当应用比厂商更长寿:物联网废弃软件的安全影响
When Apps Outlive Vendors: Security Implications of IoT Abandonware
浏览论文内容
中文总结 AI 辅助
针对物联网配套应用被厂商遗弃后仍运行的现象,首次大规模测量61,500个应用,发现73.6%存在安全风险,包括过时依赖、可劫持域名及数据泄露流向。
中文摘要 AI 辅助
随着物联网(IoT)市场的持续扩张,许多配套应用被发布到应用商店中,这引发了人们对那些厂商已放弃支持的应用的安全担忧。即使厂商停止支持,这些应用通常仍会在用户的移动设备上继续运行,继续与用户的物联网设备交互,并在未接收安全更新的情况下收集用户数据。这使得已知和新发现的安全漏洞得不到修复,增加了远程利用、未经授权的设备访问以及长期数据滥用的风险。我们将这些被遗弃的应用定义为“物联网废弃软件”(IoT abandonware),并首次对已停止服务的应用相关的安全风险进行了大规模测量研究。我们分析了61,500个物联网配套安卓应用,这些应用截至2025年3月至少两年未更新或已不再服务。从反编译的二进制文件中,我们提取了潜在和嵌入的资源(例如捆绑的库、域名和权限),并评估了其安全影响。首先,我们识别了带有废弃后CVE报告的过时依赖项,并发现了易受接管或数据泄露影响的域名。其次,我们执行静态数据流分析,以追踪从提取的权限中推断出的敏感数据如何传播到损坏或可劫持的外部端点。我们发现,在厂商控制失效后,持久性的分析和第三方跟踪器继续聚合用户数据和设备遥测信息,形成了攻击者可以重定向或滥用的数据流。总体而言,我们在数据集的73.6%中识别出了安全风险,其中前1000个最常安装的应用中有30个将数据发送到损坏的外部端点。
英文摘要
As the Internet of Things (IoT) market continues to expand, many companion apps are being published in app stores, raising security concerns for those whose vendors have abandoned support. Even after vendors discontinue support, such applications frequently remain operational on users' mobile devices, continue to interface with users' IoT devices and collect user data without receiving security updates. This leaves known and newly discovered vulnerabilities unmitigated, increasing risks of remote exploitation, unauthorized device access, and prolonged data misuse. We define these abandoned applications as "IoT abandonware" and present the first large-scale measurement study of the security risks associated with discontinued applications. We analyze 61,500 IoT companion Android applications that had not been updated for at least two years or were no longer in service as of March 2025. From decompiled binaries, we extracted latent and embedded resources (e.g., bundled libraries, domain names, and permissions), and assessed their security implications. First, we identify outdated dependencies with post-abandonment CVE reports and discover domains vulnerable to takeover or data exfiltration. Second, we perform static data-flow analysis to trace how sensitive data, inferred from the extracted permissions, propagates to broken or hijackable external endpoints. We found that persistent analytics and third-party trackers continue aggregating user data and device telemetry long after vendor control lapses, creating data flows that adversaries can redirect or abuse. Overall, we identified security risks in 73.6% of our dataset, with 30 of the top 1,000 most-installed apps sending data to broken external endpoints.
发表机构
- University of Massachusetts Amherst(马萨诸塞大学阿默斯特分校)
机构由 AI 辅助整理,请以论文原文为准。