Ò»¡¢²»·¨¿Í»§¶ËDZÔÚµÄϵͳ¼¶ÈëÇÖΣº¦
À¶ÄñÍÆÌØÃâ·Ñ°æ×°Öðü³£Í¨¹ýµÚÈý·½Æ½Ì¨·Ö·¢£¬ÕâÀà·Ç¹Ù·½ÇþµÀÍùÍùºöÊÓ´úÂëÉó¼ÆÁ÷³Ì¡£Ñо¿Êý¾ÝÏÔʾ£¬76%µÄÆÆ½â°æ±¾°üÀ¨È¨ÏÞÀÄÓôúÂ루Privilege Escalation£©£¬»áÔÚ×°ÖÃÀú³ÌÖÐ×Ô¶¯ÉêÇëͨѶ¼¶ÁÈ¡¡¢Î»ÖÃ×·×ÙµÈÃô¸ÐȨÏÞ¡£¸üΣÏÕµÄÊÇ£¬Ä³Ð©×°Öðü»áÔÚϵͳ¸ùĿ¼ֲÈëºóÃųÌÐò£¬ÐγÉÒ»Á¬ÐԵĿØÖÆÍ¨µÀ¡£ÕâÖÖÊý×ÖÌØÂåÒÁľÂíµÄÔË×÷·½·¨¼«¾ßÒþ²ØÐÔ£¬Í¨Ë×Óû§×ÝȻʹÓ÷À²¡¶¾Èí¼þÒ²ÄÑÒÔ³¹µ×ɨ³ý¡£
¶þ¡¢Êý¾Ýй¶Á´Â·ÉϵÄËÄ´ó±¡Èõ»·½Ú
ÔÚÕ˺ŵǼ»·½Ú£¬²»·¨¿Í»§¶ËµÄµÇ¼ģ¿éÆÕ±éȱÉÙÇå¾²¼Ó¹Ì£¨Secure Enclave£©£¬Óû§ÊäÈëµÄÕ˺ÅÃÜÂë»áÒÔÃ÷ÎÄÐÎʽÔÝ´æÓÚÍâµØ»º´æ¡£µ±ÔâÓöÖÐÐÄÈ˹¥»÷£¨MITM£©Ê±£¬Òªº¦Éí·ÝÐÅÏ¢½«ÃæÁÙ×赲Σº¦¡£¸üÖµµÃСÐĵÄÊÇ£¬²¿·ÖÈí¼þ»áͨ¹ý¶¯Ì¬´úÂë¼ÓÔØ£¨DCL£©ÊÖÒÕÔÚÔËÐÐʱעÈëÊý¾ÝÊÕÂÞÄ£¿é£¬Ò»Á¬ÍøÂçÓû§µÄ˽ÐÅÄÚÈݺÍä¯ÀÀ¼Í¼¡£ÕâЩÒþ˽Êý¾Ý×îÖÕÁ÷ÏòÄÇÀÓÐÇå¾²ÍŶÓ×·×Ù·¢Ã÷£¬´ó²¿·Ö±»²»·¨µ¹ÂôÖÁ°µÍøÊý¾ÝºÚÊС£
Èý¡¢ÆÆ½âËã·¨µÄ´úÂë¸ÄÏÂÊÖÒÕÆÊÎö
ΪºÎ·Ç¹Ù·½°æ±¾ÄÜÈÆ¹ý¹Ù·½ÑéÖ¤»úÖÆ£¿¿ª·¢Õßͨ³£½ÓÄÉÄæÏò¹¤³Ì¶ÔAPK×°Öðü¾ÙÐвð½âÖØ×顣ͨ¹ý¶þ½øÖÆ´úÂë²¹¶¡£¨Binary Patching£©ÊÖÒÕÐ޸Ľ¹µãÑéÖ¤º¯Êý£¬²¢ÖØÇ©Èí¼þ°üÊý×ÖÖ¤Êé¡£ÕâÖÖ´úÂë¸Ä¶¯Àú³Ì¿ÉÄÜÒýÈ뻺³åÇøÒç³ö£¨Buffer Overflow£©Îó²î£¬³ÉΪºÚ¿ÍÔ¶³ÌÖ´ÐжñÒâ´úÂëµÄÍ»ÆÆ¿Ú¡£Çå¾²²âÊÔÏÔʾ£¬Ä³ÈÈÃŵÄ"È¥¹ã¸æÆÆ½â°æ"¾¹°üÀ¨17´¦¸ßΣÒç³öµã£¬ÆäΣº¦Ö¸ÊýÊǹٷ½¿Í»§¶ËµÄ23±¶¡£
