers and access their internal functionalities and data. We term the novel security issue caused by hybrid postMessage "Origin Stripping Vulnerability" (OSV). In this paper, our contributions are fourfold. First, we conduct the first systematic study on OSV. Second, we propose a lightweight detection tool against OSV, called OSV-Hunter. Third, we evaluate OSV-Hunter using a set of popular apps. We found that 74 apps implemented hybrid postMessage, and all these apps suffered from OSV, which might be exploited by adversaries to perform remote real-time microphone monitoring, data race, internal data manipulation, denial of service (DoS) attacks and so on. Several popular development frameworks, libraries (such as the Facebook React Native framework, and the Google cloud print library) and apps (such as Adobe Reader and WPS office) are impacted. Lastly, to mitigate OSV from the root, we design and implement three new postMessage APIs, called OSV-Free. Our evaluation shows that OSV-Free is secure and fast, and it is generic and resilient to the notorious Android fragmentation problem. We also demonstrate that OSV-Free is easy to use, by applying OSV-Free to harden the complex "Facebook React Native" framework. OSV-Free is open source, and its source code and more implementation and evaluation details are available online.