A technique to circumvent SSL/TLS validations on iOS devices

A technique to circumvent SSL/TLS validations on iOS devices
复制标题

DOI:
10.1016/j.future.2016.08.019
复制
发表时间:
2017-09
期刊:
Future Gener. Comput. Syst.
影响因子:
--
通讯作者:
Christian D'Orazio;Kim-Kwang Raymond Choo
Christian D'Orazio;Kim-Kwang Raymond Choo
中科院分区:
其他
文献类型:
--
作者:
Christian D'Orazio;Kim-Kwang Raymond Choo

文献摘要

被引文献

相似文献

SSL/TLS验证(如证书和公钥固定)可以加强物联网设备与远程服务器之间加密通信的安全性,并确保用户的隐私。然而,这样的实现使信息泄露的取证分析和检测复杂化;例如,当移动的应用通过向第三方发送敏感信息而侵犯用户隐私时。因此,开发审查移动的应用程序的能力以增强SSL/TLS流量的安全性至关重要。在本文中,我们提出了一种技术来绕过系统的默认证书验证以及在iOS应用程序中执行的内置SSL/TLS验证。然后,我们通过分析40个流行的iOS社交网络,电子支付,银行和云计算应用程序来展示其实用性。
SSL/TLS validations such as certificate and public key pinning can reinforce the security of encrypted communications between Internet-of-Things devices and remote servers, and ensure the privacy of users. However, such implementations complicate forensic analysis and detection of information disclosure; say, when a mobile app breaches user’s privacy by sending sensitive information to third parties. Therefore, it is crucial to develop the capacity to vet mobile apps augmenting the security of SSL/TLS traffic. In this paper, we propose a technique to bypass the system’s default certificate validation as well as built-in SSL/TLS validations performed in iOS apps. We then demonstrate its utility by analysing 40 popular iOS social networking, electronic payment, banking, and cloud computing apps.