Peep With A Mirror: Breaking The Integrity of Android App Sandboxing via Unprivileged Cache Side Channel
Yan Lin, Joshua Wong, Xiang Li, Haoyu Ma, Debin Gao
摘要
Application sandboxing is a well-established security principle employed in the Android platform to safeguard sensitive information. However, hardware resources, specifically the CPU caches, are beyond the protection of this software-based mechanism, leaving room for potential side-channel attacks. Existing attacks against this particular weakness of app sandboxing mainly target shared components among apps, hence can only observe system-level program dynamics (such as UI tracing). In this work, we advance cache side-channel attacks by demonstrating the viability of non-intrusive and fine-grained probing across different app sandboxes, which have the potential to uncover app-specific and private program behaviors, thereby highlighting the importance of further research in this area. In contrast to conventional attack schemes, our proposal leverages a user-level attack surface within the Android platform, namely the dynamic inter-app component sharing with package context (also known as DICI), to fully map the code of targeted victim apps into the memory space of the attacker's sandbox. Building upon this concept, we have developed a proof-of-concept attack demo called ANDROSCOPE and demonstrated its effectiveness with empirical evaluations where the attack app was shown to be able to successfully infer private information pertaining to individual apps, such as driving routes and keystroke dynamics with considerable accuracy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 被引用 1 次
- Formal Security Analysis of the Olvid MessengerNoemi Terzo), Cas Cremers, Ruben Gonzalez, Peter Schwabe) 等CCS 2026
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi 等USENIX Security 2026
它引用的顶会 Paper9
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 被引用 155 次
- Inferring User Routes and Locations Using Zero-Permission Mobile SensorsSashank Narain, Triet D. Vo-Huu, Kenneth Block, Guevara NoubirS&P 2016 · 被引用 149 次
- Return-Oriented Flush-Reload Side Channels on ARM and Their Implications for Android DevicesXiaokuan Zhang, Yuan Xiao, Yinqian ZhangCCS 2016 · 被引用 77 次
- An empirical assessment of security risks of global Android banking appsSen Chen, Lingling Fan, Guozhu Meng, Ting Su 等ICSE 2020 · 被引用 70 次
相关 Paper
- Borrowing your enemy's arrows: the case of code reuse in Android via direct inter-app code invocationJun Gao, Li Li, Pingfan Kong, Tegawendé F. Bissyandé 等FSE 2020 · 被引用 10 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
- OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOSXiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang 等NDSS 2018 · 被引用 34 次
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
- The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock AndroidJie Huang, Oliver Schranz, Sven Bugiel, Michael BackesCCS 2017 · 被引用 32 次
