Chaoshun Zuo

dblp:149/8302 · DBLP profile ↗
← Back
31ranked-venue papers
8as first author
17since 2021 · last 2026
0000-0003-3581-1500ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 26 · 7 first-author · 14 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSystems, architecture and hardware · 1Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic Verification
Xiangpu Song, Longjia Pei, Jianliang Wu 0002, Yingpei Zeng, Gaoshuo He, Chaoshun Zuo, Xiaofeng Liu 0013, Qingchuan Zhao, Shanqing Guo
NDSS6
2026 Your Copied Data is Under Monitoring: A Study of Clipboard Usage in Android Applications
abstract
Clipboard usage is prevalent in mobile applications nowadays. However, insufficient access control on the clipboard in mobile operating systems exposes its contained data to high risks where one application can read the data, store it locally, or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile application ecosystem. Therefore, this paper proposes an automated tool, ClipboardScope+, that leverages the principled static program analysis to uncover the clipboard data usage in mobile applications at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an application. ClipboardScope+ is evaluated on over1.2 millionmobile applications available on Google Play, spanning the years 2022 and 2023. It uncovered an increase of 5.9% in behaviors of storing and transferring clipboard data over the one-year time, most of which occur automatically in background services. We also conducted a comprehensive case study to characterize different clipboard usages and reveal their privacy issues. Moreover, we uncovered a prevalent programming habit of using theSharedPreferencesobject to store historical data, which can become an unnoticeable privacy leakage channel.
Jiayimei Wang, Ruoqin Tang, Chaoshun Zuo, Lei Xue 0001, Weitao Xu, Xiapu Luo, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.4
2026 Characterizing Contactless Side-Channel Eavesdropping on Wireless Chargers
abstract
Today, there are an increasing number of smartphones equipped with wireless charging capabilities that use electromagnetic induction to transfer power from a wireless charger to devices that are being charged. In this paper, we unveil a novelcontactlessandcontext-awareside-channel attack in wire less charging, which harnesses two physical phenomena,i.e., the coil whine and the magnetic field perturbations, emanating from the wireless charging process and further infers user interactions on the charging smartphone. To validate the feasibility of this new side channel, we design and implement a three-stage attack framework, dubbed WISERS+, that first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to builduser interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of our proposed attacks with different commercial-off-the-shelf (COTS) smartphones and wireless chargers. Our evaluation results suggest that WISERS+canachieve over 90.4% accuracy in inferring sensitive information, such as the unlocking passcode on the screen and the launch of mobile apps. In addition, our study also demonstrates that WISERS+ is resilient to several practical impact factors, and presents its potential to be extended to attack the fast charging mode. Finally, we propose effective countermeasures and mitigate threats from the WISERS+ attack.
Tao Ni 0003, Chaoshun Zuo, Jianfeng Li 0006, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.2
2025 A Thorough Security Analysis of BLE Proximity Tracking Protocols
Xiaofeng Liu 0013, Chaoshun Zuo, Qinsheng Hou, Jianliang Wu 0002, Qingchuan Zhao, Shanqing Guo
USENIX Security Symposium2
2025 AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality Apps
John Y. Kim, Chaoshun Zuo, Zhiqiang Lin 0001
USENIX Security Symposium2
2025 MBFuzzer: A Multi-Party Protocol Fuzzer for MQTT Brokers
Xiangpu Song, Jianliang Wu 0002, Yingpei Zeng, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo
USENIX Security Symposium5
2025 CSFuzzer: A grey-box fuzzer for network protocol using context-aware state feedback
Xiangpu Song, Yingpei Zeng, Jianliang Wu 0002, Hao Li 0092, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo
Comput. Secur.5
2024 Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android Apps
abstract
Recently, clipboard usage has become prevalent in mobile apps allowing users to copy and paste text within the same app or across different apps. However, insufficient access control on the clipboard in the mobile operating systems exposes its contained data to high risks where one app can read the data copied in other apps and store it locally or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile app ecosystem. To establish the missing links, this paper proposes an automated tool, ClipboardScope, that leverages the principled static program analysis to uncover the clipboard data usage in mobile apps at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an app. ClipboardScope is evaluated on 26,201 out of a total of 2.2 million mobile apps available on Google Play as of June 2022 that access and process the clipboard text. It identifies 23,948, 848, 1,075, and 330 apps that are recognized as the four designated categories, respectively. In addition, we uncovered a prevalent programming habit of using the SharedPreferences object to store historical data, which can become an unnoticeable privacy leakage channel.
Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang, Lei Xue 0001, Xiapu Luo, Qingchuan Zhao
ICSE3
2024 DEMISTIFY: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile Apps
abstract
Mobile apps have become popular for providing artificial intelligence (AI) services via on-device machine learning (ML) techniques. Unlike accomplishing these AI services on remote servers traditionally, these on-device techniques process sensitive information required by AI services locally, which can mitigate the severe concerns of the sensitive data collection on the remote side. However, these on-device techniques have to push the core of ML expertise (e.g., models) to smartphones locally, which are still subject to similar vulnerabilities on the remote clouds and servers, especially when facing the model stealing attack. To defend against these attacks, developers have taken various protective measures. Unfortunately, we have found that these protections are still insufficient, and on-device ML models in mobile apps could be extracted and reused without limitation. To better demonstrate its inadequate protection and the feasibility of this attack, this paper presents DeMistify, which statically locates ML models within an app, slices relevant execution components, and finally generates scripts automatically to instrument mobile apps to successfully steal and reuse target ML models freely. To evaluate DeMistify and demonstrate its applicability, we apply it on 1,511 top mobile apps using on-device ML expertise for several ML services based on their install numbers from Google Play and DeMistify can successfully execute 1250 of them (82.73%). In addition, an in-depth study is conducted to understand the on-device ML ecosystem in the mobile application.
Chaoshun Zuo, Xiaofeng Liu 0013, Wenrui Diao, Qingchuan Zhao, Shanqing Guo
ICSE2
2023 Uncovering Vulnerabilities of Bluetooth Low Energy IoT from Companion Mobile Apps with Ble-Guuide
abstract
Increasingly, with embedded intelligence and control, IoT devices are being adopted faster than ever. However, the IoT landscape and its security implications are not yet fully understood. This paper seeks to shed light on this by focusing on a particular type of IoT devices, namely the ones using Bluetooth Low Energy (BLE). Our contributions are two-fold: First, we present Ble-Guuide, a framework for performing mobile app-centric security issue identification. We exploit Universally Unique Identifiers (UUIDs), which underpin data transmissions in BLE, to glean rich information regarding device functionality and the underlying security issues. We combine this with information from app descriptions and BLE libraries, to identify the corresponding security vulnerabilities in BLE devices and determine the security or privacy impact they could have depending on the device functionality. Second, we present a large-scale analysis of 17,243 free, BLE-enabled Android APKs, systematically crawled from the official Google Play store. By applying Ble-Guuide to this dataset, we uncover that more than 70% of these APKs contain at least one security vulnerability. We also obtain insights into the identified security vulnerabilities and their impact.
Pallavi Sivakumaran, Chaoshun Zuo, Zhiqiang Lin 0001, Jorge Blasco Alís
AsiaCCS2
2023 Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot Learning
abstract
Recently, power banks for smartphones have begun to support wireless charging. Although these wireless charging power banks appear to be immune to most reported vulnerabilities in either power banks or wireless charging, we have found a new contactless wireless charging side channel in these power banks that leaks user privacy from their wireless charging smartphones without compromising either power banks or victim smartphones. We have proposed BankSnoop to demonstrate the practicality of the newly discovered wireless charging side channel in power banks. Specifically, it leverages the coil whine and magnetic field disturbance emitted by a power bank when wirelessly charging a smartphone and adopts the few-shot learning to recognize the app running on the smartphone and uncover keystrokes. We evaluate the effectiveness of BankSnoop using commodity wireless charging power banks and smartphones, and the results show it achieves over 90% accuracy on average in recognizing app launching and keystrokes. It also presents high adaptability when apply to different smartphone models, power banks, etc., achieving over 85% accuracy with 10-shot learning.
