arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

在权限中迷失:探索Microsoft 365应用生态系统

Lost in Permissions: Exploring the Microsoft 365 App Ecosystem

Vincenzo Longo, Alberto Verna, Nikhil Jha, Marco Mellia

arXiv 2608.02336首次发表:更新:

AI 中文总结

本文对Microsoft 365应用生态系统开展隐私安全测量,爬取8000余个应用,发现权限披露不一致、过度特权访问普遍,提出的主题感知异常检测框架可识别异常应用,为管理员提供安全见解。

AI 中文摘要

Microsoft 365(M365)生态系统托管着数千个第三方应用,这些应用通过细粒度OAuth权限与企业租户集成,可能访问电子邮件、文件、日历、聊天记录和用户目录等敏感组织资源。尽管这些权限授予存在安全隐患,但M365生态系统尚未得到系统研究。本文首次开展面向隐私与安全的M365第三方应用测量,结合公开市场API与自动化租户侧部署,爬取超过8000个应用,发现其中仅1069个同时提供描述和权限集,官方分发渠道间透明度存在显著不一致。接着,利用主题感知异常检测框架评估请求权限是否与声明功能匹配:通过神经主题建模对应用聚类,在每个主题内应用无监督异常检测,识别与同侪权限配置文件的偏差;对最异常案例的大语言模型(LLM)辅助分析及盲测人工检查,揭示异常权限配置与请求权限风险存在相关性。研究发现,许多应用请求过于宽泛的租户范围权限(如目录级读写访问),违反最小权限原则并扩大组织攻击面。本文的流程通过识别异常应用及最具异常贡献的权限,为租户管理员提供可操作的见解。总体而言,研究结果揭示M365应用生态系统存在系统性不透明与结构不成熟问题,权限披露不一致且过度特权访问现象普遍。

英文摘要

The Microsoft 365 (M365) ecosystem hosts thousands of third-party applications that integrate with enterprise tenants via fine-grained OAuth permissions, potentially granting access to sensitive organisational resources such as emails, files, calendars, chats, and user directories. Despite the security implications of these permission grants, the M365 ecosystem has not been systematically studied. We present the first privacy- and security-oriented measurement of M365 third-party applications. By combining public marketplace APIs with automated tenant-side deployment, we crawl over 8,000 applications. We find that only 1,069 of them expose both descriptions and permission sets, with significant inconsistencies in transparency across official distribution channels. Next, we leverage a topic-aware anomaly detection framework to assess whether requested permissions align with declared functionality. We cluster applications via Neural Topic Modelling and apply unsupervised anomaly detection within each topic to identify deviations from peer permission profiles. LLM-assisted analysis of the most anomalous cases and blind manual inspection reveal a correlation between anomalous permission profiles and the risk associated with the requested permissions. We find that many applications request overly broad tenant-wide scopes (e.g., directory-wide read/write access), violating least-privilege principles and increasing the organisational attack surface. Our pipeline provides tenant administrators with actionable insights by identifying anomalous applications and the permissions that most contribute to their anomalousness. Overall, our findings expose systemic opacity and structural immaturity in the M365 app ecosystem, where permission disclosure is inconsistent and over-privileged access is common.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