Hindsight: Understanding the Evolution of UI Vulnerabilities in Mobile Browsers
Meng Luo, Oleksii Starov, Nima Honarmand, Nick Nikiforakis
摘要
Much of recent research on mobile security has focused on malicious applications. Although mobile devices have powerful browsers that are commonly used by users and are vulnerable to at least as many attacks as their desktop counterparts, mobile web security has not received the attention that it deserves from the community. In particular, there is no longitudinal study that investigates the evolution of mobile browser vulnerabilities over the diverse set of browsers that are available out there. In this paper, we undertake the first such study, focusing on UI vulnerabilities among mobile browsers. We investigate and quantify vulnerabilities to 27 UI-related attacks-compiled from previous work and augmented with new variations of our own-across 128 browser families and 2,324 individual browser versions spanning a period of more than 5 years. In the process, we collect an extensive dataset of browser versions, old and new, from multiple sources. We also design and implement a browser-agnostic testing framework, called Hindsight, to automatically expose browsers to attacks and evaluate their vulnerabilities. We use Hindsight to conduct the tens of thousands of individual attacks that were needed for this study. We discover that 98.6% of the tested browsers are vulnerable to at least one of our attacks and that the average mobile web browser is becoming less secure with each passing year. Overall, our findings support the conclusion that mobile web security has been ignored by the community and must receive more attention.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 被引用 94 次
- Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing AttacksKaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng 等USENIX Security 2021 · 被引用 49 次
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
- Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile BrowsersMeng Luo, Pierre Laperdrix, Nima Honarmand, Nick NikiforakisNDSS 2019 · 被引用 35 次
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee 等USENIX Security 2024 · 被引用 29 次
它引用的顶会 Paper1
相关 Paper
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 被引用 279 次
- PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing BlacklistsAdam Oest, Yeganeh Safaei, Penghui Zhang, Brad Wardman 等USENIX Security 2020
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 被引用 7 次
- Automated Generation of Event-Oriented Exploits in Android Hybrid AppsGuangliang Yang, Jeff Huang, Guofei GuNDSS 2018 · 被引用 79 次
- An Empirical Analysis of UI-based Flaky TestsAlan Romano, Zihe Song, Sampath Grandhi, Wei Yang 等ICSE 2021 · 被引用 43 次
