Pride and Prejudice in Progressive Web Apps: Abusing Native App-like Features in Web Applications
Jiyeon Lee, Hayeon Kim, Junghwan Park, Insik Shin, Sooel Son
摘要
Progressive Web App (PWA) is a new generation of Web application designed to provide native app-like browsing experiences even when a browser is offline. PWAs make full use of new HTML5 features which include push notification, cache, and service worker to provide short-latency and rich Web browsing experiences.
We conduct the first systematic study of the security and privacy aspects unique to PWAs. We identify security flaws in main browsers as well as design flaws in popular third-party push services, that exacerbate the phishing risk. We introduce a new sidechannel attack that infers the victim's history of visited PWAs. The proposed attack exploits the offline browsing feature of PWAs using a cache. We demonstrate a cryptocurrency mining attack which abuses service workers. Defenses and recommendations to mitigate the identified security and privacy risks are suggested with in-depth understanding.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
- "Shhh...be quiet!" Reducing the Unwanted Interruptions of Notification Permission Prompts on ChromeIgor Bilogrevic, Balazs Engedy, Judson L. Porter III, Nina Taft 等USENIX Security 2021 · 被引用 10 次
- InviCloak: An End-to-End Approach to Privacy and Performance in Web Content DistributionShihan Lin, Rui Xin, Aayush Goel, Xiaowei YangCCS 2022 · 被引用 5 次
- Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost WebsitesTakuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya MoriNDSS 2020
- Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy LeakageSoroush Karami, Panagiotis Ilia, Jason PolakisNDSS 2021
它引用的顶会 Paper7
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett 等CCS 2017 · 被引用 248 次
- Beauty and the Burst: Remote Identification of Encrypted Video StreamsRoei Schuster, Vitaly Shmatikov, Eran TromerUSENIX Security 2017 · 被引用 205 次
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 被引用 118 次
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 被引用 101 次
- How the Web Tangled Itself: Uncovering the History of Client-Side Web (In)SecurityBen Stock, Martin Johns, Marius Steffens, Michael BackesUSENIX Security 2017 · 被引用 67 次
相关 Paper
- Fill in the Blanks: Empirical Analysis of the Privacy Threats of Browser Form AutofillXu Lin, Panagiotis Ilia, Jason PolakisCCS 2020 · 被引用 24 次
- SWAPP: A New Programmable Playground for Web Application SecurityPhakpoom Chinprutthiwong, Jianwei Huang, Guofei GuUSENIX Security 2022
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser 等USENIX Security 2019 · 被引用 159 次
- Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel DefensesAnatoly Shusterman, Ayush Agarwal, Sioli O'Connell, Daniel Genkin 等USENIX Security 2021 · 被引用 73 次
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 被引用 67 次