Tao Ni 0003, Jianfeng Li 0006, Xiaokuan Zhang, Chaoshun Zuo, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
MobiCom4
2023 Extracting Threat Intelligence From Cheat Binaries For Anti-Cheating
abstract
Rampant cheating remains a serious concern for game developers who fear losing loyal customers and revenue. While numerous anti-cheating techniques have been proposed, cheating persists in a vibrant (and profitable) illicit market. Inspired by novel insights into the economics behind cheat development and recent techniques for defending against advanced persistent threats (APTs), we propose a fully automated methodology for extracting “cheat intelligence” from widely distributed cheat binaries to produce a “memory access graph” that guides selective data randomization to yield immune game clients. We have implemented a prototype system for Android and Windows games, CheatFighter, and evaluated it on 86 cheats collected from a variety of real-world sources, including Telegram channels and online forums. CheatFighter successfully counteracts 80 of the real-world cheats in under a minute, demonstrating practical end-to-end protection against widespread cheating.
Md Sakib Anwar, Chaoshun Zuo, Carter Yagemann, Zhiqiang Lin 0001
RAID2
2023 Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side Channels
abstract
Today, there is an increasing number of smartphones supporting wireless charging that leverages electromagnetic induction to transmit power from a wireless charger to the charging smartphone. In this paper, we report a new contactless and context-aware wireless-charging side-channel attack, which captures two physical phenomena (i.e., the coil whine and the magnetic field perturbation) generated during this wireless charging process and further infers the user interactions on the charging smartphone. We design and implement a three-stage attack framework, dubbed WISERS, to demonstrate the practicality of this new side channel. WISERS first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to build user interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of WISERS with popular smartphones and commercial-off-the-shelf (COTS) wireless chargers. Our evaluation results suggest that WISERS can achieve over 90.4% accuracy in inferring sensitive information, such as screen-unlocking passcode and app launch. In addition, our study also shows that WISERS is resilient to a list of impact factors.
Tao Ni 0003, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li 0006, Zhenyu Yan 0002, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
SP3
2023 A Peek into the Metaverse: Detecting 3D Model Clones in Mobile Games
Chaoshun Zuo, Chao Wang 0113, Zhiqiang Lin 0001
USENIX Security Symposium1
2022 PeriScope: Comprehensive Vulnerability Analysis of Mobile App-defined Bluetooth Peripherals
abstract
Many IoT devices today talk to each other via Bluetooth Low Energy (BLE), a wireless communication technology often used to exchange data between a paired central and peripheral. These peripheral devices include not only firmware-defined bare-metal peripherals but also mobile application defined peripherals where a mobile app turns a smartphone into a peripheral instead of their usual central role. However, this role reversal increases the attack surface and brings vulnerabilities in bare-metal Bluetooth peripherals to mobile apps where relevant security and privacy have not been well studied. To fill this knowledge gap, this paper presents PeriScope, an automated tool to unveil the security and privacy vulnerabilities at the link layer of app-defined Bluetooth peripherals in the procedures of broadcasting, pairing, and communication by systematically analyzing their companion mobile apps. PeriScope has analyzed 1,160 Bluetooth peripheral apps from Google Play and identified 69.13% of them that broadcast device or personal identifiable information in cleartext, and, in addition, there are 95% pieces of data managed by these apps (e.g., personal health data and digital keys to unlock doors) to exchange with connected devices can be accessed without authentication. Finally, a set of guidelines for secure app-defined Bluetooth peripherals development is also provided.
