首页> 外文期刊>International Journal of Computer Network and Information Security >Assessing Vulnerability of Mobile Messaging Apps to Man-in-the-Middle (MitM) Attack
【24h】

Assessing Vulnerability of Mobile Messaging Apps to Man-in-the-Middle (MitM) Attack

机译:评估移动消息应用程序对中间人(MitM)攻击的漏洞

获取原文
           

摘要

Mobile apps are gaining in popularity and are becoming an indispensable part of our digital lives. Several mobile apps (such as messaging apps) contain personal/private information of the users. Inevitably, the compromise of accounts associated with such sensitive apps can result in disastrous consequences for the end user. Recently, Password Reset Man-in-the-Middle (PRMitM) attack was proposed at the application level in which an attacker can take over a user’s web account while the user is trying to access/download resources from the attacker’s website. In this work, we adapt this attack so that it can be applied in the context of mobile messaging apps. Specifically, we analyze 20 popular mobile messaging apps for vulnerability to MitM attack, 10 of which support secure communication through end-to-end encryption. Based on our holistic analysis, we have identified 10 of the tested apps as being vulnerable to MitM attack and elaborated on the corresponding attack scenarios. On comparing the secure messaging apps to non-secure messaging apps for vulnerability to MitM attack, we found that an app’s features and design choices decide if it is susceptible to MitM attack irrespective of whether it provides end-to-end encryption or not. Further, we have proposed design improvements to increase the overall security of all mobile messaging apps against MitM attack.
机译:移动应用程序越来越流行,并且已成为我们数字生活中不可或缺的一部分。几个移动应用程序(例如消息传递应用程序)包含用户的个人/私人信息。不可避免地,与此类敏感应用程序相关联的帐户的泄露可能会给最终用户带来灾难性的后果。最近,在应用程序级别提出了密码重置中间人(PRMitM)攻击,攻击者可以在用户试图从攻击者的网站访问/下载资源时接管其Web帐户。在这项工作中,我们适应了这种攻击,以便可以将其应用于移动消息传递应用程序的上下文中。具体来说,我们分析了20种流行的移动消息传递应用程序是否存在MitM攻击漏洞,其中10种支持通过端到端加密进行安全通信。根据我们的整体分析,我们确定了10个经过测试的应用程序容易受到MitM攻击,并详细说明了相应的攻击场景。在比较安全消息传递应用程序与非安全消息传递应用程序是否受到MitM攻击的脆弱性时,我们发现,应用程序的功能和设计选择决定了它是否容易受到MitM攻击,而与是否提供端到端加密无关。此外,我们提出了改进设计的建议,以提高所有移动消息应用程序抵抗MitM攻击的总体安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号