Lune

USENIX Security2021Top-tier venue

PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems

Yu Tsung Lee, William Enck, Haining Chen, Hayawardh Vijayakumar, Ninghui Li, Zhiyun Qian, Daimeng Wang, Giuseppe Petracca, Trent Jaeger

2021Year
17Citations
8Top-tier citations

Abstract

Android's filesystem access control is its foundation for system integrity. It combines mandatory (e.g., SELinux) and discretionary (e.g., Unix permissions) access control with other specialized access controls (e.g., Android permissions), aiming to protect Android/OEM services from third-party applications. However, OEMs often introduce vulnerabilities when they add market-differentiating features because they fail to correctly reconfigure this complex combination of policies. In this paper, we propose the POLYSCOPE tool to triage Android filesystem access control policies to find the authorized operations that may be exploited by adversaries to escalate their privileges, called attack operations. In this paper, we demonstrate the effectiveness of POLYSCOPE by assessing the impact of the recently introduced Scoped Storage defense for Android. POLYSCOPE introduces three major advantages over prior access control policy analyses for this analysis: (1) independent extension and analysis of individual policy models, to ease the addition of Scoped Storage; (2) knowledge of the flexibility that untrusted parties have to modify access control policies; and (3) the ability to identify attack operations that system configurations allow. We apply POLYSCOPE to three Google and five OEM Android releases, finding that Scoped Storage reduces the number of attack operations possible on external storage resources by over 50%. However, we also find two previously unknown vulnerabilities because OEMs only adopt Scoped Storage partially, limiting its benefit. Thus, we show how to use POLYSCOPE to assess an ideal scenario where all apps are compliant to Scoped Storage, which can the number of untrusted parties that can access attack operations by over 65% on OEM systems. As a result, we find that POLYSCOPE can help Android OEMs triage complex access control policies to identify the specific attack operations worthy of further examination.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 387fa73b-460d-4861-ac5a-d24130df3c17

Cited by top-tier papers8

Ask how each one uses it

Builds on2

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines