Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential Analysis
Andrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti, Ali Zand, Christopher Kruegel, Giovanni Vigna
摘要
Mobile apps are notorious for collecting a wealth of private information from users. Despite significant effort from the research community in developing privacy leak detection tools based on data flow tracking inside the app or through network traffic analysis, it is still unclear whether apps and ad libraries can hide the fact that they are leaking private information. In fact, all existing analysis tools have limitations: data flow tracking suffers from imprecisions that cause false positives, as well as false negatives when the data flow from a source of private information to a network sink is interrupted; on the other hand, network traffic analysis cannot handle encryption or custom encoding. We propose a new approach to privacy leak detection that is not affected by such limitations, and it is also resilient to obfuscation techniques, such as encoding, formatting, encryption, or any other kind of transformation performed on private information before it is leaked. Our work is based on blackbox differential analysis, and it works in two steps: first, it establishes a baseline of the network behavior of an app; then, it modifies sources of private information, such as the device ID and location, and detects leaks by observing deviations in the resulting network traffic. The basic concept of black-box differential analysis is not novel, but, unfortunately, it is not practical enough to precisely analyze modern mobile apps. In fact, their network traffic contains many sources of non-determinism, such as random identifiers, timestamps, and server-assigned session identifiers, which, when not handled properly, cause too much noise to correlate output changes with input changes. The main contribution of this work is to make black-box differential analysis practical when applied to modern Android apps. In particular, we show that the network-based non-determinism can often be explained and eliminated, and it is thus possible to reliably use variations in the network traffic as a strong signal to detect privacy leaks. We implemented this approach in a tool, called AGRIGENTO, and we evaluated it on more than one thousand Android apps. Our evaluation shows that our approach works well in practice and outperforms current state-of-the-art techniques. We conclude our study by discussing several case studies that show how popular apps and ad libraries currently exfiltrate data by using complex combinations of encoding and encryption mechanisms that other approaches fail to detect. Our results show that these apps and libraries seem to deliberately hide their data leaks from current approaches and clearly demonstrate the need for an obfuscation-resilient approach such as ours. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski 等USENIX Security 2021 · 被引用 2,866 次
- Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking EcosystemAbbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan 等NDSS 2018 · 被引用 271 次
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On 等USENIX Security 2019 · 被引用 196 次
- Bug Fixes, Improvements, ... and Privacy Leaks - A Longitudinal Study of PII Leaks Across Android App VersionsJingjing Ren, Martina Lindorfer, Daniel J. Dubois, Ashwin Rao 等NDSS 2018 · 被引用 91 次
- Diane: Identifying Fuzzing Triggers in Apps to Generate Under-constrained Inputs for IoT DevicesNilo Redini, Andrea Continella, Dipanjan Das, Giulio De Pasquale 等S&P 2021 · 被引用 72 次
它引用的顶会 Paper3
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 被引用 188 次
- Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing PolicyVitor Monte Afonso, Paulo L. de Geus, Antonio Bianchi, Yanick Fratantonio 等NDSS 2016 · 被引用 119 次
- Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile ServicesChaoshun Zuo, Wubing Wang, Zhiqiang Lin, Rui WangNDSS 2016 · 被引用 40 次
相关 Paper
- Algebraic-datatype taint tracking, with applications to understanding Android identifier leaksSydur Rahaman, Iulian Neamtiu, Xin YinFSE 2021 · 被引用 3 次
- WhisperCatcher: Demystifying Unauthorized and Encrypted Private Data Transmission in Android ApplicationsZhaoyu Qiu, Ming Fan, Bocan Ma, Yutian Tang 等ICSE 2026
- RAICC: Revealing Atypical Inter-Component Communication in Android AppsJordan Samhi, Alexandre Bartel, Tegawendé F. Bissyandé, Jacques KleinICSE 2021 · 被引用 3 次
- FOAP: Fine-Grained Open-World Android App FingerprintingJianfeng Li, Hao Zhou, Shuohan Wu, Xiapu Luo 等USENIX Security 2022
- An Empirical Study on the Robustness of Android Third-Party Library Detection Tools Against Advanced ObfuscationDahan Pan, Zhuohao Zhang, Yunjia Min, Runhan Feng 等ICSE 2026
