ADLIB: Analyzer for Mobile Ad Platform Libraries

被引:6
|
作者
Lee, Sangho [1 ]
Ryu, Sukyoung [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
基金
新加坡国家研究基金会;
关键词
Advertising Libraries; Malicious Advertisements; Advertisement Attacks; Android Hybrid Apps;
D O I
10.1145/3293882.3330562
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile advertising has become a popular advertising approach by taking advantage of various information from mobile devices and rich interaction with users. Mobile advertising platforms show advertisements of nearby restaurants to users using the geographic locations of their mobile devices, and also allow users to make reservations easily using their phone numbers. However, at the same time, they may open the doors for advertisements to steal device information or to perform malicious behaviors. When application developers integrate mobile advertising platform SDKs (AdSDKs) to their applications, they are informed of only the permissions required by the AdSDKs, and they may not be aware of the rich functionalities of the SDKs that are available to advertisements. In this paper, we first report that various AdSDKs provide powerful functionalities to advertisements, which are seriously vulnerable to security threats. We present representative malicious behaviors by advertisements using APIs provided by AdSDKs. To mitigate the security vulnerability, we develop a static analyzer, ADLIB, which analyzes Android Java libraries that use hybrid features to enable communication with JavaScript code and detects possible flows from the APIs that are accessible from third-party advertisements to device-specific features like geographic locations. Our evaluation shows that ADLIB found genuine security vulnerabilities from real-world AdSDKs.
引用
收藏
页码:262 / 272
页数:11
相关论文
共 50 条
  • [31] Mobile Academic Libraries A Snapshot
    Jackson, Rebecca
    [J]. REFERENCE & USER SERVICES QUARTERLY, 2013, 52 (03) : 174 - 178
  • [32] Mobile Libraries Opening Costs
    Little, Minnie J.
    [J]. LIBRARY JOURNAL, 1953, 78 (03) : 179 - 184
  • [33] Using Ad-Related Network Behavior to Distinguish Ad Libraries
    Su, Ming-Yang
    Wei, Hong-Siou
    Chen, Xin-Yu
    Lin, Po-Wei
    Qiu, Ding-You
    [J]. APPLIED SCIENCES-BASEL, 2018, 8 (10):
  • [34] Robomote: A tiny mobile robot platform for large-scale ad-hoc sensor networks
    Sibley, GT
    Rahimi, MH
    Sukhatme, GS
    [J]. 2002 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION, VOLS I-IV, PROCEEDINGS, 2002, : 1143 - 1148
  • [35] M-Libraries 3: Transforming Libraries with Mobile Technology
    Isfandyari-Moghaddam, Alireza
    [J]. ELECTRONIC LIBRARY, 2012, 30 (06): : 871 - 872
  • [36] M-Libraries 3 Transforming Libraries with Mobile Technology
    Mullen, Philip
    [J]. LIBRARY MANAGEMENT, 2012, 33 (8-9)
  • [37] M-libraries 3: Transforming Libraries with Mobile Technology
    McNicol, Sarah
    [J]. NEW LIBRARY WORLD, 2012, 113 (9-10) : 499 - +
  • [38] M-libraries 3: Transforming Libraries with Mobile Technology
    du Preez, Madely
    [J]. ONLINE INFORMATION REVIEW, 2012, 36 (05) : 770 - 771
  • [39] Adaptive OpenCL Libraries for Platform Portability
    Fox, Paul A.
    Batten, Allyssa L.
    Hayes, Marcus
    Kelmelis, Eric J.
    [J]. MODELING AND SIMULATION FOR DEFENSE SYSTEMS AND APPLICATIONS X, 2015, 9478
  • [40] Mobile ad hoe services: Semantic service discovery in mobile ad hoc networks
    Nedos, Andronikos
    Singh, Kulpreet
    Clarke, Siobhan
    [J]. SERVICE ORIENTED COMPUTING - ICSOC 2006, PROCEEDINGS, 2006, 4294 : 90 - +