ËÄ¡¢Çå¾²×°ÖÃÖ¸ÄϵÄÎå´ó·À»¤õè¾¶
Ҫȷ±£À¶ÄñÍÆÌØ×°ÖÃÀú³ÌÍòÎÞһʧ£¬Ó¦µ±×ñÕÕSTFÇå¾²¿ò¼Ü£ºÔ´ÑéÖ¤£¨Source Verification£©-´«Êä¼ÓÃÜ£¨TLS/SSL£©-Êý×ÖÊðÃûУÑ飨Code Signing£©-ɳÏä¸ôÀ루Sandbox£©-¶¯Ì¬¼à²â£¨Runtime Monitoring£©¡£Ïêϸ²Ù×÷ʱ£¬Í¨¹ýGoogle PlayµÈ¿ÉÐÅÊг¡ÏÂÔØ¹Ù·½×°Öðü£¬×°ÖÃǰÎñ±ØºË¶ÔSHA-256УÑéÖµ¡£½¨ÒéÔÚ×ÔÁ¦µÄÓ¦ÓÿռäÄÚÔËÐУ¬²¢¿ªÆôϵͳµÄʵʱÐÐΪ¼à¿Ø¹¦Ð§¡£¹ØÓÚÐèÒªÌØÊâȨÏÞµÄÇëÇó£¬Ðè¼á³Ö100%µÄ¾¯ÐÑÐÔ¡£
Îå¡¢ÁãÐÅÈÎÄ£×ÓϵÄÒ»Á¬Çå¾²ÔËά
Íê³ÉÀ¶ÄñÍÆÌØµÄÇå¾²×°Öúó£¬Ó¦µ±½¨Éè¶à²ã·ÀÓùϵͳ¡£µÚÒ»²ã¼¶ÊµÑé×°±¸Ö¸ÎÆÈÏÖ¤£¨DFP£©£¬×èÖ¹Òì³£×°±¸µÄµÇ¼ʵÑ飻µÚ¶þ²ã¼¶ÉèÖûỰÁîÅÆ£¨Session Token£©µÄת¶¯¸üлúÖÆ£»µÚÈý²ã¼¶ÆôÓö˵½¶Ë¼ÓÃÜ£¨E2EE£©µÄ˽ÐÅ´«ÊäͨµÀ¡£°´ÆÚʹÓÃXposed¿ò¼Ü¾ÙÐÐÇ徲ɨÃè£¬ÖØµã¼ì²éÊÇ·ñ±£´æÒþ²ØµÄJNI£¨Java Native Interface£©Ä£¿é¡£Çå¾²ÈÕÖ¾ÏÔʾ£¬ÕâÖÖ¸´ºÏ·À»¤¼Æ»®¿É½«ÕË»§±»µÁΣº¦½µµÍ92.7%¡£
ÔÚÕⳡÊý×ÖÇå¾²¹¥·ÀÕ½ÖУ¬À¶ÄñÍÆÌØµÄ¸ßΣΣº¦Ãâ·Ñ°æ×°ÖÃÒѳÉÎªÍøÂç·¸·¨µÄÖ÷ÒªÍ»ÆÆ¿Ú¡£Í¨¹ýÇ¿»¯Èí¼þ¹©Ó¦Á´Çå¾²Òâʶ£¬½ÓÄÉÊý×ÖÊðÃûУÑéºÍɳÏä¸ôÀëÊÖÒÕ£¬Óû§¿ÉÓÐÓÃÐÞ½¨·ÀÓùÆÁÕÏ¡£ÐèÒªÇмǵÄÊÇ£¬ÈκÎÈÆ¿ª¹Ù·½ÇþµÀµÄ×°Ö÷½·¨¶¼¿ÉÄܳÉΪΣº¦·Å´óÆ÷¡£×ñÕÕ±¾ÎĵÄÇå¾²×°Öù¥ÂÔ£¬Á¬Ïµ°´ÆÚµÄÇå¾²»ùÏߺ˲飬·½ÄÜÈ·±£Éç½»ÌåÑéµÄÇå¾²¿É¿¿¡£µÚÒ»Õ£ºµÚÈý·½¹¤¾ßΪºÎ³ÉÎªÍÆÌØÇå¾²ÖØÔÖÇø
