期刊论文详细信息
Entropy
A Framework to Secure the Development and Auditing of SSL Pinning in Mobile Applications: The Case of Android Devices
ÁngelJesús Varela-Vaca1  Joaquín Luque2  FranciscoJosé Ramírez-López2  Alejandro Carrasco2  Jorge Ropero2 
[1] Departamento de Lenguajes y Sistemas Informáticos, Universidad de Sevilla, 41012 Sevilla, Spain;Departamento de Tecnología Electrónica, Universidad de Sevilla, 41012 Sevilla, Spain;
关键词: ssl pinning;    security;    mobile applications;    android;    auditing;    vulnerabilities;    owasp;   
DOI  :  10.3390/e21121136
来源: DOAJ
【 摘 要 】

The use of mobile devices has undergone rapid growth in recent years. However, on some occasions, security has been neglected when developing applications. SSL/TLS has been used for years to secure communications although it is not a vulnerability-free protocol. One of the most common vulnerabilities is SSL pinning bypassing. This paper first describes some security controls to help protect against SSL pinning bypassing. Subsequently, some existing methods for bypassing are presented and two new methods are defined. We performed some experiments to check the use of security controls in widely used applications, and applied SSL pinning bypassing methods. Finally, we created an applicability framework, relating the implemented security controls and the methods that are applicable. This framework provides a guideline for pentesters and app developers.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次