Preventing and Detecting State Inference Attacks on Android

Andrea Possemato, Dario Nisi, Yanick Fratantonio · 2021

between these states.Attacks aiming at determining the state of another app are called state inference attacks, which are particularly relevant in the context of phishing attacks.Phishing attacks consist of luring an unsuspecting user into revealing her sensitive information (e.g., credentials) to a malicious app that mimics the UI of the legitimate one, a technique we refer to as UI Spoofing.The peculiar problem of mobile platforms is that the user cannot understand whether she is inserting her credentials into a legitimate app or into a malicious app spoofing its UI.State inference attacks play a key role in this context since, if the malicious app can infer, for example, that the user is about to use a specific app, it can show the spoofed UI at the right time, and hijack the legitimate app's flow.In the context of Android security, malicious apps are able to leak this state-related information by exploiting vulnerable APIs or resources (e.g., /proc file system).For example, a vulnerable API, when invoked with specific arguments, may return data that can be used to infer whether another app was just started.These attacks have been known for several years, and previous works have shown that several APIs and resources do leak sensitive information [6], [4].Given the security implications of these vulnerabilities, Google has restricted access to the /proc file-system (eradicating potential bugs at its root) and fixed all APIs known to be vulnerable [18].However, as for many forms of bugs, this is an arms race and there can potentially be many more vulnerable APIs still undisclosed.

Read the paper · More papers on PaperTik