Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification Systems

被引:2
|
作者
Lou, Jiadong [1 ]
Zhang, Xiaohan [2 ]
Zhang, Yihe [1 ]
Li, Xinghua [2 ]
Yuan, Xu [1 ]
Zhang, Ning [3 ]
机构
[1] Univ Louisiana Lafayette, Lafayette, LA 70506 USA
[2] Xidian Univ, Xian, Peoples R China
[3] Washington Univ St Louis, St Louis, MO USA
关键词
mobile notification; vulnerability analysis; privacy exposure; CHOSEN-PREFIX COLLISIONS; MD5;
D O I
10.1109/DSN58367.2023.00017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Witnessing the blooming adoption of push notifications on mobile devices, this new message delivery paradigm has become pervasive in diverse applications. Accompanying with its broad adoption, the potential security risks and privacy exposure issues raise public concerns regarding its great social impacts. This paper conducts the first attempt to exploit the mobile notification ecosystem. By dissecting its structural elements and implementation process, a comprehensive vulnerability analysis is conducted towards the complete flow of mobile notification from platform enrollment to messaging. Meanwhile, for privacy exposure, we first examine the implementation of privacy policy compliance by proposing a three-level inspection approach to guide our analysis. Then, our top-down methods from documentation analysis, application network traffic study, to static analysis expose the illicit data collection behaviors in released applications. In addition, we uncover the potential privacy inference resulted from the notification monitoring. To support our analysis, we conduct empirical studies on 12 most popular notification platforms and perform static analysis over 30,000+ applications. We discover: 1) six platforms either provide ambiguous KEY naming rules or offer vulnerable messaging APIs; 2) privacy policy compliance implementations are either stagnated at the documentation stages (8 of 12 platforms) or never implemented in apps, resulting in billions of users suffering from privacy exposure; and 3) some apps can stealthily monitor notification messages delivering to other apps, potentially incurring user privacy inference risks. Our study raises the urgent demand for better regulations of mobile notification deployment.
引用
收藏
页码:28 / 41
页数:14
相关论文
共 24 条
  • [1] The Privacy Calculus: Mobile Apps and User Perceptions of Privacy and Security
    Fife, Elizabeth
    Orjuela, Juan
    INTERNATIONAL JOURNAL OF ENGINEERING BUSINESS MANAGEMENT, 2012, 4
  • [2] Empowering mobile crowdsourcing apps with user privacy control
    Meftah, Lakhdar
    Rouvoy, Romain
    Chrisment, Isabelle
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 147 : 1 - 15
  • [3] A Study of User Privacy in Android Mobile AR Apps
    Yang, Xiaoyi
    Zhang, Xueling
    PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [4] MOBILE APPS - USER AWARENESS ON PERMISSIONS, INFORMATION PRIVACY AND SECURITY
    Tutunea, Mihaela Filofteia
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON INFORMATICS IN ECONOMY (IE 2017): EDUCATION, RESEARCH & BUSINESS TECHNOLOGIES, 2017, : 70 - 77
  • [5] Data Sharing in Mobile Apps - User Privacy Expectations in Europe
    Quermann, Nils
    Degeling, Martin
    2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, : 107 - 119
  • [6] MOBILE APPS IN RETAIL: EFFECT OF PUSH NOTIFICATION FREQUENCY ON APP USER BEHAVIOR
    Wohllebe, Atilla
    Hubner, Dirk-Siegfried
    Radtke, Uwe
    Podruzsik, Szilard
    INNOVATIVE MARKETING, 2021, 17 (02) : 102 - 111
  • [7] FOUGERE: User-Centric Location Privacy in Mobile Crowdsourcing Apps
    Meftah, Lakhdar
    Rouvoy, Romain
    Chrisment, Isabelle
    DISTRIBUTED APPLICATIONS AND INTEROPERABLE SYSTEMS, DAIS 2019, 2019, 11534 : 116 - 132
  • [8] Privacy-preserving Comparison of Cloud Exposure Induced by Mobile Apps
    Henze, Martin
    Inaba, Ritsuma
    Fink, Ina Berenice
    Ziegeldorf, Jan Henrik
    PROCEEDINGS OF THE 14TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS 2017), 2017, : 543 - 544
  • [9] Mobile apps and data privacy: when the service is free, the product is your data
    Polykalas, Spyros E.
    Prezerakos, George N.
    Chrysidou, Froso D.
    Pylarinou, Eleni D.
    2017 8TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS & APPLICATIONS (IISA), 2017, : 444 - 448
  • [10] USER PREFERENCES FOR PRIVACY PROTECTION METHODS IN MOBILE HEALTH APPS: A MIXEDMETHODS STUDY
    Zhou, Leming
    Parmanto, Bambang
    INTERNATIONAL JOURNAL OF TELEREHABILITATION, 2020, 12 (02): : 13 - 26