arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

一键泄露:基于移动网络运营商的单点登录网站的真实使用与威胁影响分析

One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On Websites

Jiasheng Huang, Mingxuan Liu, Pei Chen, Baojun Liu, Yiming Zhang, Geng Hong, Zhenrui Zhang, Hai Yang, Haixin Duan, Hui Jiang

arXiv 2609.12037首次发表:更新:

发表机构

Tsinghua University; Zhongguancun Laboratory; Fudan University; Baidu Inc.; Quancheng Laboratory(清华大学; 中关村实验室; 复旦大学; 百度公司; 泉城实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究分析基于移动网络运营商的单点登录(MSSO)网站,揭示其流程中的信任缺陷,提出一键泄露(OCL)攻击,并通过大规模纵向研究证实广泛存在的安全风险,旨在加强移动认证安全。

AI 中文摘要

基于移动网络运营商(MNO)的单点登录(MSSO)是一种依赖移动数据会话的无密码认证框架。与传统单点登录不同,它将身份提供商(IdP)转移至移动网络运营商,并将认证锚点转移至服务提供商(SP)。MSSO的部署日益广泛,并已从移动应用扩展至网站,然而其网络生态系统和安全风险在很大程度上仍未得到探索。我们分析了主流的MSSO部署,识别出一个包含三个阶段的流程,其中存在三个信任缺陷,可导致信任劫持。我们进一步演示了一键泄露(OCL)攻击,即单次网页访问即可泄露敏感身份信息(如电话号码)。我们与一家领先的安全公司合作,开展了首次针对基于网页的MSSO的大规模纵向研究。我们设计了一个分层检测框架,利用被动DNS关联和从搜索数据中重构URL的方法来识别启用MSSO的网站。在一年多的时间里,我们识别出729个顶级域名下的116,852个网站URL。其中,73.6%的URL至少存在一个信任缺陷:69.4%暴露了开发者凭据,27.1%在用户同意前签发高权限令牌,这表明广泛存在可促成OCL的信任缺陷。在729个顶级域名中,31.8%依赖经销商(Resellers),在分析流程中使下游服务提供商对移动网络运营商不可见。脚本分析识别出101个与OCL攻击行为密切相关的网站。我们与合作伙伴追踪了一个具有代表性的上游平台(该平台随后被执法部门查封),并揭示了一个货币化的地下生态系统。经脱敏的后端数据显示,该平台在三天内收集了14,100名用户的电话号码,并将其与浏览活动等敏感信息相关联。我们的工作对基于网页的MSSO部署及其安全影响进行了全面研究。通过负责任的信息披露,我们的工作有助于保障移动认证生态系统的安全。

英文摘要

Mobile Network Operator (MNO)-based Single Sign-On (MSSO) is a password-free authentication framework relying on mobile data sessions. Unlike traditional SSO, it shifts the Identity Provider (IdP) to the MNO and the authentication anchor to the Service Provider (SP). MSSO is increasingly deployed and has expanded from mobile apps to websites, yet its web ecosystem and security risks remain largely unexplored. We analyze mainstream MSSO deployments and identify a 3-phase workflow with three trust defects enabling trust hijacking. We further demonstrate One-Click-to-Leak (OCL) attacks, where a single webpage visit can leak sensitive identity information (e.g., phone numbers). With a leading security company, we conduct the first large-scale, longitudinal study of web-based MSSO. We design a hierarchical detection framework using passive DNS correlations and URL reconstruction from search data to identify MSSO-enabled websites. Over one year, we identified 116,852 website URLs across 729 apex domains. Of these URLs, 73.6% exhibit at least one trust defect: 69.4% expose developer credentials, and 27.1% issue high-privilege tokens before user consent, indicating widespread OCL-enabling trust defects. Among the 729 apex domains, 31.8% rely on Resellers, obscuring the downstream SP from the MNO in the analyzed flows. Script analysis identifies 101 websites strongly associated with OCL attack behavior. With our partner, we trace a representative upstream platform subsequently seized by law enforcement and uncover a monetized underground ecosystem. Sanitized backend data shows that it collected 14,100 users' phone numbers within three days and linked them to sensitive information such as browsing activity. Our work provides a comprehensive study of web-based MSSO deployment and security implications. Through responsible disclosure, our work helps secure the mobile authentication ecosystem.

Comments19 pages. To appear in the Proceedings of the 2026 ACM Conference on Computer and Communications Security (CCS 2026), The Hague, Netherlands

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