arrow
Return

Android Data-Clone Attack via Operating System Customization

delete2020-01-01
delete0
delete
OA
AI
W
Wenna Song
J
Jiang Ming
H
Han Yan
Y
Yi Xiang
陈垣 (Yuan Chen)
Y
Yuan Luo
K
Kun He
G
Guojun Peng *
DOI:10.1109/ACCESS.2020.3035089delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
To avoid the inconvenience of retyping a user's ID and password, most mobile apps now provide the automatic login feature for a better user experience. To this end, auto-login credential is stored locally on the smartphone. However, such sensitive credential can be stolen by attackers and placed into their smartphones via the well-known credential-clone attack. Then, attackers can imperceptibly log into the victim's account, which causes more devastating and covert losses than merely intercepting the user's password. In this article, we propose a generalized Android credential-clone attack, called data-clone attack. By exploiting the new-found vulnerabilities of original equipment manufacturer (OEM)-made phone clone apps, we design an identity theft method that overcomes the problem of incomplete credential extraction and eliminates the requirement of root authority. To evade the consistency check of device-specific attributes in apps, we design two environment customization methods for app-level and operating system (OS)-level, respectively. Especially, we develop a transparent Android OS customization solution, named CloneDroid, which simulates 101 special attributes of Android OS. We implement a prototype of CloneDroid and the experimental results show that 172 out of 175 most-downloaded apps' accounts can be jeopardized, such as Facebook and WeChat. Moreover, our study has identified 18 confirmed zero-day vulnerabilities. Our findings paint a cautionary tale for the security community that billions of accounts are potentially exposed to Android OS customization-assisted data-clone attacks.
Keywords:
Automatic login
data-clone attack
identity theft
OS customization
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.7W
Citations:
29.4W

Organization

U
university of texas system
Scholars:
18.5W
Papers: 15.6W
Citations: 210
W
wuhan university
Scholars:
8.0W
Papers: 5.8W
Citations: 70