AdSplit: Separating smartphone advertising from applications
arXiv:1202.4030
Abstract
A wide variety of smartphone applications today rely on third-party advertising services, which provide libraries that are linked into the hosting application. This situation is undesirable for both the application author and the advertiser. Advertising libraries require additional permissions, resulting in additional permission requests to users. Likewise, a malicious application could simulate the behavior of the advertising library, forging the user's interaction and effectively stealing money from the advertiser. This paper describes AdSplit, where we extended Android to allow an application and its advertising to run as separate processes, under separate user-ids, eliminating the need for applications to request permissions on behalf of their advertising libraries. We also leverage mechanisms from Quire to allow the remote server to validate the authenticity of client-side behavior. In this paper, we quantify the degree of permission bloat caused by advertising, with a study of thousands of downloaded apps. AdSplit automatically recompiles apps to extract their ad services, and we measure minimal runtime overhead. We also observe that most ad libraries just embed an HTML widget within and describe how AdSplit can be designed with this in mind to avoid any need for ads to have native code.
References in corpus (1)
Cited by in corpus (11)
- Longitudinal Analysis of Android Ad Library Permissions
- Android Inter-App Communication Threats and Detection Techniques
- Intra-Library Collusion: A Potential Privacy Nightmare on Smartphones
- Dissecting Click Fraud Autonomy in the Wild
- Research on Third-Party Libraries in AndroidApps: A Taxonomy and Systematic LiteratureReview
- EnclaveDom: Privilege Separation for Large-TCB Applications in Trusted Execution Environments
- An Empirical Study of Usages, Updates and Risks of Third-Party Libraries in Java Projects
- A First Look at Firefox OS Security
- Pyronia: Intra-Process Access Control for IoT Applications
- In-Vivo Bytecode Instrumentation for Improving Privacy on Android Smartphones in Uncertain Environments
- Differentiated context-aware hook placement for different owners' smartphones