引用本文:王持恒,陈晶,苏涵,何琨,杜瑞颖.基于宿主权限的移动广告漏洞攻击技术.软件学报,2018,29(5):1392-1409
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 4221次   下载 7964 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于宿主权限的移动广告漏洞攻击技术
王持恒1, 陈晶1, 苏涵1, 何琨1, 杜瑞颖1,2
1.国家网络安全学院(武汉大学), 湖北 武汉 430072;2.地球空间信息技术协同创新中心, 湖北 武汉 430079
摘要:
移动广告作为市场营销的一种重要手段,越来越受到应用开发者的青睐,其市场规模也日趋增大.但是,为了追求广告的精准投放和其他非法利益,移动广告给用户的隐私与财产安全也带来了很大的威胁.目前,众多学者关注广告平台、广告主和移动应用的安全风险,还未出现在广告网络中直接发起攻击的案例.提出了一种基于宿主权限的移动广告漏洞攻击方法,能够在移动应用获取广告内容时,在流量中植入攻击代码.通过对广告流量的拦截,提取出宿主应用的标识和客户端相关信息,间接得到宿主应用的权限列表和当前设备的WebView漏洞.另外,提出了一种攻击者的能力描述语言,能够自动生成定制化的攻击载荷.实验结果表明,所提出的攻击方法能够影响到大量含有移动广告的应用.几个攻击实例的分析也证明了自动生成攻击载荷的可行性.最后,提出了几种防护方法和安全增强措施,包括应用标识混淆、完整性校验和中间人攻击防护技术等.
关键词:  移动广告生态系统  宿主权限  中间人攻击  攻击载荷自动生成  能力描述语言
DOI:10.13328/j.cnki.jos.005494
分类号:
基金项目:国家自然科学基金(61572380,61772383,61702379);国家重点基础研究发展计划(973)(2014CB340600)
Mobile Advertising Loophole Attack Technology Based on Host APP's Permissions
WANG Chi-Heng1, CHEN Jing1, SU Han1, HE Kun1, DU Rui-Ying1,2
1.School of Cyber Science and Engineering(Wuhan University), Wuhan 430072, China;2.Collaborative Innovation Center of Geospatial Technology, Wuhan 430079, China
Abstract:
As an important channel for mobile marketing,mobile advertising has become more and more popular among app developers.However,in pursuit of targeted ads delivery and other illegal tactics,mobile ads may introduce serious threat to users' privacy and property.Recently,many researches have paid attention on the threat of advertisement platforms,advertisement providers,and mobile apps,though few studies put focus on the security of advertisement network.In this paper,based on the automatic analysis of host app's permissions,a man-in-the-middle (MITM) attack scheme is proposed to inject malicious code into the ads' traffic.Through analyzing network traffic,this method can identify the name of host app and extract the permissions from the official app market.Moreover,it also extracts the device information such as system version and sensors,which is helpful to excavate the loophole of corresponding WebView.To generate the attack code automatically,a capability description language (CDL),which can describe the attacker's ability in a standardized format,is also developed.The distribution of loopholes among different Android versions are studied.Experimental results show that the proposed attack scheme can affect many apps,and the attack cases also illustrate the feasibility of this work.In the end,several protection methods and security enhance schemes,including host app name confusion,ads content integrity check,and the remission technologies of MITM attacks,are put forward.
Key words:  mobile advertising ecosystem  host permission  man-in-the-middle attack  automatic attack code generation  capabilit description language

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: