When Apps Outlive Vendors: Security Implications of IoT Abandonware
Dayeon Kang, Elvis Yeboah-Duako, Sachin Thomas, Pubali Datta
摘要
As the Internet of Things (IoT) market continues to expand, many companion apps are being published in app stores, raising security concerns for those whose vendors have abandoned support. Even after vendors discontinue support, such applications frequently remain operational on users' mobile devices, continue to interface with users' IoT devices and collect user data without receiving security updates. This leaves known and newly discovered vulnerabilities unmitigated, increasing risks of remote exploitation, unauthorized device access, and prolonged data misuse. We define these abandoned applications as "IoT abandonware" and present the first large-scale measurement study of the security risks associated with discontinued applications.
We analyze 61,500 IoT companion Android applications that had not been updated for at least two years or were no longer in service as of March 2025. From decompiled binaries, we extracted latent and embedded resources (e.g., bundled libraries, domain names, and permissions), and assessed their security implications. First, we identify outdated dependencies with post-abandonment CVE reports and discover domains vulnerable to takeover or data exfiltration. Second, we perform static data-flow analysis to trace how sensitive data, inferred from the extracted permissions, propagates to broken or hijackable external endpoints. We found that persistent analytics and third-party trackers continue aggregating user data and device telemetry long after vendor control lapses, creating data flows that adversaries can redirect or abuse. Overall, we identified security risks in 73.6% of our dataset, with 30 of the top 1,000 most-installed apps sending data to broken external endpoints.
• Security and privacy → Software and application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 被引用 411 次
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 被引用 91 次
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon 等S&P 2016 · 被引用 76 次
- Looking from the Mirror: Evaluating IoT Device Security through Mobile Companion AppsXueqiang Wang, Yuqiong Sun, Susanta Nanda, XiaoFeng WangUSENIX Security 2019 · 被引用 65 次
相关 Paper
- Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion AppsYuhong Nan, Xueqiang Wang, Luyi Xing, Xiaojing Liao 等USENIX Security 2023
- IoTFlow: Inferring IoT Device Behavior at Scale through Static Mobile Companion App AnalysisDavid Schmidt, Carlotta Tagliaro, Kevin Borgolte, Martina LindorferCCS 2023 · 被引用 13 次
- Lost in the Mists of Time: Expirations in DNS Footprints of Mobile AppsJohnny So, Iskander Sánchez-Rola, Nick NikiforakisUSENIX Security 2025
- Understanding IoT Security from a Market-Scale PerspectiveXin Jin, Sunil Manandhar, Kaushal Kafle, Zhiqiang Lin 等CCS 2022 · 被引用 30 次
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu 等ICSE 2022 · 被引用 21 次
