• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

最小暴露的危险:通过多侧信道学习理解iOS上的跨应用信息泄露

The Danger of Minimum Exposures: Understanding Cross-App Information Leaks on iOS through Multi-Side-Channel Learning.

作者信息

Wang Zihao, Guan Jiale, Wang XiaoFeng, Wang Wenhao, Xing Luyi, Alharbi Fares

机构信息

Indiana University Bloomington.

Institute of Information Engineering, Chinese Academy of Sciences.

出版信息

Conf Comput Commun Secur. 2023 Nov;2023:281-295. doi: 10.1145/3576915.3616655. Epub 2023 Nov 21.

DOI:10.1145/3576915.3616655
PMID:39391799
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC11466504/
Abstract

Research on side-channel leaks has long been focusing on the information exposure from a single channel (memory, network traffic, power, etc.). Less studied is the risk of learning from multiple side channels related to a target activity (e.g., website visits) even when individual channels are not informative enough for an effective attack. Although the prior research made the first step on this direction, inferring the operations of foreground apps on iOS from a set of global statistics, still less clear are how to determine the maximum information leaks from all target-related side channels on a system, what can be learnt about the target from such leaks and most importantly, how to control information leaks from the whole system, not just from an individual channel. To answer these fundamental questions, we performed the first systematic study on multi-channel inference, focusing on iOS as the first step. Our research is based upon a novel attack technique, called Mischief, which given a set of potential side channels related to a target activity (e.g., foreground apps), utilizes probabilistic search to approximate an optimal subset of the channels exposing most information, as measured by Merit Score, a metric for correlation-based feature selection. On such an optimal subset, an inference attack is modeled as a multivariate time series classification problem, so the state-of-the-art deep-learning based solution, InceptionTime in particular, can be applied to achieve the best possible outcome. Mischief is found to work effectively on today's iOS (16.2), identifying foreground apps, website visits, sensitive IoT operations (e.g., opening the door) with a high confidence, even in an open-world scenario, which demonstrates that the protection Apple puts in place against the known attack is inadequate. Also importantly, this new understanding enables us to develop more comprehensive protection, which could elevate today's side-channel research from suppressing leaks from individual channels to controlling information exposure across the whole system.

摘要

长期以来,对侧信道泄漏的研究一直聚焦于单个信道(内存、网络流量、功耗等)的信息暴露。较少被研究的是,即使单个信道提供的信息不足以发动有效攻击,从与目标活动(如网站访问)相关的多个侧信道中获取信息的风险。尽管先前的研究在这个方向上迈出了第一步,即从一组全局统计数据推断iOS上的前台应用操作,但仍不清楚如何确定系统上所有与目标相关的侧信道的最大信息泄漏量,从这些泄漏中可以了解到关于目标的哪些信息,以及最重要的是,如何控制整个系统的信息泄漏,而不仅仅是单个信道的信息泄漏。为了回答这些基本问题,我们首先以iOS为对象,对多信道推理进行了首次系统研究。我们的研究基于一种名为“恶作剧”(Mischief)的新型攻击技术,该技术针对与目标活动(如前台应用)相关的一组潜在侧信道,利用概率搜索来近似找出通过“价值分数”(Merit Score,一种基于相关性的特征选择指标)衡量的、暴露最多信息的信道的最优子集。在这样一个最优子集上,推理攻击被建模为一个多元时间序列分类问题,因此可以应用基于深度学习的最新解决方案,特别是InceptionTime,以实现最佳可能结果。结果发现,“恶作剧”在当今的iOS(16.2)系统上能有效运行,即使在开放世界场景下,也能以高置信度识别前台应用、网站访问、敏感的物联网操作(如开门),这表明苹果针对已知攻击所采取的保护措施并不充分。同样重要的是,这种新认识使我们能够开发更全面的保护措施,这可以将当今的侧信道研究从抑制单个信道的泄漏提升到控制整个系统的信息暴露。

相似文献

1
The Danger of Minimum Exposures: Understanding Cross-App Information Leaks on iOS through Multi-Side-Channel Learning.最小暴露的危险:通过多侧信道学习理解iOS上的跨应用信息泄露
Conf Comput Commun Secur. 2023 Nov;2023:281-295. doi: 10.1145/3576915.3616655. Epub 2023 Nov 21.
2
Folic acid supplementation and malaria susceptibility and severity among people taking antifolate antimalarial drugs in endemic areas.在流行地区,服用抗叶酸抗疟药物的人群中,叶酸补充剂与疟疾易感性和严重程度的关系。
Cochrane Database Syst Rev. 2022 Feb 1;2(2022):CD014217. doi: 10.1002/14651858.CD014217.
3
Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android.探索移动健康的另一面:iOS 和 Android 上移动健康应用的信息安全和隐私。
JMIR Mhealth Uhealth. 2015 Jan 19;3(1):e8. doi: 10.2196/mhealth.3672.
4
Measuring the Quality of Clinical Skills Mobile Apps for Student Learning: Systematic Search, Analysis, and Comparison of Two Measurement Scales.测量临床技能移动应用程序对学生学习质量的评估:两种测量量表的系统搜索、分析和比较。
JMIR Mhealth Uhealth. 2021 Apr 23;9(4):e25377. doi: 10.2196/25377.
5
Health Internet Technology for Chronic Conditions: Review of Diabetes Management Apps.慢性病的健康互联网技术:糖尿病管理应用程序综述
JMIR Diabetes. 2021 Aug 31;6(3):e17431. doi: 10.2196/17431.
6
Macromolecular crowding: chemistry and physics meet biology (Ascona, Switzerland, 10-14 June 2012).大分子拥挤现象:化学与物理邂逅生物学(瑞士阿斯科纳,2012年6月10日至14日)
Phys Biol. 2013 Aug;10(4):040301. doi: 10.1088/1478-3975/10/4/040301. Epub 2013 Aug 2.
7
[Standard technical specifications for methacholine chloride (Methacholine) bronchial challenge test (2023)].[氯化乙酰甲胆碱支气管激发试验标准技术规范(2023年)]
Zhonghua Jie He He Hu Xi Za Zhi. 2024 Feb 12;47(2):101-119. doi: 10.3760/cma.j.cn112147-20231019-00247.
8
Engineering Aspects of Olfaction嗅觉的工程学方面
9
Medication Management Apps for Diabetes: Systematic Assessment of the Transparency and Reliability of Health Information Dissemination.糖尿病用药管理应用程序:健康信息传播透明度和可靠性的系统评估。
JMIR Mhealth Uhealth. 2020 Feb 19;8(2):e15364. doi: 10.2196/15364.
10
What's really 'ing'? A forensic analysis of Android and iOS dating apps.究竟是什么在“作祟”?对安卓和iOS约会应用程序的法医分析。
Comput Secur. 2020 Jul;94:101833. doi: 10.1016/j.cose.2020.101833. Epub 2020 Apr 28.

本文引用的文献

1
Text Data Augmentation for Deep Learning.用于深度学习的文本数据增强
J Big Data. 2021;8(1):101. doi: 10.1186/s40537-021-00492-0. Epub 2021 Jul 19.
2
The great multivariate time series classification bake off: a review and experimental evaluation of recent algorithmic advances.多元时间序列分类大比拼:对近期算法进展的综述与实验评估
Data Min Knowl Discov. 2021;35(2):401-449. doi: 10.1007/s10618-020-00727-3. Epub 2020 Dec 18.
3
Toward open set recognition.面向开集识别。
IEEE Trans Pattern Anal Mach Intell. 2013 Jul;35(7):1757-72. doi: 10.1109/TPAMI.2012.256.