A comparative analysis of certificate pinning in Android & iOS

A comparative analysis of certificate pinning in Android & iOS
复制标题

DOI:
10.1145/3517745.3561439
复制
发表时间:
2022-10
期刊:
Proceedings of the 22nd ACM Internet Measurement Conference
影响因子:
--
通讯作者:
Amogh Pradeep;Muhammad Talha Paracha;Protick Bhowmick;Ali Davanian;Abbas Razaghpanah;Taejoong Chung;Martina Lindorfer;Narseo Vallina-Rodriguez;Dave Levin;D. Choffnes
Amogh Pradeep;Muhammad Talha Paracha;Protick Bhowmick;Ali Davanian;Abbas Razaghpanah;Taejoong Chung;Martina Lindorfer;Narseo Vallina-Rodriguez;Dave Levin;D. Choffnes
中科院分区:
其他
文献类型:
--
作者:
Amogh Pradeep;Muhammad Talha Paracha;Protick Bhowmick;Ali Davanian;Abbas Razaghpanah;Taejoong Chung;Martina Lindorfer;Narseo Vallina-Rodriguez;Dave Levin;D. Choffnes

文献摘要

相似文献

TLS证书固定是应用程序使用的一种安全机制,用于保护其网络流量免受恶意证书颁发机构(ca)、路径内监控和其他TLS篡改方法的攻击。钉住可以提供增强的安全性,以防止恶意第三方访问传输中的敏感数据(例如,保护敏感的银行和医疗保健信息),但也可以向用户和审计人员隐藏应用程序的个人数据收集。之前的研究发现,除了高调的、对安全敏感的应用程序外,在Android生态系统中很少使用钉住;而且,我们对它在iOS和手机平台上的使用情况知之甚少。在本文中,我们深入研究了证书绑定在Android和iOS上的使用。我们从两个官方应用商店中收集了5079个独特的应用程序:575个常见应用程序,每个流行应用程序1000个,每个随机选择的应用程序1000个。我们开发了新颖的、跨平台的、静态的和动态的分析技术来检测证书绑定的使用。因此,我们的研究提供了一个更全面的了解证书钉钉比以往的研究。我们发现证书钉钉的广泛采用程度是最近研究报告的4倍。更具体地说,我们发现0.9%至8%的Android应用和2.5%至11%的iOS应用在运行时使用证书绑定(取决于上述应用集)。然后,我们调查哪些类别的应用程序最常使用固定(例如,“金融”类别的应用程序),哪些目的地通常是固定的(例如,第一方目的地与第三方库使用的目的地),哪些证书是固定的,以及这些证书是如何固定的(例如,CA与叶子证书),以及固定连接与未固定连接的连接安全性(例如,使用弱密码或不适当的证书验证)。最后,我们研究了有多少固定连接适合二进制检测,以揭示其连接的内容;对于那些受保护的,我们分析通过固定连接发送的数据,以了解通过固定保护的内容。
TLS certificate pinning is a security mechanism used by applications (apps) to protect their network traffic against malicious certificate authorities (CAs), in-path monitoring, and other methods of TLS tampering. Pinning can provide enhanced security to defend against malicious third-party access to sensitive data in transit (e.g., to protect sensitive banking and health care information), but can also hide an app's personal data collection from users and auditors. Prior studies found pinning was rarely used in the Android ecosystem, except in high-profile, security-sensitive apps; and, little is known about its usage on iOS and across mobile platforms. In this paper, we thoroughly investigate the use of certificate pinning on Android and iOS. We collect 5,079 unique apps from the two official app stores: 575 common apps, 1,000 popular apps each, and 1,000 randomly selected apps each. We develop novel, cross-platform, static and dynamic analysis techniques to detect the usage of certificate pinning. Thus, our study offers a more comprehensive understanding of certificate pinning than previous studies. We find certificate pinning as much as 4 times more widely adopted than reported in recent studies. More specifically, we find that 0.9% to 8% of Android apps and 2.5% to 11% of iOS apps use certificate pinning at run time (depending on the aforementioned sets of apps). We then investigate which categories of apps most frequently use pinning (e.g., apps in the "finance" category), which destinations are typically pinned (e.g., first-party destinations vs those used by third-party libraries), which certificates are pinned and how these are pinned (e.g., CA vs leaf certificates), and the connection security for pinned connections vs unpinned ones (e.g., the use of weak ciphers or improper certificate validation). Lastly, we investigate how many pinned connections are amenable to binary instrumentation to reveal the contents of their connections; for those that are, we analyze the data sent over pinned connections to understand what is protected by pinning.