首页> 外文会议>International conference on cryptology and network security >Oh-Pwn-VPN! Security Analysis of Open VPN-Based Android Apps
【24h】

Oh-Pwn-VPN! Security Analysis of Open VPN-Based Android Apps

机译:OH-PWN-VPN!基于VPN的Android应用程序的安全分析

获取原文

摘要

Free VPN apps have gained popularity among millions of users due to their convenience, and have been massively used for accessing blocked sites and preventing network eavesdropping. As a popular open-source VPN solution, OpenVPN is widely used by developers to implement their own VPN services. Despite the prevalence of OpenVPN, it can be insecurely customized and deployed by developers in lack of security guide. In this paper, we perform a systematic security analysis of 84 popular OpenVPN-based apps on the Google Play store. We analyze the deployment security of OpenVPN on Android from the aspects of client profile, code implementation, and permission management. Our experiment reveals three types of misconfigurations that exist in several apps: insecure customized protocols, weak authentication at the client side, and incorrect file permissions on Android. The misconfigurations found by us can lead to some serious attacks, such as VPN traffic decryption and Man-in-the-Middle attacks, endangering millions of users' privacy. Our work shows that, although OpenVPN protocol itself has withstood security analysis, insecure custom modification and configuration can still compromise the security of VPN apps. We then discuss potential causes of these misconfigurations and make practical recommendations for developers to securely deploy OpenVPN services.
机译:免费VPN应用因其方便而在数百万用户中获得了普及,并且已经大量用于访问被封锁的网站和防止网络窃听。作为流行的开源VPN解决方案,开发人员广泛使用OpenVPN来实现自己的VPN服务。尽管OpenVPN普遍存在,但在缺乏安全指南中,开发人员可以不确定地定制和部署。在本文中,我们在Google Play商店中执行了84个基于OpenVPN的应用程序的系统安全分析。我们从客户端配置文件,代码实现和权限管理方面分析了Android上的OpenVPN的部署安全性。我们的实验揭示了几种应用中存在的三种类型的错误配置:不安全的定制协议,客户端的身份障碍弱,以及Android上的文件权限不正确。美国发现的错误配置可能会导致一些严重的攻击,例如VPN交通解密和中间人攻击,危及数百万用户的隐私。我们的工作表明,虽然OpenVPN协议本身具有安全性分析,但不安全的自定义修改和配置仍可危及VPN应用程序的安全性。然后,我们讨论这些错误配置的潜在原因,并对开发人员进行实际建议,以安全地部署OpenVPN服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号