USENIX Security2022Top-tier venue
Experimental Security Analysis of the App Model in Business Collaboration Platforms
Yunang Chen, Yue Gao, Nick Ceccio, Rahul Chatterjee, Kassem Fawaz, Earlence Fernandes
Abstract
Business Collaboration Platforms like Microsoft Teams and Slack enable teamwork by supporting text chatting and third-party resource integration. A user can access online file storage, make video calls, and manage a code repository, all from within the platform, thus making them a hub for sensitive communication and resources. The key enabler for these productivity features is a third-party application model. We contribute an experimental security analysis of this model and the third-party apps. Performing this analysis is challenging because commercial platforms and their apps are closed-source systems. Our analysis methodology is to systematically investigate different types of interactions possible between apps and users. We discover that the access control model in these systems violates two fundamental security principles: least privilege and complete mediation. These violations enable a malicious app to exploit the confidentiality and integrity of user messages and third-party resources connected to the platform. We construct proof-of-concept attacks that can: (1) eavesdrop on user messages without having permission to read those messages; (2) launch fake video calls; (3) automatically merge code into repositories without user approval or involvement. Finally, we provide an analysis of countermeasures that systems like Slack and Microsoft Teams can adopt today.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Is It Safe to Share Your Files? An Empirical Security Analysis of Google WorkspaceLiuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong BaiWWW 2024 · 6 citations
- Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group ChatsKai-Hsiang Chou, Yi-Min Lin, Yi-An Wang, Jonathan Weiping Li et al.USENIX Security 2025
- RøB: Ransomware over Modern Web BrowsersHarun Oz, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay et al.USENIX Security 2023
Builds on10
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 684 citations
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 253 citations
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu et al.USENIX Security 2018 · 236 citations
- Skill Squatting Attacks on Amazon AlexaDeepak Kumar, Riccardo Paccagnella, Paul Murley, Eric Hennenfent et al.USENIX Security 2018 · 177 citations
- TriggerScope: Towards Detecting Logic Bombs in Android ApplicationsYanick Fratantonio, Antonio Bianchi, William K. Robertson, Engin Kirda et al.S&P 2016 · 161 citations
Related papers
- Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat SystemsMingming Zha, Jice Wang, Yuhong Nan, Xiaofeng Wang et al.NDSS 2022
- Unveiling AI-Driven Web Applications: Insights into Characteristics, Functionality, and ComplianceLiuhuo Wan, Zicong Liu, Chuan Yan, Liujia Wan et al.FSE 2026
- Identity Confusion in WebView-based Mobile App-in-app EcosystemsLei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao et al.USENIX Security 2022
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
- Understanding and Mitigating Remote Code Execution Vulnerabilities in Cross-platform EcosystemFeng Xiao, Zheng Yang, Joey Allen, Guangliang Yang et al.CCS 2022 · 14 citations
