Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat Systems
Mingming Zha, Jice Wang, Yuhong Nan, Xiaofeng Wang, Yuqing Zhang, Zelin Yang
摘要
—Team Chat ( TACT ) systems are now widely used for online collaborations and project management. A unique feature of these systems is their integration of third-party apps, which extends their capabilities but also brings in the complexity that could potentially put the TACT system and its end-users at risk. In this paper, for the first time, we demonstrate that third-party apps in TACT systems indeed open the door to new security risks, such as privilege escalation, deception, and privacy leakage. We studied 12 popular TACT systems, following the key steps of a third-party app’s life cycle (its installation, update, configuration, and runtime operations). Notably, we designed and implemented a pipeline for efficiently identifying the security risks of TA APIs, a core feature provided for system-app communication. Our study leads to the discovery of 55 security issues across the 12 platforms, with 25 in the install and configuration stages and 30 vulnerable (or risky) APIs. These security weaknesses are mostly introduced by improper design, lack of fine-grained access control, and ambiguous data-access policies. We reported our findings to all related parties, and 8 have been acknowledged. Although we are still working with the TACT vendors to determine the security impacts of the remaining flaws, their significance has already been confirmed by our user study, which further reveals users’ concerns about some security policies implemented on mainstream TACT platforms and their misconceptions about the protection in place. Also, our communication with the vendors indicates that their threat models have not been well-thought-out, with some assumptions conflicting with each other. We
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Enforcing End-to-end Security for Remote Conference ApplicationsYuelin Liu, Huangxun Chen, Zhice YangS&P 2024 · 被引用 5 次
- Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile AppsFannv He, Yan Jia, Jiayu Zhao, Yue Fang 等NDSS 2024
它引用的顶会 Paper6
- Charting the Attack Surface of Trigger-Action IoT PlatformsQi Wang, Pubali Datta, Wei Yang, Si Liu 等CCS 2019 · 被引用 162 次
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang 等S&P 2019 · 被引用 160 次
- Finding Clues for Your Secrets: Semantics-Driven, Learning-Based Privacy Discovery in Mobile AppsYuhong Nan, Zhemin Yang, Xiaofeng Wang, Yuan Zhang 等NDSS 2018 · 被引用 79 次
- A First Look at ZoombombingChen Ling, Utkucan Balci, Jeremy Blackburn, Gianluca StringhiniS&P 2021 · 被引用 51 次
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar 等USENIX Security 2021 · 被引用 45 次
相关 Paper
- Experimental Security Analysis of the App Model in Business Collaboration PlatformsYunang Chen, Yue Gao, Nick Ceccio, Rahul Chatterjee 等USENIX Security 2022
- A First Look at Security and Privacy Risks in the RapidAPI EcosystemSong Liao, Long Cheng, Xiapu Luo, Zheng Song 等CCS 2024 · 被引用 3 次
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu 等CCS 2023 · 被引用 15 次
- Identifying privacy weaknesses from multi-party trigger-action integration platformsKulani Mahadewa, Yanjun Zhang, Guangdong Bai, Lei Bu 等ISSTA 2021 · 被引用 25 次
- Identity Confusion in WebView-based Mobile App-in-app EcosystemsLei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao 等USENIX Security 2022
