ADLIB: Analyzer for Mobile Ad Platform Libraries

被引:6
|
作者
Lee, Sangho [1 ]
Ryu, Sukyoung [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
基金
新加坡国家研究基金会;
关键词
Advertising Libraries; Malicious Advertisements; Advertisement Attacks; Android Hybrid Apps;
D O I
10.1145/3293882.3330562
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile advertising has become a popular advertising approach by taking advantage of various information from mobile devices and rich interaction with users. Mobile advertising platforms show advertisements of nearby restaurants to users using the geographic locations of their mobile devices, and also allow users to make reservations easily using their phone numbers. However, at the same time, they may open the doors for advertisements to steal device information or to perform malicious behaviors. When application developers integrate mobile advertising platform SDKs (AdSDKs) to their applications, they are informed of only the permissions required by the AdSDKs, and they may not be aware of the rich functionalities of the SDKs that are available to advertisements. In this paper, we first report that various AdSDKs provide powerful functionalities to advertisements, which are seriously vulnerable to security threats. We present representative malicious behaviors by advertisements using APIs provided by AdSDKs. To mitigate the security vulnerability, we develop a static analyzer, ADLIB, which analyzes Android Java libraries that use hybrid features to enable communication with JavaScript code and detects possible flows from the APIs that are accessible from third-party advertisements to device-specific features like geographic locations. Our evaluation shows that ADLIB found genuine security vulnerabilities from real-world AdSDKs.
引用
收藏
页码:262 / 272
页数:11
相关论文
共 50 条
  • [1] Mobile phone platform as portable chemical analyzer
    Garcia, Antonio
    Erenas, M. M.
    Marinetto, Eugenio D.
    Abad, Carlos A.
    de Orbe-Paya, Ignacio
    Palma, Alberto J.
    Capitan-Vallvey, Luis F.
    [J]. SENSORS AND ACTUATORS B-CHEMICAL, 2011, 156 (01): : 350 - 359
  • [2] Impact of Ad Libraries on Ratings of Android Mobile Apps
    Ruiz, Israel J. Mojica
    Nagappan, Meiyappan
    Adams, Bram
    Berger, Thorsten
    Dienst, Steffen
    Hassan, Ahmed E.
    [J]. IEEE SOFTWARE, 2014, 31 (06) : 86 - 92
  • [3] A model of mobile app and ad platform markets
    Zennyo, Yusuke
    [J]. International Journal of Industrial Organization, 2024, 97
  • [4] Using cross platform development libraries. Telerik Mobile
    Ionescu, Valeriu Manuel
    [J]. 2016 15TH ROEDUNET CONFERENCE - NETWORKING IN EDUCATION AND RESEARCH, 2016,
  • [5] Pervaho: A development & test platform for mobile ad hoc applications*
    Eugster, Patrick
    Garbinato, Benoit
    Holzer, Adrian
    [J]. 2006 3RD ANNUAL INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS - WORKSHOPS, 2006, : 74 - +
  • [6] Towards a Mobile Ad-hoc Cloud Management Platform
    Khalifa, Ahmed
    Azab, Mohamed
    Eltoweissy, Mohamed
    [J]. 2014 IEEE/ACM 7TH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC), 2014, : 427 - 434
  • [7] Pervaho: A development & test platform for mobile ad hoc applications
    Eugster, Patrick
    Garbinato, Benoit
    Holzer, Adrian
    [J]. 2006 THIRD ANNUAL INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: NETWORKING & SERVICES, 2006, : 23 - +
  • [8] Transhumance:: A platform on a Mobile Ad hoc NETwork challenging collaborative gaming
    Demeure, Isabelle
    Gentes, Annie
    Stuyck, Julien
    Guyot-Mbodji, Aude
    Martin, Ludovic
    [J]. PROCEEDINGS OF THE 2008 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS: CTS 2008, 2008, : 221 - 228
  • [9] MobASim: a Software Platform for Mobile Ad Hoc Networks Modeling and Simulation
    Sikora, Andrzej
    Niewiadomska-Szynkiewicz, Ewa
    [J]. 2008 4TH IEEE INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2008, : 625 - 630
  • [10] A Mobile Agent Platform for Supporting Ad-hoc Network Environment
    Park, Jinbae
    Youn, Hyunsang
    Lee, Eunseok
    [J]. INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2008, 1 (01): : 9 - 16