AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online Services
Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin
Abstract
When accessing online private resources (e.g., user proiles, photos, shopping carts) from a client (e.g., a desktop web-browser or a mobile app), the service providers must implement proper access control, which typically involves both authentication and authorization. However, not all of the service providers follow the best practice, resulting in various access control vulnerabilities. To understand such a threat in a large scale, and identify the vulnerable access control implementations in online services, this paper introduces AuthScope, a tool that is able to automatically execute a mobile app and pinpoint the vulnerable access control implementations, particularly the vulnerable authorizations, in the corresponding online service. he key idea is to use diferential traic analysis to recognize the protocol ields and then automatically substitute the ields and observe the server response. One of the key challenges for a large scale study lies in how to obtain the postauthentication request-and-response messages for a given app. We have thus developed a targeted dynamic activity explorer to perform an in-context analysis and drive the app execution to automatically log in the service. We have tested AuthScope with 4, 838 popular mobile apps from Google Play, and identiied 597 0-day vulnerable authorizations that map to 306 apps.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1084f560-3363-4e3e-a874-a69a1bb6a1e9Cited by top-tier papers23
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 77 citations
- O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the WebMohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich et al.USENIX Security 2018 · 63 citations
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 56 citations
Builds on2
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 253 citations
- Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile ServicesChaoshun Zuo, Wubing Wang, Zhiqiang Lin, Rui WangNDSS 2016 · 40 citations
Related papers
- Automatic Uncovering of Hidden Behaviors From Input Validation in Mobile AppsQingchuan Zhao, Chaoshun Zuo, Brendan Dolan-Gavitt, Giancarlo Pellegrino et al.S&P 2020 · 33 citations
- Playing Without Paying: Detecting Vulnerable Payment Verification in Native Binaries of Unity Mobile GamesChaoshun Zuo, Zhiqiang LinUSENIX Security 2022
- Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability ScanningXigao Li, Babak Amin Azad, Amir Rahmati, Nick NikiforakisWWW 2023 · 7 citations
- SigScope: Detecting and Understanding Off-Chain Message Signing-related Vulnerabilities in Decentralized ApplicationsSajad Meisami, Hugo Dabadie, Song Li, Yuzhe Tang et al.WWW 2025 · 2 citations
- Foot in the Door: Uncovering the Multi-Step Authorization Exploitation in Mobile ApplicationsYizhe Shi, Zhemin Yang, Qiaodan Hou, Lukai Cui et al.CCS 2026
