首页> 外文会议>International Conference on Contemporary Computing >Network Forensics Analysis of iOS Social Networking and Messaging Apps
【24h】

Network Forensics Analysis of iOS Social Networking and Messaging Apps

机译:IOS社交网络和消息传递应用的网络取证分析

获取原文

摘要

What type of user data are the mobile applications sending? With the plethora of mobile applications available on the online stores, most of the users are unaware about the security risks they may pose. These include breaching end user's privacy by sharing unencrypted private and sensitive data to app's own server or third parties without user's approval. In this research, we tested 70 iOS applications dynamically through network penetration. Out of these, 20 apps were popular social networking and messaging applications. These were analyzed for their runtime behavior and their network traces were used for reconstruction of application layer payload. In about 15 apps out of 20, we were able to trace and reconstruct at least one of the entire message content, user's location, email credentials (including passwords), social networking credentials, profile images or tweeted messages. Apart from that, network traffic of 50 iOS applications was captured to check how end user's data is shared over the network. It was particularly found that many apps share authorized/unauthorized information of app user in unencrypted form. Apart from testing run-time behavior of applications proposed work can be used to warn app developers about unintentional security holes.
机译:发送的移动应用程序是哪种类型的用户数据?在网上商店上提供的普遍的移动应用程序,大多数用户都没有意识到他们可能姿势的安全风险。这些包括通过在没有用户批准的情况下将未加密的私人和敏感数据分享到应用程序自己的服务器或第三方来违反最终用户的隐私。在这项研究中,我们通过网络渗透动态地测试了70个IOS应用程序。其中,20个应用程序是流行的社交网络和消息传递应用程序。分析了它们的运行时行为,其网络迹线用于重建应用层有效载荷。在20分中的大约15个应用中,我们能够追踪并重建整个消息内容,用户的位置,电子邮件凭据(包括密码),社交网络凭据,配置文件图像或推文消息中的至少一个。除此之外,捕获了50个IOS应用程序的网络流量,以检查最终用户的数据如何在网络上共享。特别地发现,许多应用程序以未加密的形式共享App用户的授权/未经授权的信息。除了测试应用程序的运行时行为之外,建议的工作可用于警告应用程序开发人员关于无意的安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号