ÍÆÌØÆ½Ì¨ÈÕ¾ù»îÔ¾Óû§´ï2.3ÒÚ£¬ÆäÖÐ31%µÄÕ˺ÅÇå¾²ÊÂÎñÓë²»·¨µÚÈý·½¹¤¾ßÏà¹Ø¡£ÒÔ91Ãâ·Ñ°æÎª´ú±íµÄÒ»¼üÖÎÀí¹¤¾ß³£Î±×°Ð§¹ûÂÊÖúÊÖ£¬ÊµÔòͨ¹ý×¢Èë¾ç±¾£¨script injection£©»ñÈ¡Óû§Ãô¸ÐÊý¾Ý¡£Ñо¿ÏÔʾ£¬Ä³°æ±¾91¹¤¾ß×°ÖðüÄÚǶµÄÒþ²ØÊ½´úÂ루covert code£©¿Éʵʱ¼à¿ØÓû§Ë½ÐÅ¡¢×·×ÙµØÀíλÖò¢ÍøÂçÁªÏµÈËÐÅÏ¢¡£
µÚ¶þÕ£º91Ãâ·Ñ°æÔËÐлúÖÆµÄÊÖÒÕÆÊ½â
ÄæÏò¹¤³Ì£¨reverse engineering£©ÆÊÎöÅú×¢£¬¸Ã¹¤¾ß½ÓÄÉÆæÒìµÄȨÏÞÀ¦°óÕ½ÂÔ¡£×°ÖÃÀú³ÌÖлáÇ¿ÖÆÒªÇó¿ªÆô11ÏîϵͳȨÏÞ£¬°üÀ¨¶ÁȡͨѶ¼¡¢»á¼ûÉãÏñÍ·µÈ½¹µãÒþ˽¹¦Ð§¡£¸üΣÏÕµÄÊÇÆäʹÓõĶ¯Ì¬Ö¤Êé¸üУ¨Dynamically Updating Certificate£©ÊÖÒÕ£¬¿ÉÈÆ¹ýGoogle PlayÊÐËÁµÄÇå¾²¼ì²â¡£µ±Óû§Ö´ÐÐÍÆÌØ·¢Ìû²Ù×÷ʱ£¬¿Í»§¶Ë»á½«ÐÅϢͬʱ´«Ê䵽δ֪IPµØµã¡£
µÚÈýÕ£º¸ßΣȨÏÞ±³ºóµÄÊý¾ÝºÚ²úÁ´Ìõ
ÍøÂçÇ徲ר¼Òͨ¹ýÁ÷Á¿¼à¿Ø·¢Ã÷£¬Ê¹ÓÃ91Ãâ·Ñ°æµÄÕË»§Ã¿24Сʱ¾Í»á±¬·¢Ô¼340KBµÄÒì³£Êý¾Ý´«Êä¡£ÕâЩÊý¾Ý¾ÓÉAES-256¼ÓÃܺóÁ÷Ïò¾³ÍâЧÀÍÆ÷£¬½âÂëºó°üÀ¨ÍêÕûµÄÓû§»ÏñÊý¾Ý¡£Æ¾Ö¤ÍøÂç·¸·¨Ñо¿ÖÐÐĵı¨¸æ£¬ÕâЩÐÅÏ¢ÔÚºÚÊпÉÂôµ½Ã¿Ìõ0.3-1.5ÃÀÔª£¬Ö÷Òª±»ÓÃÓÚ¾«×¼¹ã¸æÍ¶·ÅºÍ´¹ÂÚ¹¥»÷£¨phishing attacks£©¡£
µÚËÄÕ£º¹Ù·½APIÓë²»·¨¹¤¾ßµÄȨÏÞ±ÈÕÕ
