【24h】

Event-Based Remote Attacks in HTML5-Based Mobile Apps

机译:基于HTML5的移动应用程序中基于事件的远程攻击

获取原文

摘要

HTML5-based mobile apps become increasingly popular as they leverage standard web technologies such as HTML5, JavaScript, CSS for saving development cost. Like web apps, they are built using JavaScript frameworks (e.g. jQuery) for making mobile websites responsive, faster, etc. Attackers may fire the events integrated into the frameworks for reusing sensitive APIs included in apps. Once the internal functions are accessed successfully, it may cause serious consequences (e.g. resource access). Its main advantage is that it is not required to inject malicious payloads for accessing to the system resources into apps. We define this vector of attacks as event-based remote attacks. In this paper, we present a systematic study about the event-based remote attacks. In addition, we introduce a static detection approach to detect vulnerable apps that can be exploited to launch such remote attacks. For the measurement, we performed the approach on a dataset of 2,536 HTML5-based mobile apps. It eventually flagged out 53 vulnerable apps, including 45 true positives.
机译:基于HTML5的移动应用程序利用标准Web技术(例如HTML5,JavaScript,CSS)来节省开发成本,因此变得越来越流行。与网络应用程序一样,它们是使用JavaScript框架(例如jQuery)构建的,用于使移动网站具有响应能力,更快的响应速度等。攻击者可能会触发集成到框架中的事件,以重用应用程序中包含的敏感API。成功访问内部功能后,可能会导致严重的后果(例如资源访问)。它的主要优点是不需要为访问系统资源而向应用程序中注入恶意负载。我们将这种攻击媒介定义为基于事件的远程攻击。在本文中,我们对基于事件的远程攻击进行了系统的研究。此外,我们引入了一种静态检测方法,以检测可被利用来发起此类远程攻击的易受攻击的应用程序。为了进行测量,我们在基于2,536个基于HTML5的移动应用程序的数据集上执行了该方法。最终,它发现了53个易受攻击的应用程序,其中包括45个肯定的漏洞。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号