App's Auto-Login Function Security Testing via Android OS-Level Virtualization
Wenna Song, Jiang Ming, Lin Jiang, Han Yan, Yi Xiang, Yuan Chen, Jianming Fu, Guojun Peng
摘要
Limited by the small keyboard, most mobile apps support the automatic login feature for better user experience. Therefore, users avoid the inconvenience of retyping their ID and password when an app runs in the foreground again. However, this auto-login function can be exploited to launch the so-called "data-clone attack": once the locally-stored, auto-login depended data are cloned by attackers and placed into their own smartphones, attackers can break through the login-device number limit and log in to the victim's account stealthily. A natural countermeasure is to check the consistency of device-specific attributes. As long as the new device shows different device fingerprints with the previous one, the app will disable the auto-login function and thus prevent data-clone attacks. In this paper, we develop VPDroid, a transparent Android OS-level virtualization platform tailored for security testing. With VPDroid, security analysts can customize different device artifacts, such as CPU model, Android ID, and phone number, in a virtual phone without user-level API hooking. VPDroid's isolation mechanism ensures that user-mode apps in the virtual phone cannot detect device-specific discrepancies. To assess Android apps' susceptibility to the data-clone attack, we use VPDroid to simulate data-clone attacks with 234 most-downloaded apps. Our experiments on five different virtual phone environments show that VPDroid's device attribute customization can deceive all tested apps that perform device-consistency checks, such as Twitter, WeChat, and PayPal. 19 vendors have confirmed our report as a zero-day vulnerability. Our findings paint a cautionary tale: only enforcing a device-consistency check at client side is still vulnerable to an advanced data-clone attack.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Virtual Device Farms for Mobile App Testing at Scale: A Pursuit for Fidelity, Efficiency, and AccessibilityHao Lin, Jiaxing Qiu, Hongyi Wang, Zhenhua Li 等MobiCom 2023 · 被引用 18 次
- When Ad Networks Misbehave: Understanding Risks of Semi-Drive-By Splash AdsSong Wu, Bo Wang, Yifan Zhang, Yinfeng Cao 等CCS 2026
它引用的顶会 Paper2
相关 Paper
- Component Security Ten Years Later: An Empirical Study of Cross-Layer Threats in Real-World Mobile ApplicationsKeke Lian, Lei Zhang, Guangliang Yang, Shuo Mao 等FSE 2024 · 被引用 5 次
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang 等NDSS 2018 · 被引用 95 次
- Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based VirtualizationWenna Song, Jiang Ming, Lin Jiang, Yi Xiang 等CCS 2021 · 被引用 11 次
- Prison Break of Android Reflection Restriction and DefenseZhen Ling, Ruizhao Liu, Yue Zhang, Kang Jia 等INFOCOM 2021
- Mobile Application Web API Reconnaissance: Web-to-Mobile Inconsistencies & VulnerabilitiesAbner Mendoza, Guofei GuS&P 2018 · 被引用 43 次
