The Seven Deadly Sins of the HTML5 WebAPI

Author:

Diamantaris Michalis1,Marcantoni Francesco2,Ioannidis Sotiris1,Polakis Jason2

Affiliation:

1. FORTH, Greece

2. University of Illinois at Chicago, USA

Abstract

Modern smartphone sensors can be leveraged for providing novel functionality and greatly improving the user experience. However, sensor data can be misused by privacy-invasive or malicious entities. Additionally, a wide range of other attacks that use mobile sensor data have been demonstrated; while those attacks have typically relied on users installing malicious apps, browsers have eliminated that constraint with the deployment of HTML5 WebAPI. In this article, we conduct a comprehensive evaluation of the multifaceted threat that mobile web browsing poses to users by conducting a large-scale study of mobile-specific HTML5 WebAPI calls across more than 183K of the most popular websites. We build a novel testing infrastructure consisting of actual smartphones on top of a dynamic Android app analysis framework, allowing us to conduct an end-to-end exploration. In detail, our system intercepts and tracks data access in real time, from the WebAPI JavaScript calls down to the Android system calls. Our study reveals the extent to which websites are actively leveraging the WebAPI for collecting sensor data, with 2.89% of websites accessing at least one sensor. To provide a comprehensive assessment of the risks of this emerging practice, we create a taxonomy of sensor-based attacks from prior studies and present an in-depth analysis by framing our collected data within that taxonomy. We find that 1.63% of websites can carry out at least one attack and emphasize the need for a standardized policy across all browsers and the ability for users to control what sensor data each website can access.

Funder

Horizon 2020

CONCORDIA

THREAT-ARREST

DARPA ASED Program and AFRL

NSF

Publisher

Association for Computing Machinery (ACM)

Subject

Safety, Risk, Reliability and Quality,General Computer Science

Reference133 articles.

1. Alexa—Top 50 Banks and Institutions. 2019. Retrieved from https://www.alexa.com/topsites/category/Business/Financial_Services/Banking_Services/Banks_and_Institutions. Alexa—Top 50 Banks and Institutions. 2019. Retrieved from https://www.alexa.com/topsites/category/Business/Financial_Services/Banking_Services/Banks_and_Institutions.

2. Erik Derr. 2016. Axplorer—Demystifying the Android Application Framework. Retrieved from http://axplorer.org/. Erik Derr. 2016. Axplorer—Demystifying the Android Application Framework. Retrieved from http://axplorer.org/.

3. The EU General Data Protection Regulation. 2019. Retrieved from https://eugdpr.org. The EU General Data Protection Regulation. 2019. Retrieved from https://eugdpr.org.

4. Mozilla. 2019. MDN Web Docs—Magnetometer. Retrieved from https://developer.mozilla.org/en-US/docs/Web/API/Magnetometer/Magnetometer. Mozilla. 2019. MDN Web Docs—Magnetometer. Retrieved from https://developer.mozilla.org/en-US/docs/Web/API/Magnetometer/Magnetometer.

5. Mozilla. 2019. Mozilla Support—Does Firefox share my location with websites? Retrieved from https://support.mozilla.org/en-US/kb/does-firefox-share-my-location-websites. Mozilla. 2019. Mozilla Support—Does Firefox share my location with websites? Retrieved from https://support.mozilla.org/en-US/kb/does-firefox-share-my-location-websites.

Cited by 12 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. LuxTrack: Activity Inference Attacks via Smartphone Ambient Light Sensors and Countermeasures;IEEE Internet of Things Journal;2024-09-01

2. Privacy Preserving Release of Mobile Sensor Data;Proceedings of the 19th International Conference on Availability, Reliability and Security;2024-07-30

3. Are We Aware? An Empirical Study on the Privacy and Security Awareness of Smartphone Sensors;Studies in Computational Intelligence;2024

4. Are We Aware? An Empirical Study on the Privacy and Security Awareness of Smartphone Sensors;2023 IEEE/ACIS 21st International Conference on Software Engineering Research, Management and Applications (SERA);2023-05-23

5. Who Funds Misinformation? A Systematic Analysis of the Ad-related Profit Routines of Fake News Sites;Proceedings of the ACM Web Conference 2023;2023-04-30

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3