WindowGuard: Systematic Protection of GUI Security in Android
Chuangang Ren, Peng Liu, Sencun Zhu
摘要
Android graphic user interface (GUI) system plays an important role in rendering app GUIs on display and interacting with users. However, the security of this critical subsystem remains under-investigated. In fact, Android GUI has been plagued by a variety of GUI attacks in recent years. GUI attack refers to any harmful behavior that attempts to adversely affect the integrity or availability of the GUIs belonging to other apps. These attacks are real threats and can cause severe consequences, such as sensitive user information leakage, user device denial of service, etc. Given the seriousness and rapid growth of GUI attacks, we are in a pressing need for a comprehensive defense solution. Nevertheless, existing defense methods fall short in defense coverage, effectiveness and practicality. To overcome these challenges, we systematically scrutinize the security implications of Android GUI system design and propose a new security model, Android Window Integrity (AWI), to comprehensively protect the system against GUI attacks. The AWI model defines the user session to be protected and the legitimacy of GUI system states in the unique mobile GUI environment. By doing so, it can protect a normal user session against arbitrary manipulation by attackers, and still preserve the original user experience. Our implementation, WindowGuard, enforces the AWI model and responds to a suspicious behavior by briefing the user about a security event and asking for the final decision from the user. This design not only improves the detection accuracy, but also makes WindowGuard more usable and practical to meet diverse user needs. WindowGuard is implemented as an Xposed module, making it practical to be quickly deployed on a large number of user devices. Our evaluation shows that WindowGuard can successfully detect all known GUI attacks, while yielding small impacts on user experience and system performance. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen 等CCS 2017 · 被引用 47 次
- Too Much Accessibility is Harmful! Automated Detection and Analysis of Overly Accessible Elements in Mobile AppsForough Mehralian, Navid Salehnamadi, Syed Fatiul Huq, Sam MalekASE 2022 · 被引用 19 次
- Demystifying Diehard Android AppsHao Zhou, Haoyu Wang, Yajin Zhou, Xiapu Luo 等ASE 2020 · 被引用 17 次
- A Decade of Privacy-Relevant Android App Reviews: Large Scale TrendsOmer Akgul, Sai Teja Peddinti, Nina Taft, Michelle L. Mazurek 等USENIX Security 2024 · 被引用 14 次
它引用的顶会 Paper2
相关 Paper
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 被引用 126 次
- Beyond the Surface: Uncovering the Unprotected Components of Android Against Overlay AttackHao Zhou, Shuohan Wu, Chenxiong Qian, Xiapu Luo 等NDSS 2024
- Mind the Gap: Action Rebinding Attacks against Android GUI AgentsYi Qian, Kunwei Qian, Xingbang He, Ligeng Chen 等CCS 2026
- WinSpy: Cross-window Side-channel Attacks on Android's Multi-window ModeZeng Li, Chuan Yan, Liuhuo Wan, Hui Zhuang 等MobiCom 2025
- Checking conformance of applications against GUI policiesZhen Zhang, Yu Feng, Michael D. Ernst, Sebastian Porst 等FSE 2021 · 被引用 8 次
