首页> 外文会议>International workshop on structured object-oriented formal language and method >E-SSL: An SSL Security-Enhanced Method for Bypassing MITM Attacks in Mobile Internet
【24h】

E-SSL: An SSL Security-Enhanced Method for Bypassing MITM Attacks in Mobile Internet

机译:E-SSL:一种用于移动Internet中绕过MITM攻击的SSL安全性增强方法

获取原文

摘要

In mobile internet, the Secure Sockets Layer (SSL) validation vulnerabilities of applications can be easily exploited through SSL Man-in-the-Middle (MITM) attacks, which are difficult to defeat. In this paper, an SSL Security-Enhanced method (E-SSL) is proposed to detect and defeat SSL MITM attacks, which improves the security of internet communication under malicious attacks. SSL proxy is used to find SSL certificate validation vulnerabilities and detect SSL MITM attacks. Based on randomness and hash theory, an SSL shared service with random port mapping is implemented to bypass SSL MITM attacks, the spatio-temporal randomization will increase the difficulty of attacker's correct guessing. We implement a prototype on Android platform, and verify its effectiveness and reliability with 650 apps under realistic SSL MITM attacks. Using the E-SSL approach, 185 apps out of 650 are detected with SSL certificate validation vulnerabilities. Furthermore, evaluation results show that the E-SSL approach enables these SSL certificate validation vulnerabilities apps to successfully bypass SSL MITM attacks, thus significantly increases the security of user data privacy in public mobile internet.
机译:在移动互联网中,可以通过难以克服的SSL中间人(MITM)攻击轻松利用应用程序的安全套接字层(SSL)验证漏洞。本文提出了一种SSL安全增强方法(E-SSL)来检测和消除SSL MITM攻击,从而提高了恶意攻击下Internet通信的安全性。 SSL代理用于查找SSL证书验证漏洞并检测SSL MITM攻击。基于随机性和哈希理论,实现了具有随机端口映射的SSL共享服务来绕过SSL MITM攻击,时空随机化将增加攻击者正确猜测的难度。我们在Android平台上实现了一个原型,并在真实的SSL MITM攻击下使用650个应用验证了其有效性和可靠性。使用E-SSL方法,使用SSL证书验证漏洞检测到650个应用程序中的185个。此外,评估结果表明,E-SSL方法使这些SSL证书验证漏洞应用程序能够成功绕过SSL MITM攻击,从而显着提高了公共移动互联网中用户数据隐私的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号