Qingchuan Zhao, Chaoshun Zuo, Jorge Blasco Alís, Zhiqiang Lin 0001
AsiaCCS2
2022 Detecting and Measuring Misconfigured Manifests in Android Apps
abstract
The manifest file of an Android app is crucial for app security as it declares sensitive app configurations, such as access permissions required to access app components. Surprisingly, we noticed a number of widely-used apps (some with over 500 million downloads) containing misconfigurations in their manifest files that can result in severe security issues. This paper presents ManiScope, a tool to automatically detect misconfigurations of manifest files when given an Android APK. The key idea is to build a manifest XML Schema by extracting ManiScope constraints from the manifest documentation with novel domain-aware NLP techniques and rules, and validate manifest files against the schema to detect misconfigurations. We have implemented ManiScope, with which we have identified 609,428 (33.20%) misconfigured Android apps out of 1,853,862 apps from Google Play, and 246,658 (35.64%) misconfigured ones out of 692,106 pre-installed apps from 4,580 Samsung firmwares, respectively. Among them, 84,117 (13.80%) of misconfigured Google Play apps and 56,611 (22.95%) of misconfigured pre-installed apps have various security implications including app defrauding, message spoofing, secret data leakage, and component hijacking.
Yuqing Yang 0003, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson 0002, Angelos Stavrou, Zhiqiang Lin 0001
CCS3
2022 Playing Without Paying: Detecting Vulnerable Payment Verification in Native Binaries of Unity Mobile Games
Chaoshun Zuo, Zhiqiang Lin 0001
USENIX Security Symposium1
2020 Automatic Uncovering of Hidden Behaviors From Input Validation in Mobile Apps
abstract
Mobile applications (apps) have exploded in popularity, with billions of smartphone users using millions of apps available through markets such as the Google Play Store or the Apple App Store. While these apps have rich and useful functionality that is publicly exposed to end users, they also contain hidden behaviors that are not disclosed, such as backdoors and blacklists designed to block unwanted content. In this paper, we show that the input validation behavior-the way the mobile apps process and respond to data entered by users-can serve as a powerful tool for uncovering such hidden functionality. We therefore have developed a tool, InputScope, that automatically detects both the execution context of user input validation and also the content involved in the validation, to automatically expose the secrets of interest. We have tested InputScope with over 150,000 mobile apps, including popular apps from major app stores and preinstalled apps shipped with the phone, and found 12,706 mobile apps with backdoor secrets and 4,028 mobile apps containing blacklist secrets.
Qingchuan Zhao, Chaoshun Zuo, Brendan Dolan-Gavitt, Giancarlo Pellegrino, Zhiqiang Lin 0001
SP2
2020 FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware
Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin 0001
USENIX Security Symposium4
2020 An empirical study of potentially malicious third-party libraries in Android apps
abstract
The rapid development of Android apps primarily benefits from third-party libraries that provide well-encapsulated functionalities. On the other hand, more and more malicious libraries are discovered in the wild, which brings new security challenges. Despite some previous studies focusing on the malicious libraries, however, most of them only study specific types of libraries or individual cases. The security community still lacks a comprehensive understanding of potentially malicious libraries (PMLs) in the wild.