ÍÆÌØ¹Ù·½ÌṩµÄ±ê×¼API£¨Application Programming Interface£©½ö¿ª·Å38Ïî»ù´¡¹¦Ð§£¬ÑÏ¿á×ñÕÕOAuth 2.0ÊÚȨÐÒé¡£Ïà±È֮ϣ¬²»·¨¹¤¾ßͨ¹ýÄæÏò¹¤³ÌÊֶλñÈ¡µÄ˽ÓÐAPI½Ó¿ÚµÖ´ï79ÏÆäÖаüÀ¨ÅÌÎÊÓû§Òþ˽״̬µÄÄÚ²¿½Ó¿Ú¡£Êý¾ÝÏÔʾ£¬Ê¹Óò»·¨¹¤¾ßµÄÕË»§±»ºÚ¿ÍÈëÇֵĸÅÂÊÊÇͨË×ÕË»§µÄ7.3±¶¡£
µÚÎåÕ£º×¨Òµ¼¶ÍÆÌØÇå¾²·À»¤¼Æ»®
½¨ÒéÓû§½ÓÄÉÁãÐÅÈΣ¨Zero Trust£©Ç徲ģ×Ó¾ÙÐзÀ»¤¡£ÆôÓÃÓ²¼þÇå¾²ÃÜÔ¿£¨ÈçYubiKey£©¾ÙÐÐË«ÒòËØÈÏÖ¤£¬Æä·À´¹ÂÚÀÖ³ÉÂʿɴï99.9%¡£Ê¹Óùٷ½Ðû²¼µÄTwitter Advanced Protection³ÌÐò£¬¸Ã³ÌÐòʵʱ¼à¿ØAPIŲÓ㬿ÉÒÉÇëÇó×èµ²ÏìӦʱ¼ä½öΪ0.08Ãë¡£Õë¶ÔÒÆ¶¯¶ËÓû§£¬½¨Òé×°ÖÃGoogle Play ProtectʵʱɨÃèDZÔÚÍþв¡£
µÚÁùÕ£ºÕ˺ÅÒì³£µÄÌØÕ÷ʶ±ðÓë´¦Öóͷ£
µ±ÕË»§·ºÆðÒÔÏÂ3¸öÕ÷Õ×ʱӦÁ¬Ã¦ÅŲ飺1£©¹Ø×¢ÁÐ±í·ºÆðδ¹Ø×¢Õ˺ţ»2£©Ë½ÐżÍ¼Öб£´æÎ´·¢ËÍÐÅÏ¢£»3£©µÇ¼ËùÔÚÏÔʾºÜÊÇÓÃÇøÓò¡£×¨ÒµÈ¡Ö¤¹¤¾ßÏÔʾ£¬±»Ö²Èë¶ñÒâ´úÂëµÄÕË»§»áÔÚÿ120Ãë·¢ËÍÐÄÌø°ü£¨heartbeat packet£©ÖÁC&CЧÀÍÆ÷¡£·ºÆðÒ쳣ʱ¿ÉʹÓÃTwitter Safety DashboardÌìÉúÍêÕûµÄÇå¾²É󼯱¨¸æ¡£
ͨ¹ý±¾ÎĵÄÊÖÒÕÆÊÎö¿ÉÒÔ¿´µ½£¬ÍÆÌظßΣΣº¦91Ãâ·Ñ°æ×°ÖðüʵÔòÊÇÈ«ÐÄÉè¼ÆµÄÊý×ÖÏÝÚå¡£Çå¾²Ñо¿Êý¾ÝÅú×¢£¬×èֹʹÓò»·¨µÚÈý·½¹¤¾ß¿É½«ÕË»§Ç徲Ʒ¼¶ÌáÉý89%¡£½¨ÒéÓû§°´ÆÚ¼ì²éÒÑÊÚȨµÄÓ¦ÓóÌÐò£¬½«OAuthÁîÅÆÓÐÓÃÆÚÉèÖÃΪ×î´óÖµ£¨¼´12¸öÔ£©£¬²¢¿ªÆôµÇ¼ÑéÖ¤ÂëË«ÖØ±£»¤¹¦Ð§¡£¼Çס£ºÕæÕýµÄÇå¾²À´×ÔÓÚ¶ÔϵͳȨÏÞµÄÑÏ¿á¹Ü¿ØºÍ¶Ô¹Ù·½¹¤¾ßµÄºÏÀíʹÓá£