USENIX Security2023Top-tier venue
Notice the Imposter! A Study on User Tag Spoofing Attack in Mobile Apps
Shuai Li, Zhemin Yang, Guangliang Yang, Hange Zhang, Nan Hua, Yurui Huang, Min Yang
Abstract
Recent years have witnessed the rapid development of mobile services, spanning almost every field. To characterize users and provide personalized and targeted services, user tag sharing, which labels users and shares their data, is becoming increasingly popular. Its security attracts more and more attention, and a series of privacy issues have been reported in several specific services. However, up to now, there still lacked a thorough and comprehensive understanding of the characteristics and security of user tag sharing.
In this work, we conduct a systematic study of user tag sharing and its security. We first model user tag sharing with three phases, and discover that the privacy security issue commonly exists in practice. We generalize and formalize the privacy issue as user tag spoofing. Then, we propose a novel networklevel smart fuzzing approach, called UTSFuzzer, against user tag spoofing. The key idea behind UTSFuzzer is to explore a large number of valid user tag values as input to imitate user tag spoofing against real-world mobile services. By applying UTSFuzzer on a large scale of real-world popular apps, we verify the effectiveness of UTSFuzzer and unveil that 100 mobile apps (including 115 mobile services) are vulnerable to user tag spoofing. The accumulated installations of all affected apps (users) reach more than 413 million. Additionally, UTSFuzzer shows user tag spoofing can cause serious attack efforts, including economic loss and user activity monitoring.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e36d1593-241d-427f-9d5f-14bf23c4d1cdCited by top-tier papers1
Ask how each one uses itBuilds on19
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
Related papers
- Collect Responsibly But Deliver Arbitrarily?: A Study on Cross-User Privacy Leakage in Mobile AppsShuai Li, Zhemin Yang, Nan Hua, Peng Liu et al.CCS 2022 · 6 citations
- Exploit the Last Straw That Breaks Android SystemsLei Zhang, Keke Lian, Haoyu Xiao, Zhibo Zhang et al.S&P 2022 · 10 citations
- Misdirection of Trust: Demystifying the Abuse of Dedicated URL Shortening ServiceZhibo Zhang, Lei Zhang, Zhangyue Zhang, Geng Hong et al.NDSS 2025
- Lie to Me: Abusing the Mobile Content Sharing Service for Fun and ProfitGuosheng Xu, Siyi Li, Hao Zhou, Shucen Liu et al.WWW 2022 · 5 citations
- "Tap" Without Tapping: A Tag Discovery Forgery Attack on Android NFCYilin Li, Jianliang Wu, Chaoshun Zuo, Qingchuan Zhao et al.USENIX Security 2026
