Dergiler / Gazi Üniversitesi Fen Bilimleri Dergisi Part C: Tasarım ve Teknoloji / 2021 / Cilt: 9 - Sayı: 2

Detection of SSL/TLS Implementation Errors in Android Applications

Sayfa
211–219
DOI
—

Özet

Security Socket Layer (SSL) / Transport Layer Security (TLS) protocols are utilized to securenetwork communication (e.g., transmitting user data). Failing to properly implement SSL/TLSconfiguration during the app development results in security risks. The weak implementationsinclude trusting all host names, trusting all certificates, ignoring certificate verification errors,even lack of SSL public key pinning usage. These unsecured implementations may cause ManIn-The-Middle (MITM) attacks. The major aim of this research is to detect configuration errorsof SSL/TLS implementation in Android apps. It consists of the common use of existing opensource tools in the static analysis phase and the combination of manual method in the dynamicanalysis phase. During the static analysis phase, dynamic analysis of the findings obtained byscanning four types of vulnerabilities is used to verify the abuse status of SSL/TLS by testing.The dynamic analysis is essential for eliminating false positives generated at the static analysisstage. We analyze 109 apps from Google Play Store and the experimental results show that 45(41.28%) apps contain potential security errors in the application of SSL/TLS. We verify that 19(17.43%) out of 109 apps are vulnerable to MITM attacks.