Exploit the Last Straw That Breaks Android Systems

Exploit the Last Straw That Breaks Android Systems
复制标题

DOI:
10.1109/sp46214.2022.9833563
复制
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Lei Zhang;Keke Lian;Haoyu Xiao;Zhibo Zhang;Peng Liu;Yuan Zhang;Min Yang;Haixin Duan
Lei Zhang;Keke Lian;Haoyu Xiao;Zhibo Zhang;Peng Liu;Yuan Zhang;Min Yang;Haixin Duan
中科院分区:
其他
文献类型:
--
作者:
Lei Zhang;Keke Lian;Haoyu Xiao;Zhibo Zhang;Peng Liu;Yuan Zhang;Min Yang;Haixin Duan

文献摘要

相似文献

Android系统服务通常在运行多个重要任务和提供无缝用户体验方面发挥关键作用,例如,方便地存储用户数据。在本文中,我们首次对Android系统服务中的数据存储过程进行了系统的安全研究,并因此发现了一类新的设计缺陷(名为Straw),它可以导致严重的拒绝服务(Denial-of-Service)攻击,例如,永久崩溃整个受害者Android设备。然后,我们提出了一种新的定向模糊的方法,称为StrawFuzzer,自动检查所有系统服务对稻草漏洞。StrawFuzzer平衡了路径探索和漏洞利用之间的权衡。通过将StrawFuzzer应用于三个具有最新安全更新的Android系统,我们发现了35个独特的吸管漏洞,影响了77个系统服务的474个接口,并成功生成了相应的漏洞,可用于进行各种永久/临时DoS攻击。我们已经向相应的供应商报告了我们的调查结果,并提出了修复漏洞的建议。到目前为止,Google已将我们的漏洞评为高严重性。
The Android system services usually play a critical role in running multiple important tasks, and delivering seamless user experiences, e.g., conveniently storing user data. In this paper, we conduct the first systematic security study on the data storing process in Android system services, and consequently discover a novel class of design flaws (named Straw), which can lead to serious DoS (Denial-of-Service) attacks, e.g., permanently crashing the whole victim Android device.Then we propose a novel directed fuzzing based approach, called StrawFuzzer, to automatically vet all system services against the straw vulnerabilities. StrawFuzzer balances the tradeoff between path exploration and vulnerability exploitation. By applying StrawFuzzer on three Android systems with the latest security updates, we identified 35 unique straw vulnerabilities affecting 474 interfaces across 77 system services and successfully generated corresponding exploits, which can be used to conduct various permanent/temporary DoS attacks. We have reported our findings with suggestions for repairing the vulnerabilities to corresponding vendors. Up to now, Google has rated our vulnerability as high severity.