首页> 外文OA文献 >MITHYS: Mind The Hand You Shake - Protecting Mobile Devices from SSL Usage Vulnerabilities
【2h】

MITHYS: Mind The Hand You Shake - Protecting Mobile Devices from SSL Usage Vulnerabilities

机译:mITHYs:记住你动摇的手 - 保护移动设备免受ssL使用漏洞的侵害

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Recent studies have shown that a significant number of mobile applications, often handling sensitive data such as bank accounts and login credentials, suffers from SSL vulnerabilities. Most of the time, these vulnerabilities are due to improper use of the SSL protocol (in particular, in its handshake phase), resulting in applications exposed to man-in-the-middle attacks. In this paper, we present MITHYS, a system able to: (i) detect applications vulnerable to man-in-the-middle attacks, and (ii) protect them against these attacks. We demonstrate the feasibility of our proposal by means of a prototype implementation in Android, named MITHYSApp. A thorough set of experiments assesses the validity of our solution in detecting and protecting mobile applications from man-in-the-middle attacks, without introducing significant overheads. Finally, MITHYSApp does not require any special permissions nor OS modifications, as it operates at the application level. These features make MITHYSApp immediately deployable on a large user base.
机译:最近的研究表明,大量的移动应用程序通常处理诸如银行帐户和登录凭据之类的敏感数据,遭受SSL漏洞。大多数时候,这些漏洞是由于SSL协议的使用不当(特别是在其握手阶段),导致申请暴露于中间人攻击。在本文中,我们呈现了一个能够:(i)检测容易受到中间攻击的应用程序,并保护它们免受这些攻击。我们通过Android的原型实现展示了我们提案的可行性,名为MithySApp。彻底的一组实验评估了我们在从中间人攻击中检测和保护移动应用方面的解决方案的有效性,而不会引入显着的开销。最后,MithysApp不需要任何特殊权限,也不需要OS修改,因为它在应用程序级别运行。这些功能使MITHYSAPP能够在大型用户群上部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号