论文标题

被监护人背叛:父母控制解决方案的安全和隐私风险

Betrayed by the Guardian: Security and Privacy Risks of Parental Control Solutions

论文作者

Ali, S., Elgharabawy, M., Duchaussoy, Q., Mannan, M., Youssef, A.

论文摘要

对于幼儿和青少年的父母,数字时代提出了许多新的挑战,包括屏幕时间过多,在线内容不当,网络掠食者和网络欺凌。为了应对这些挑战,许多父母依靠不同平台上的许多父母控制解决方案,包括父母控制网络设备(例如WiFi路由器)和移动设备和笔记本电脑上的软件应用程序。尽管这些父母控制解决方案可能有助于数字育儿,但由于其特权升高并获得了大量隐私敏感的数据,它们也可能对儿童和父母引入严重的安全和隐私风险。在本文中,我们提出了一个实验框架,用于系统地评估父母控制软件和硬件解决方案中的安全性和隐私问题。使用开发的框架,我们在多个平台上提供了首次全面研究,包括网络设备,Windows应用程序,Chrome Extensions和Android应用程序。我们的分析发现了可能导致私人信息泄漏的普遍安全性和隐私问题,和/或允许对手充分控制父母控制解决方案,从而可以直接帮助网络欺凌和网络掠食者。

For parents of young children and adolescents, the digital age has introduced many new challenges, including excessive screen time, inappropriate online content, cyber predators, and cyberbullying. To address these challenges, many parents rely on numerous parental control solutions on different platforms, including parental control network devices (e.g., WiFi routers) and software applications on mobile devices and laptops. While these parental control solutions may help digital parenting, they may also introduce serious security and privacy risks to children and parents, due to their elevated privileges and having access to a significant amount of privacy-sensitive data. In this paper, we present an experimental framework for systematically evaluating security and privacy issues in parental control software and hardware solutions. Using the developed framework, we provide the first comprehensive study of parental control tools on multiple platforms including network devices, Windows applications, Chrome extensions and Android apps. Our analysis uncovers pervasive security and privacy issues that can lead to leakage of private information, and/or allow an adversary to fully control the parental control solution, and thereby may directly aid cyberbullying and cyber predators.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源