Wenrui Diao, Chengyu Hu 0001, Shanqing Guo, Chaoshun Zuo, Li Li 0044
WISEC5
2019 Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps
abstract
Being an easy-to-deploy and cost-effective low power wireless solution, Bluetooth Low Energy (BLE) has been widely used by Internet-of-Things (IoT) devices. In a typical IoT scenario, an IoT device first needs to be connected with its companion mobile app which serves as a gateway for its Internet access. To establish a connection, a device first broadcasts advertisement packets with UUIDs to nearby smartphone apps. Leveraging these UUIDs, a companion app is able to identify the device, pairs and bonds with it, and allows further data communication. However, we show that there is a fundamental flaw in the current design and implementation of the communication protocols between a BLE device and its companion mobile app, which allows an attacker to precisely fingerprint a BLE device with static UUIDs from the apps. Meanwhile, we also discover that many BLE IoT devices adopt "just works" pairing, allowing attackers to actively connect with these devices if there is no app-level authentication. Even worse, this vulnerability can also be directly uncovered from mobile apps. Furthermore, we also identify that there is an alarming number of vulnerable app-level authentication apps, which means the devices connected by these apps can be directly controlled by attackers. To raise the public awareness of IoT device fingerprinting and also uncover these vulnerable BLE IoT devices before attackers, we develop an automated mobile app analysis tool BLESCOPE and evaluate it with all of the free BLE IoT apps in Google Play store. Our tool has identified 1,757 vulnerable mobile apps in total. We also performed a field test in a 1.28 square miles region, and identified 5,822 real BLE devices, among them 5,509 (94.6%) are fingerprintable by attackers, and 431 (7.4%) are vulnerable to unauthorized access. We have made responsible disclosures to the corresponding app developers, and also reported the fingerprinting issues to the Bluetooth Special Interest Group.
Chaoshun Zuo, Haohuang Wen, Zhiqiang Lin 0001, Yinqian Zhang
CCS1
2019 Your IoTs Are (Not) Mine: On the Remote Binding Between IoT Devices and Users
abstract
Nowadays, IoT clouds are increasingly deployed to facilitate users to manage and control their IoT devices. Unlike the traditional cloud services with communication between a client and a server, IoT cloud architectures involve three parties: the IoT device, the user, and the cloud. Before a user can remotely access her IoT device, remote communication between them is bootstrapped through the cloud. However, the security implications of such a unique process in IoT are less understood today. In this paper, we report the first step towards systematic analyses of IoT remote binding. To better understand the problem, we describe the life cycle of remote binding with a state-machine model which helps us demystify the complexity in various designs and systematically explore the attack surfaces. With the evaluation of 10 real-world remote binding solutions, our study brings to light questionable practices in the designs of authentication and authorization, including inappropriate use of device IDs, weak device authentication, and weak cloud-side access control, as well as the impact of the discovered problems, which could cause sensitive user data leak, persistent denial-of-service, connection disruption, and even stealthy device control.
Jiongyi Chen, Chaoshun Zuo, Wenrui Diao, Shuaike Dong, Qingchuan Zhao, Menghan Sun, Zhiqiang Lin 0001, Yinqian Zhang, Kehuan Zhang
DSN2
2019 Geo-locating Drivers: A Study of Sensitive Data Leakage in Ride-Hailing Services
Qingchuan Zhao, Chaoshun Zuo, Giancarlo Pellegrino, Zhiqiang Lin 0001
NDSS2
2019 Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile Apps
abstract
Increasingly, more and more mobile applications (apps for short) are using the cloud as the back-end, in particular the cloud APIs, for data storage, data analytics, message notification, and monitoring. Unfortunately, we have recently witnessed massive data leaks from the cloud, ranging from personally identifiable information to corporate secrets. In this paper, we seek to understand why such significant leaks occur and design tools to automatically identify them. To our surprise, our study reveals that lack of authentication, misuse of various keys (e.g., normal user keys and superuser keys) in authentication, or misconfiguration of user permissions in authorization are the root causes. Then, we design a set of automated program analysis techniques including obfuscation-resilient cloud API identification and string value analysis, and implement them in a tool called LeakScope to identify the potential data leakage vulnerabilities from mobile apps based on how the cloud APIs are used. Our evaluation with over 1.6 million mobile apps from the Google Play Store has uncovered 15, 098 app servers managed by mainstream cloud providers such as Amazon, Google, and Microsoft that are subject to data leakage attacks. We have made responsible disclosure to each of the cloud service providers, and they have all confirmed the vulnerabilities we have identified and are actively working with the mobile app developers to patch their vulnerable services.
