WhisperCatcher: Demystifying Unauthorized and Encrypted Private Data Transmission in Android Applications
Zhaoyu Qiu, Ming Fan, Bocan Ma, Yutian Tang, Lei Xue, Haijun Wang, Ting Liu
摘要
The privacy issues associated with Android apps are increasingly raising our concerns. Unfortunately, a large portion of privacy breaches in Android apps cannot be accurately detected by existing approaches, especially private data that is collected without consent and transmitted in encrypted form. Even if existing studies are able to break the encryption at protocol level to recover the structure and content of traffic packets, they are still unable to understand the code layer encrypted data. To solve this problem, we propose WhisperCatcher, an automated tool for analyzing unauthorized and encrypted private data transmitted by apps. For each app, WhisperCatcher first captures the raw traffic generated during the app’s startup phase, before the user consents to the privacy policy, and then extracts the semantic information. Furthermore, it utilizes the traffic semantics to guide static code analysis and extracts transmission-related key functions. Finally, it performs dynamic instrumentation analysis and recovers the encrypted data, thereby identifying unauthorized private data transmissions. Extensive evaluations show that WhisperCatcher significantly outperforms existing tools, and it achieves the recall of 91.38% and F1-Score of 95.49%, respectively. In addition, we conduct a large-scale measurement analysis on 14,879 apps and WhisperCatcher identifies 13,966 traffic flows from 4,966 apps that transmit private data prior to obtaining user consent, among which 3,838 (27.48%) flows contain app-encrypted data. Our findings highlight the potential privacy leakage risks in Android apps, which should be brought to the attention of the community.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper21
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma 等NeurIPS 2022 · 被引用 22,562 次
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On 等USENIX Security 2019 · 被引用 196 次
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 被引用 188 次
- Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential AnalysisAndrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti 等NDSS 2017 · 被引用 131 次
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin 等NDSS 2018 · 被引用 87 次
相关 Paper
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 被引用 9 次
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 被引用 20 次
- WhisperTest: A Voice-Control-based Library for iOS UI AutomationZahra Moti, Tom Janssen-Groesbeek, Steven Monteiro, Andrea Continella 等CCS 2025
- Ghosts in the Memory: Detecting Unintended Sensitive Data in Android AppsSeonghyeon Song, Taeyoung Kim, Woojoo Kim, Seojin Park 等ISSTA 2026
- Understanding Worldwide Private Information Collection on AndroidYun Shen, Pierre-Antoine Vervier, Gianluca StringhiniNDSS 2021
