Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification Systems

被引:1
|
作者
Lou, Jiadong [1 ]
Zhang, Xiaohan [2 ]
Zhang, Yihe [1 ]
Li, Xinghua [2 ]
Yuan, Xu [1 ]
Zhang, Ning [3 ]
机构
[1] Univ Louisiana Lafayette, Lafayette, LA 70506 USA
[2] Xidian Univ, Xian, Peoples R China
[3] Washington Univ St Louis, St Louis, MO USA
关键词
mobile notification; vulnerability analysis; privacy exposure; CHOSEN-PREFIX COLLISIONS; MD5;
D O I
10.1109/DSN58367.2023.00017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Witnessing the blooming adoption of push notifications on mobile devices, this new message delivery paradigm has become pervasive in diverse applications. Accompanying with its broad adoption, the potential security risks and privacy exposure issues raise public concerns regarding its great social impacts. This paper conducts the first attempt to exploit the mobile notification ecosystem. By dissecting its structural elements and implementation process, a comprehensive vulnerability analysis is conducted towards the complete flow of mobile notification from platform enrollment to messaging. Meanwhile, for privacy exposure, we first examine the implementation of privacy policy compliance by proposing a three-level inspection approach to guide our analysis. Then, our top-down methods from documentation analysis, application network traffic study, to static analysis expose the illicit data collection behaviors in released applications. In addition, we uncover the potential privacy inference resulted from the notification monitoring. To support our analysis, we conduct empirical studies on 12 most popular notification platforms and perform static analysis over 30,000+ applications. We discover: 1) six platforms either provide ambiguous KEY naming rules or offer vulnerable messaging APIs; 2) privacy policy compliance implementations are either stagnated at the documentation stages (8 of 12 platforms) or never implemented in apps, resulting in billions of users suffering from privacy exposure; and 3) some apps can stealthily monitor notification messages delivering to other apps, potentially incurring user privacy inference risks. Our study raises the urgent demand for better regulations of mobile notification deployment.
引用
收藏
页码:28 / 41
页数:14
相关论文
共 24 条
  • [1] The Privacy Calculus: Mobile Apps and User Perceptions of Privacy and Security
    Fife, Elizabeth
    Orjuela, Juan
    [J]. INTERNATIONAL JOURNAL OF ENGINEERING BUSINESS MANAGEMENT, 2012, 4
  • [2] A Study of User Privacy in Android Mobile AR Apps
    Yang, Xiaoyi
    Zhang, Xueling
    [J]. PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [3] Empowering mobile crowdsourcing apps with user privacy control
    Meftah, Lakhdar
    Rouvoy, Romain
    Chrisment, Isabelle
    [J]. JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 147 : 1 - 15
  • [4] MOBILE APPS - USER AWARENESS ON PERMISSIONS, INFORMATION PRIVACY AND SECURITY
    Tutunea, Mihaela Filofteia
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON INFORMATICS IN ECONOMY (IE 2017): EDUCATION, RESEARCH & BUSINESS TECHNOLOGIES, 2017, : 70 - 77
  • [5] Data Sharing in Mobile Apps - User Privacy Expectations in Europe
    Quermann, Nils
    Degeling, Martin
    [J]. 2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, : 107 - 119
  • [6] MOBILE APPS IN RETAIL: EFFECT OF PUSH NOTIFICATION FREQUENCY ON APP USER BEHAVIOR
    Wohllebe, Atilla
    Hubner, Dirk-Siegfried
    Radtke, Uwe
    Podruzsik, Szilard
    [J]. INNOVATIVE MARKETING, 2021, 17 (02) : 102 - 111
  • [7] FOUGERE: User-Centric Location Privacy in Mobile Crowdsourcing Apps
    Meftah, Lakhdar
    Rouvoy, Romain
    Chrisment, Isabelle
    [J]. DISTRIBUTED APPLICATIONS AND INTEROPERABLE SYSTEMS, DAIS 2019, 2019, 11534 : 116 - 132
  • [8] Privacy-preserving Comparison of Cloud Exposure Induced by Mobile Apps
    Henze, Martin
    Inaba, Ritsuma
    Fink, Ina Berenice
    Ziegeldorf, Jan Henrik
    [J]. PROCEEDINGS OF THE 14TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS 2017), 2017, : 543 - 544
  • [9] Mobile apps and data privacy: when the service is free, the product is your data
    Polykalas, Spyros E.
    Prezerakos, George N.
    Chrysidou, Froso D.
    Pylarinou, Eleni D.
    [J]. 2017 8TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS & APPLICATIONS (IISA), 2017, : 444 - 448
  • [10] A Privacy-Preserving User Authentication Mechanism for Smart City Mobile Apps
    Papaioannou, Maria
    Ribeiro, Jose C.
    Monteiro, Valdemar
    Sucasas, Victor
    Mantas, Georgios
    Rodriguez, Jonathan
    [J]. 2021 IEEE 26TH INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (CAMAD), 2021,