首页> 外文期刊>ACM transactions on privacy and security >The Seven Deadly Sins of the HTML5 WebAPI: A Large-scale Study on the Risks of Mobile Sensor-based Attacks
【24h】

The Seven Deadly Sins of the HTML5 WebAPI: A Large-scale Study on the Risks of Mobile Sensor-based Attacks

机译:HTML5 WebAPI的七个致命罪:对移动传感器攻击风险的大规模研究

获取原文
获取原文并翻译 | 示例
           

摘要

Modern smartphone sensors can be leveraged for providing novel functionality and greatly improving the user experience. However, sensor data can be misused by privacy-invasive or malicious entities. Additionally, a wide range of other attacks that use mobile sensor data have been demonstrated; while those attacks have typically relied on users installing malicious apps, browsers have eliminated that constraint with the deployment of HTML5 WebAPI.In this article, we conduct a comprehensive evaluation of the multifaceted threat that mobile web browsing poses to users by conducting a large-scale study of mobile-specific HTML5 WebAPI calls across more than 183K of the most popular websites. We build a novel testing infrastructure consisting of actual smartphones on top of a dynamic Android app analysis framework, allowing us to conduct an end-to-end exploration. In detail, our system intercepts and tracks data access in real time, from the WebAPI JavaScript calls down to the Android system calls. Our study reveals the extent to which websites are actively leveraging the WebAPI for collecting sensor data, with 2.89% of websites accessing at least one sensor. To provide a comprehensive assessment of the risks of this emerging practice, we create a taxonomy of sensor-based attacks from prior studies and present an in-depth analysis by framing our collected data within that taxonomy. We find that 1.63% of websites can carry out at least one attack and emphasize the need for a standardized policy across all browsers and the ability for users to control what sensor data each website can access.
机译:可以利用现代智能手机传感器,以提供新颖的功能和大大提高用户体验。但是,传感器数据可以被隐私或恶意实体滥用。此外,已经证明了使用移动传感器数据的各种其他攻击;虽然这些攻击通常依赖于用户安装恶意应用程序的用户,但浏览器已消除与部署HTML5 WebAPI的约束。在本文中,我们对移动网络浏览通过进行大规模对用户构成的多方面威胁进行了全面的评估在超过183万个最受欢迎的网站上呼叫移动特定的HTML5互联网呼叫。我们构建了一个新颖的测试基础设施,由实际的智能手机组成,在动态的Android应用程序分析框架之上,允许我们进行端到端的探索。详细地,我们的系统实时拦截并跟踪数据访问,从WebAPI JavaScript调用到Android系统调用。我们的研究揭示了网站积极利用WebAPI来收集传感器数据的程度,其中2.89%的网站访问至少一个传感器。为了对这种新兴实践的风险进行全面评估,我们通过先前研究创建了基于传感器的攻击分类,并通过框架我们在该分类中的收集数据来提出深入的分析。我们发现1.63%的网站可以至少开展一次攻击,并强调对所有浏览器的标准化政策的需求以及用户控制每个网站可以访问的传感器数据的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号