A client-side analysis of TLS usage in mobile apps
نویسندگان
چکیده
As mobile applications become more pervasive, they provide us with a variety of online services that range from social networking to banking and credit card management. Since many of these services involve communicating and handling of private user information – and also due to increasing security demands from users – the use of TLS connections has become a necessity for today’s mobile applications. However, an improper use of TLS and failure to adhere to TLS security guidelines by app developers, exposes users to agents performing TLS interception thus giving them a false sense of security. Unfortunately, researchers and users alike lack of information and easy-to-deploy mechanisms to analyze how securely mobile apps implement TLS. Hence, in order to understand and assess the security of mobile app communications, it is crucial to study their use of the TLS protocol. In this poster we present a method to study the use of TLS in mobile apps using the data provided by the ICSI Haystack app [2], a mobile measurement platform that enables on-device analysis of mobile traffic without requiring root access. The unique vantage point provided by the Haystack platform enables a variety of measurements from the edge of the network with real user workload and the added bonus of having contextual information on the device to supplement the data collection.
منابع مشابه
LinkDroid: Reducing Unregulated Aggregation of App Usage Behaviors
Usage behaviors of different smartphone apps capture different views of an individual’s life, and are largely independent of each other. However, in the current mobile app ecosystem, a curious party can covertly link and aggregate usage behaviors of the same user across different apps. We refer to this as unregulated aggregation of appusage behaviors. In this paper, we present a fresh perspecti...
متن کاملFactors Influencing Professional Nurses’ Acceptance and Use of Mobile Medical Apps in Ghana
The use of mobile medical apps in clinical settings has recently received considerable attention. While some practitioners are using this technology to optimize decision making, others, on the other hand, are indifferent about its usage. Therefore, this study has utilized a modified UTAUT2 model to determine factors that influence the acceptance and use of mobile medical apps among professional...
متن کاملMobSafe: Cloud Computing based Forensic Analysis for Massive Mobile Applications using Data Mining
With the explosive increase in Mobile apps, more and more threats migrate from traditional PC client to mobile device. Compared with traditional Win+Intel alliance in PC, Android+ARM alliance dominates in Mobile Internet, the apps replace the PC client software as the major target of malicious usage. In this paper, to improve the security status of current mobile apps, we propose a methodology ...
متن کاملEvaluating ELT Materials: A Comparison between Traditional Materials and Mobile Apps
This study attempted to evaluate and compare language learning apps and the related traditional books on the same subject. The apps included Murphy’s English Grammar and Cambridge Discovery Readers and the traditional materials were English Grammar in Use and Developing Reading Skills. The study, thus, aimed to do a comparative analysis between traditional ELT materials and the digital versions...
متن کاملEvaluating ELT Materials: A Comparison between Traditional Materials and Mobile Apps
This study attempted to evaluate and compare language learning apps and the related traditional books on the same subject. The apps included Murphy’s English Grammar and Cambridge Discovery Readers and the traditional materials were English Grammar in Use and Developing Reading Skills. The study, thus, aimed to do a comparative analysis between traditional ELT materials and the digital versions...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016