LibGuard: Protecting Sensitive Data In Android Third-Party Libraries From XLDH Attacks

被引:0
|
作者
He, Fannv [1 ]
Wang, Jice [1 ]
Huang, Yuhang [1 ]
Peng, Xiancui [1 ]
Zhang, Yuqing [1 ,2 ]
机构
[1] Univ Chinese Acad Sci, Natl Comp Network Intrus Protect Ctr, Beijing, Peoples R China
[2] Hainan Univ, Sch Cyberspace Secur, Haikou, Peoples R China
基金
北京市自然科学基金; 中国国家自然科学基金;
关键词
Third-party Library; Attack; Defense; Access control;
D O I
10.1109/ICCCN61486.2024.10637585
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile app vendors/developers extensively integrate third-party libraries into mobile applications. While they enrich the functions of apps, third-party libraries also bring in security risks. It has been widely studied that malicious third-party libraries could collect users' sensitive data from the host apps and the app backend servers. Recent research has reported a new attack vector - malicious libraries strategically target other vendors' library(SDKs) integrated in the same host app to harvest private user data. In this paper, we found two new dimensions of cross library data harvesting(XLDH) attack with serious privacy impacts that start from two new attack surfaces - accessing sensitive fields and accessing sensitive storage. However, the mitigation scheme, significantly, has not been yet studied. To prevent the leaks of sensitive data due to XLDH activities, we first proposed a mitigation scheme - LibGuard, which has been proven to be effective without affecting user's experience on real-world apps.
引用
收藏
页数:6
相关论文
共 50 条
  • [11] DPC:A Dynamic Permission Control Mechanism for Android Third-Party Libraries
    Hsu, Fu-Hau
    Liu, Nien-Chi
    Hwang, Yan-Ling
    Liu, Che-Hao
    Wang, Chuan-Sheng
    Chen, Chang-Yi
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (04) : 1751 - 1761
  • [12] LibRadar: Fast and Accurate Detection of Third-party Libraries in Android Apps
    Ma, Ziang
    Wang, Haoyu
    Guo, Yao
    Chen, Xiangqun
    2016 IEEE/ACM 38TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING COMPANION (ICSE-C), 2016, : 653 - 656
  • [13] User-Side Updating of Third-Party Libraries for Android Applications
    Ogawa, Hiroki
    Takimoto, Eiji
    Mouri, Koichi
    Saito, Shoichi
    2018 SIXTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING WORKSHOPS (CANDARW 2018), 2018, : 452 - 458
  • [14] Detecting Third-Party Libraries in Android Applications with High Precision and Recall
    Zhang, Yuan
    Dai, Jiarun
    Zhang, Xiaohan
    Huang, Sirong
    Yang, Zhemin
    Yang, Min
    Chen, Hao
    2018 25TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ANALYSIS, EVOLUTION AND REENGINEERING (SANER 2018), 2018, : 141 - 152
  • [15] SurgeScan: Enforcing Security Policies on Untrusted Third-Party Android Libraries
    Vronsky, Jonathan
    Stevens, Ryan
    Chen, Hao
    2017 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTED, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2017,
  • [16] Understanding and Conquering the Difficulties in Identifying Third-Party Libraries From Millions of Android Apps
    Zhang, Yanghua
    Wang, Jice
    Huang, Hexiang
    Zhang, Yuqing
    Liu, Peng
    IEEE TRANSACTIONS ON BIG DATA, 2022, 8 (06) : 1511 - 1523
  • [17] Research on Third-Party Libraries in Android Apps: A Taxonomy and Systematic Literature Review
    Zhan, Xian
    Liu, Tianming
    Fan, Lingling
    Li, Li
    Chen, Sen
    Luo, Xiapu
    Liu, Yang
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (10) : 4181 - 4213
  • [18] Automated Detection and Classification of Third-Party Libraries in Large Scale Android Apps
    Wang H.-Y.
    Guo Y.
    Ma Z.-A.
    Chen X.-Q.
    Guo, Yao (yaoguo@pku.edu.cn), 1600, Chinese Academy of Sciences (28): : 1373 - 1388
  • [19] Should energy consumption influence the choice of Android third-party HTTP libraries?
    Anwar, Hina
    Demirer, Berker
    Pfahl, Dietmar
    Srirama, Satish
    2020 IEEE/ACM 7TH INTERNATIONAL CONFERENCE ON MOBILE SOFTWARE ENGINEERING AND SYSTEMS, MOBILESOFT, 2020, : 87 - 97
  • [20] ANDetect: A Third-party Ad Network Libraries Detection Framework for Android Applications
    Liu, Xinyu
    Jin, Ze
    Liu, Jiaxi
    Liu, Wei
    Wang, Xiaoxi
    Liu, Qixu
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 98 - 112