LibGuard: Protecting Sensitive Data In Android Third-Party Libraries From XLDH Attacks

被引:0
|
作者
He, Fannv [1 ]
Wang, Jice [1 ]
Huang, Yuhang [1 ]
Peng, Xiancui [1 ]
Zhang, Yuqing [1 ,2 ]
机构
[1] Univ Chinese Acad Sci, Natl Comp Network Intrus Protect Ctr, Beijing, Peoples R China
[2] Hainan Univ, Sch Cyberspace Secur, Haikou, Peoples R China
基金
北京市自然科学基金; 中国国家自然科学基金;
关键词
Third-party Library; Attack; Defense; Access control;
D O I
10.1109/ICCCN61486.2024.10637585
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile app vendors/developers extensively integrate third-party libraries into mobile applications. While they enrich the functions of apps, third-party libraries also bring in security risks. It has been widely studied that malicious third-party libraries could collect users' sensitive data from the host apps and the app backend servers. Recent research has reported a new attack vector - malicious libraries strategically target other vendors' library(SDKs) integrated in the same host app to harvest private user data. In this paper, we found two new dimensions of cross library data harvesting(XLDH) attack with serious privacy impacts that start from two new attack surfaces - accessing sensitive fields and accessing sensitive storage. However, the mitigation scheme, significantly, has not been yet studied. To prevent the leaks of sensitive data due to XLDH activities, we first proposed a mitigation scheme - LibGuard, which has been proven to be effective without affecting user's experience on real-world apps.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Security analysis and enhancement of third-party android push service
    Lu Y.
    Li Y.
    Ying L.
    Gu Y.
    Su P.
    Feng D.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2016, 53 (11): : 2431 - 2445
  • [42] AndroLib: Third-Party Software Library Recommendation for Android Applications
    Chouchen, Moataz
    Ouni, Ali
    Mkaouer, Mohamed Wiem
    REUSE IN EMERGING SOFTWARE ENGINEERING PRACTICES, ICSR 2020, 2020, 12541 : 208 - 225
  • [43] Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java']Java Projects
    Zhang, Lyuye
    Liu, Chengwei
    Xu, Zhengzi
    Chen, Sen
    Fan, Lingling
    Zhao, Lida
    Wu, Jiahui
    Liu, Yang
    2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ICSE, 2023, : 2540 - 2552
  • [44] Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps
    Zhao, Kaifa
    Zhan, Xian
    Yu, Le
    Zhou, Shiyao
    Zhou, Hao
    Luo, Xiapu
    Wang, Haoyu
    Liu, Yepang
    2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ICSE, 2023, : 1583 - 1595
  • [45] CrossRec: Supporting software developers by recommending third-party libraries
    Nguyen, Phuong T.
    Di Rocco, Juri
    Di Ruscio, Davide
    Di Penta, Massimiliano
    JOURNAL OF SYSTEMS AND SOFTWARE, 2020, 161 (161)
  • [46] Do Developers Update Third-Party Libraries in Mobile Apps?
    Salza, Pasquale
    Palomba, Fabio
    Di Nucci, Dario
    D'Uva, Cosmo
    De Lucia, Andrea
    Ferrucci, Filomena
    2018 IEEE/ACM 26TH INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION (ICPC 2018), 2018, : 255 - 265
  • [47] CanvasMirror: Secure Integration of Third-Party Libraries in a WebVR Environment
    Lee, Jiyeon
    2020 50TH ANNUAL IEEE-IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS-SUPPLEMENTAL VOLUME (DSN-S), 2020, : 75 - 76
  • [48] Armor Within: Defending against Vulnerabilities in Third-Party Libraries
    Ali, Sameed
    Anantharaman, Prashant
    Smith, Sean W.
    2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2020), 2020, : 291 - 299
  • [49] Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps
    Zhao, Kaifa
    Zhan, Xian
    Yu, Le
    Zhou, Shiyao
    Zhou, Hao
    Luo, Xiapu
    Wang, Haoyu
    Liu, Yepang
    Proceedings - International Conference on Software Engineering, 2023, : 1583 - 1595
  • [50] Leakage of Sensitive Information to Third-Party Voice Applications
    Bispham, Mary
    Zard, Clara
    Sattar, Suliman
    Ferrer-Aran, Xavier
    Suarez-Tangil, Guillermo
    Such, Jose
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON CONVERSATIONAL USER INTERFACES, CUI 2022, 2022,