USENIX Security2024Top-tier venue
Peep With A Mirror: Breaking The Integrity of Android App Sandboxing via Unprivileged Cache Side Channel
Yan Lin, Joshua Wong, Xiang Li, Haoyu Ma, Debin Gao
Abstract
Application sandboxing is a well-established security principle employed in the Android platform to safeguard sensitive information. However, hardware resources, specifically the CPU caches, are beyond the protection of this software-based mechanism, leaving room for potential side-channel attacks. Existing attacks against this particular weakness of app sandboxing mainly target shared components among apps, hence can only observe system-level program dynamics (such as UI tracing). In this work, we advance cache side-channel attacks by demonstrating the viability of non-intrusive and fine-grained probing across different app sandboxes, which have the potential to uncover app-specific and private program behaviors, thereby highlighting the importance of further research in this area. In contrast to conventional attack schemes, our proposal leverages a user-level attack surface within the Android platform, namely the dynamic inter-app component sharing with package context (also known as DICI), to fully map the code of targeted victim apps into the memory space of the attacker's sandbox. Building upon this concept, we have developed a proof-of-concept attack demo called ANDROSCOPE and demonstrated its effectiveness with empirical evaluations where the attack app was shown to be able to successfully infer private information pertaining to individual apps, such as driving routes and keystroke dynamics with considerable accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7c251d28-a00f-4c52-854c-3e1ec11c6f03Cited by top-tier papers3
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 1 citation
- Formal Security Analysis of the Olvid MessengerNoemi Terzo), Cas Cremers, Ruben Gonzalez, Peter Schwabe) et al.CCS 2026
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi et al.USENIX Security 2026
Builds on9
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 155 citations
- Inferring User Routes and Locations Using Zero-Permission Mobile SensorsSashank Narain, Triet D. Vo-Huu, Kenneth Block, Guevara NoubirS&P 2016 · 149 citations
- Return-Oriented Flush-Reload Side Channels on ARM and Their Implications for Android DevicesXiaokuan Zhang, Yuan Xiao, Yinqian ZhangCCS 2016 · 77 citations
- An empirical assessment of security risks of global Android banking appsSen Chen, Lingling Fan, Guozhu Meng, Ting Su et al.ICSE 2020 · 70 citations
Related papers
- Borrowing your enemy's arrows: the case of code reuse in Android via direct inter-app code invocationJun Gao, Li Li, Pingfan Kong, Tegawendé F. Bissyandé et al.FSE 2020 · 10 citations
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 90 citations
- OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOSXiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang et al.NDSS 2018 · 34 citations
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
- The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock AndroidJie Huang, Oliver Schranz, Sven Bugiel, Michael BackesCCS 2017 · 32 citations
