[논문 리뷰] Unauthorized Cross-App Resource Access on MAC OS X and iOS
이 논문은 Apple의 macOS 및 iOS 플랫폼에서 샌드박스 처리된 악성 앱이 키체인, URL 스킴, 웹소켓, NSConnection과 같은 보호되지 않은 앱 간 메커니즘을 통해 비인가된 앱 간 자원 접근(XARA)을 허용하는 심각한 보안 결함을 규명한다. 저자들은 이러한 취약성이 앱 간 상호작용에서 약한 인증을 악용하여 비밀번호, 토큰, 개인 앱 파일과 같은 민감한 사용자 데이터를 완전히 유출할 수 있음을 입증하며, 배포 이전에 이러한 결함을 탐지할 수 있는 자동화된 스캐너(Xavus)를 제안한다.
On modern operating systems, applications under the same user are separated from each other, for the purpose of protecting them against malware and compromised programs. Given the complexity of today's OSes, less clear is whether such isolation is effective against different kind of cross-app resource access attacks (called XARA in our research). To better understand the problem, on the less-studied Apple platforms, we conducted a systematic security analysis on MAC OS~X and iOS. Our research leads to the discovery of a series of high-impact security weaknesses, which enable a sandboxed malicious app, approved by the Apple Stores, to gain unauthorized access to other apps' sensitive data. More specifically, we found that the inter-app interaction services, including the keychain, WebSocket and NSConnection on OS~X and URL Scheme on the MAC OS and iOS, can all be exploited by the malware to steal such confidential information as the passwords for iCloud, email and bank, and the secret token of Evernote. Further, the design of the app sandbox on OS~X was found to be vulnerable, exposing an app's private directory to the sandboxed malware that hijacks its Apple Bundle ID. As a result, sensitive user data, like the notes and user contacts under Evernote and photos under WeChat, have all been disclosed. Fundamentally, these problems are caused by the lack of app-to-app and app-to-OS authentications. To better understand their impacts, we developed a scanner that automatically analyzes the binaries of MAC OS and iOS apps to determine whether proper protection is missing in their code. Running it on hundreds of binaries, we confirmed the pervasiveness of the weaknesses among high-impact Apple apps. Since the issues may not be easily fixed, we built a simple program that detects exploit attempts on OS~X, helping protect vulnerable apps before the problems can be fully addressed.
연구 동기 및 목표
- macOS 및 iOS의 앱 격리 메커니즘이 비인가된 앱 간 자원 접근(XARA) 공격에 효과적인지 조사하기.
- 이러한 공격을 가능하게 하는 Apple의 앱 간 통신 및 샌드박싱 메커니즘의 보안 취약점을 규명하고 분석하기.
- 앱 바이너리 내 결여된 인증을 탐지할 수 있는 자동화된 스캐너(Xavus) 개발하기.
- 고영향도 앱을 대상으로 테스트하여 이러한 취약성의 실제 세계 영향을 평가하고, 탐지되지 않는 악성 악성 체인을 시연하기.
- 향후 운영체제 및 앱 보안 설계 향상을 위한 통찰력과 대응 전략 제공하기.
제안 방법
- 키체인, 웹소켓, NSConnection, URL 스킴과 같은 앱 간 메커니즘의 동작을 역공학하고 테스트하기 위해 macOS 및 iOS의 체계적 보안 분석을 수행했다.
- Facebook, Evernote, WeChat 등의 고영향도 앱을 대상으로 종단 간 악성 악성 체인을 구축하여 자격 증명 및 개인 데이터에 대한 비인가 접근을 시연했다.
- macOS 및 iOS 앱 바이너리를 스캔하여 앱 간 상호작용에서 결여된 인증을 탐지할 수 있는 자동화된 바이너리 분석 도구 Xavus를 개발했다.
- macOS의 BID 기반 샌드박싱 모델을 악용하여 Apple Bundle ID를 가로채 악성 앱이 다른 앱의 컨테이너 디렉터리에 완전히 접근하도록 했다.
- 양 플랫폼에서 중간자 기법을 사용하여 탈취된 토큰을 피해 앱에 도용적으로 전달함으로써 탐지 회피를 구현했다.
- 수백 개의 앱 바이너리를 분석하여 스캐너의 효과성을 검증했으며, 이로써 취약성이 널리 퍼져 있음을 확인했다.
실험 결과
연구 질문
- RQ1샌드박스 처리된 악성 앱이 macOS 및 iOS에서 격리 메커니즘을 우회하여 다른 앱의 민감한 데이터에 접근할 수 있는가?
- RQ2Apple의 앱 간 통신 메커니즘(예: 키체인, URL 스킴, 웹소켓, NSConnection)은 비인가 접근으로부터 충분히 보호되고 있는가?
- RQ3Apple의 샌드박싱 및 번들 ID 메커니즘은 신원 위조를 통한 권한 상승 공격에 얼마나 취약한가?
- RQ4앱 간 및 앱-OS 간 인증의 부재가 광범위하고 은밀한 데이터 유출을 초래할 수 있는가?
- RQ5실제 앱 바이너리에서 이러한 취약성의 자동 탐지는 얼마나 효과적인가?
주요 결과
- macOS 및 iOS의 키체인 서비스는 앱 간 접근 제어에서 부족한 인증으로 인해 악성 앱에 의한 비인가 접근이 가능하다.
- macOS 및 iOS의 URL 스킴 가로채기 공격을 통해 악성 앱이 정상 앱을 위장하여 민감한 토큰(예: Evernote, iCloud)을 도용할 수 있다.
- macOS의 NSConnection 및 웹소켓 메커니즘은 적절한 인증 검사 없이도 앱 간 데이터 유출을 가능하게 한다.
- macOS의 BID 기반 샌드박싱 모델은 악성 앱이 다른 앱의 번들 ID를 가로채면 해당 앱의 개인 컨테이너 디렉터리에 완전한 접근이 가능하게 되어 있다.
- 저자들은 악성 앱을 Apple App Store에 제출하여 승인을 받는 데 성공했으며, 이는 이 취약성이 Apple의 심사 프로세스를 우회할 수 있음을 증명한다.
- 스캐너 Xavus는 수백 개의 고영향도 앱에서 결여된 인증을 탐지하여, 이 결함이 생태계 전반에 걸쳐 널리 퍼져 있음을 확인했다.
더 나은 연구,지금 바로 시작하세요
논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.
카드 등록 없음 · 무료 플랜 제공
이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.