Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification Systems

  • Jiadong Lou
  • , Xiaohan Zhang
  • , Yihe Zhang
  • , Xinghua Li
  • , Xu Yuan
  • , Ning Zhang

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Witnessing the blooming adoption of push notifications on mobile devices, this new message delivery paradigm has become pervasive in diverse applications. Accompanying with its broad adoption, the potential security risks and privacy exposure issues raise public concerns regarding its great social impacts. This paper conducts the first attempt to exploit the mobile notification ecosystem. By dissecting its structural elements and implementation process, a comprehensive vulnerability analysis is conducted towards the complete flow of mobile notification from platform enrollment to messaging. Meanwhile, for privacy exposure, we first examine the implementation of privacy policy compliance by proposing a three-level inspection approach to guide our analysis. Then, our top-down methods from documentation analysis, application network traffic study, to static analysis expose the illicit data collection behaviors in released applications. In addition, we uncover the potential privacy inference resulted from the notification monitoring. To support our analysis, we conduct empirical studies on 12 most popular notification platforms and perform static analysis over 30,000+ applications. We discover: 1) six platforms either provide ambiguous KEY naming rules or offer vulnerable messaging APIs; 2) privacy policy compliance implementations are either stagnated at the documentation stages (8 of 12 platforms) or never implemented in apps, resulting in billions of users suffering from privacy exposure; and 3) some apps can stealthily monitor notification messages delivering to other apps, potentially incurring user privacy inference risks. Our study raises the urgent demand for better regulations of mobile notification deployment.

Original languageEnglish
Title of host publicationProceedings - 2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages28-41
Number of pages14
ISBN (Electronic)9798350347937
DOIs
StatePublished - 2023
Event53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2023 - Porto, Portugal
Duration: Jun 27 2023Jun 30 2023

Publication series

NameProceedings - 2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2023

Conference

Conference53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2023
Country/TerritoryPortugal
CityPorto
Period06/27/2306/30/23

Keywords

  • mobile notification
  • privacy exposure
  • vulnerability analysis

Fingerprint

Dive into the research topics of 'Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification Systems'. Together they form a unique fingerprint.

Cite this