Chaoshun Zuo, Zhiqiang Lin 0001, Yinqian Zhang
IEEE Symposium on Security and Privacy1
2019 The Betrayal At Cloud City: An Empirical Analysis Of Cloud-Based Mobile Backends
Omar Alrawi, Chaoshun Zuo, Ruian Duan, Ranjita Pai Kasturi, Zhiqiang Lin 0001, Brendan Saltaformaggio
USENIX Security Symposium2
2018 IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin 0001, XiaoFeng Wang 0001, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang
NDSS4
2018 An automatically vetting mechanism for SSL error-handling vulnerability in android hybrid Web apps
Yang Liu 0165, Chaoshun Zuo, Zonghua Zhang, Shanqing Guo, Xin-Shun Xu
World Wide Web2
2017 AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online Services
abstract
When accessing online private resources (e.g., user profiles, photos, shopping carts) from a client (e.g., a desktop web-browser or a mobile app), the service providers must implement proper access control, which typically involves both authentication and authorization. However, not all of the service providers follow the best practice, resulting in various access control vulnerabilities. To understand such a threat in a large scale, and identify the vulnerable access control implementations in online services, this paper introduces AuthScope, a tool that is able to automatically execute a mobile app and pinpoint the vulnerable access control implementations, particularly the vulnerable authorizations, in the corresponding online service. The key idea is to use differential traffic analysis to recognize the protocol fields and then automatically substitute the fields and observe the server response. One of the key challenges for a large scale study lies in how to obtain the post-authentication request-and-response messages for a given app. We have thus developed a targeted dynamic activity explorer to perform an in-context analysis and drive the app execution to automatically log in the service. We have tested AuthScope with 4,838 popular mobile apps from Google Play, and identified 597 0-day vulnerable authorizations that map to 306 apps.
Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin 0001
CCS1
2017 SMARTGEN: Exposing Server URLs of Mobile Apps With Selective Symbolic Execution
abstract
Server URLs including domain names, resource path, and query parameters are important to many security applications such as hidden service identification, malicious website detection, and server vulnerability fuzzing. Unlike traditional desktop web apps in which server URLs are often directly visible, the server URLs of mobile apps are often hidden, only being exposed when the corresponding app code gets executed. Therefore, it is important to automatically analyze the mobile app code to expose the server URLs and enable the security applications with them. We have thus developed SMARTGEN to feature selective symbolic execution for the purpose of automatically generate server request messages to expose the server URLs by extracting and solving user input constraints in mobile apps. Our evaluation with 5,000 top-ranked mobile apps (each with over one million installs) in Google Play shows that with SMARTGEN we are able to reveal 297,780 URLs in total for these apps. We have then submitted all of these exposed URLs to a harmful URL detection service provided by VirusTotal, which further identified 8634 URLs being harmful. Among them, Phising belong to phishing sites, 3,722 malware sites and 3,228 malicious sites (there are 387 overlapped sites between malware and malicious sites).
Chaoshun Zuo, Zhiqiang Lin 0001
WWW1
2016 Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile Services
Chaoshun Zuo, Wubing Wang, Zhiqiang Lin 0001
NDSS1
2015 Automatically Detecting SSL Error-Handling Vulnerabilities in Hybrid Mobile Web Apps
abstract
Today, there are many hybrid apps in which both native Android app UI and WebView UI are used. To protect the security and privacy of the communications, these hybrid apps all use HTTPS by WebView, a key component in modern web browser. In this paper, we show there is another type of SSL vulnerability that stems from the error-handling code in the hybrid mobile web apps. At a high level, this error-handling code should have stopped the communication but it still proceeds regardless of certificate errors, thereby leading to the MITM attacks. To automatically identify these vulnerable apps, we present a hybrid approach that combines both static analysis and dynamic analysis. We have implemented our approach and evaluated with 13,820 real world mobile web apps from a third party market, of which 645 are confirmed truly vulnerable, with an average overhead of 60.8 seconds per app.
Chaoshun Zuo, Jianliang Wu 0002, Shanqing Guo
AsiaCCS1