WireWatch: Measuring the Security of Proprietary Network Encryption in the Global Android Ecosystem
Mona Wang, Jeffrey Knockel, Zoë Reichert, Prateek Mittal, Jonathan R. Mayer
摘要
We present WireWatch, a large-scale measurement pipeline to evaluate the network security of Android apps. WireWatch measures apps' usage of plaintext network traffic and non-standard, proprietary network cryptography. We found that 47.6% of top Mi Store applications used proprietary network cryptography without any additional encryption, compared to only 3.51% of top Google Play Store applications. We analyzed the 18 most popular protocols from WireWatch, which belonged to 9 protocol families, including cryptosystems designed by Alibaba, iQIYI, Kuaishou, and Tencent. We found that 8 of these protocol families sent requests that allowed network eavesdroppers to decrypt underlying data, including browsing data and device metadata, among various other issues, such as being downgradable, not validating TLS certificates, and the use of RSA without OAEP. These vulnerabilities affected 26.9% of our Mi Store dataset with a cumulative 130 billion downloads. Ultimately, WireWatch reveals that a large portion of massively popular applications are using insecure proprietary network protocols to encrypt sensitive user data.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel 等S&P 2017 · 被引用 261 次
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On 等USENIX Security 2019 · 被引用 196 次
- AutoDroid: LLM-powered Task Automation in AndroidHao Wen, Yuanchun Li, Guohong Liu, Shanhui Zhao 等MobiCom 2024 · 被引用 94 次
- Make LLM a Testing Expert: Bringing Human-like Interaction to Mobile GUI Testing via Functionality-aware DecisionsZhe Liu, Chunyang Chen, Junjie Wang, Mengzhuo Chen 等ICSE 2024 · 被引用 81 次
- Return Of Bleichenbacher's Oracle Threat (ROBOT)Hanno Böck, Juraj Somorovsky, Craig YoungUSENIX Security 2018 · 被引用 69 次
相关 Paper
- Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-ProgramsYue Zhang, Yuqing Yang, Zhiqiang LinCCS 2023 · 被引用 14 次
- Hidden in Plain Sight: Exploring Encrypted Channels in Android AppsSajjad Pourali, Nayanamana Samarasinghe, Mohammad MannanCCS 2022 · 被引用 5 次
- The Not-So-Silent Type: Vulnerabilities in Chinese IME Keyboards' Network Security ProtocolsJeffrey Knockel, Mona Wang, Zoë ReichertCCS 2024 · 被引用 1 次
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 被引用 345 次
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar 等USENIX Security 2021 · 被引用 45 次
