首页> 外文会议>European symposium on research in computer security >Mind-Reading: Privacy Attacks Exploiting Cross-App KeyEvent Injections
【24h】

Mind-Reading: Privacy Attacks Exploiting Cross-App KeyEvent Injections

机译:读心术:利用跨应用程序KeyEvent注入进行隐私攻击

获取原文

摘要

Input Method Editor (IME) has been widely installed on mobile devices to help user type non-Latin characters and reduce the number of key presses. To improve the user experience, popular IMEs integrate personalized features like reordering suggestion list of words based on user's input history, which inevitably turn them into the vaults of user's secret. In this paper, we make the first attempt to evaluate the security implications of IME personalization and the back-end infrastructure on Android devices. In the end, we identify a critical vulnerability lying under the Android KeyEvent processing framework, which can be exploited to launch cross-app KeyEvent injection (CAKI) attack and bypass the app-isolation mechanism. By abusing such design flaw, an adversary is able to harvest entries from the personalized user dictionary of IME through an ostensibly innocuous app only asking for common permissions. Our evaluation over a broad spectrum of Android OSes, devices, and IMEs suggests such issue should be fixed immediately. All Android versions and most IME apps are vulnerable and private information, like contact names, location, etc., can be easily exfiltrated. Up to hundreds of millions of mobile users are under this threat. To mitigate this security issue, we propose a practical defense mechanism which augments the existing KeyEvent processing framework without forcing any change to IME apps.
机译:输入法编辑器(IME)已广泛安装在移动设备上,以帮助用户键入非拉丁字符并减少按键次数。为了改善用户体验,流行的IME集成了个性化功能,例如根据用户的输入历史记录对单词的建议列表进行重新排序,这不可避免地将它们变成了用户秘密的保险库。在本文中,我们首次尝试评估IME个性化和Android设备上的后端基础结构的安全性。最后,我们确定了Android KeyEvent处理框架下的一个关键漏洞,可以利用该漏洞发起跨应用程序KeyEvent注入(CAKI)攻击并绕过应用程序隔离机制。通过滥用这种设计缺陷,攻击者可以通过表面上无害的应用程序(仅要求通用权限)从IME的个性化用户词典中收集条目。我们对各种Android操作系统,设备和IME的评估表明,应立即解决此问题。所有Android版本和大多数IME应用程序都容易受到攻击,并且很容易泄露联系人信息,位置等私人信息。多达数亿的移动用户正受到这种威胁。为了缓解此安全问题,我们提出了一种实用的防御机制,该机制可以在不强制对IME应用进行任何更改的情况下增强现有的KeyEvent处理框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号