All your app links are belong to us: understanding the threats of instant apps based attacks
Yutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo, Hao Zhou, Zhou Xu
摘要
Android deep link is a URL that takes users to a specific page of a mobile app, enabling seamless user experience from a webpage to an app. Android app link, a new type of deep link introduced in Android 6.0, is claimed to offer more benefits, such as supporting instant apps and providing more secure verification to protect against hijacking attacks that previous deep links can not. However, we find that the app link is not as secure as claimed, because the verification process can be bypassed by exploiting instant apps.
In this paper, we explore the weakness of the existing app link mechanism and propose three feasible hijacking attacks. Our findings show that even popular apps are subject to these attacks, such as Twitter, Whatsapp, Facebook Message. Our observation is confirmed by Google. To measure the severity of these vulnerabilities, we develop an automatic tool to detect vulnerable apps, and perform a large-scale empirical study on 400,000 Android apps.
Experiment results suggest that app link hijacking vulnerabilities are prevalent in the ecosystem. Specifically, 27.1% apps are vulnerable to link hijacking with smart text selection (STS); 30.0% apps are vulnerable to link hijacking without STS, and all instant apps are vulnerable to instant app attack. We provide an in-depth understanding of the mechanisms behind these types of attacks. Furthermore, we propose the corresponding detection and defense methods that can successfully prevent the proposed hijackings for all the evaluated apps, thus raising the bar against the attacks on Android app links. Our insights and findings demonstrate the urgency to identify and prevent app link hijacking attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Demystifying Illegal Mobile Gambling AppsYuhao Gao, Haoyu Wang, Li Li, Xiapu Luo 等WWW 2021 · 被引用 30 次
- CHAMP: Characterizing Undesired App Behaviors from User Comments based on Market PoliciesYangyu Hu, Haoyu Wang, Tiantong Ji, Xusheng Xiao 等ICSE 2021 · 被引用 19 次
- A Comprehensive Evaluation of Android ICC Resolution TechniquesJiwei Yan, Shixin Zhang, Yepang Liu, Xi Deng 等ASE 2022 · 被引用 15 次
- Demystifying the underground ecosystem of account registration botsYuhao Gao, Guoai Xu, Li Li, Xiapu Luo 等FSE 2022 · 被引用 12 次
- Uncovering and Exploiting Hidden APIs in Mobile Super AppsChao Wang, Yue Zhang, Zhiqiang LinCCS 2023 · 被引用 11 次
它引用的顶会 Paper9
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ARTLei Xue, Yajin Zhou, Ting Chen, Xiapu Luo 等USENIX Security 2017 · 被引用 81 次
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 被引用 68 次
- Tackling runtime-based obfuscation in Android with TIROMichelle Y. Wong, David LieUSENIX Security 2018 · 被引用 59 次
- Draco: A System for Uniform and Fine-grained Access Control for Web Code on AndroidGüliz Seray Tuncay, Soteris Demetriou, Carl A. GunterCCS 2016 · 被引用 43 次
相关 Paper
- Measuring the Insecurity of Mobile Deep Links of AndroidFang Liu, Chun Wang, Andres Pico, Danfeng Yao 等USENIX Security 2017 · 被引用 30 次
- DeepExploitor: LLM-Enhanced Automated Exploitation of DeepLink Attack in Hybrid AppsZhangyue Zhang, Lei Zhang, Zhibo Zhang, Yongheng Liu 等ASE 2025
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 被引用 21 次
- Vulnerable Implicit Service: A RevisitLingguang Lei, Yi He, Kun Sun, Jiwu Jing 等CCS 2017 · 被引用 5 次
- Component Security Ten Years Later: An Empirical Study of Cross-Layer Threats in Real-World Mobile ApplicationsKeke Lian, Lei Zhang, Guangliang Yang, Shuo Mao 等FSE 2024 · 被引用 5 次
