MyJournals Home  

RSS FeedsEntropy, Vol. 21, Pages 1136: A Framework to Secure the Development and Auditing of SSL Pinning in Mobile Applications: The Case of Android Devices (Entropy)

 
 

21 november 2019 19:02:48

 
Entropy, Vol. 21, Pages 1136: A Framework to Secure the Development and Auditing of SSL Pinning in Mobile Applications: The Case of Android Devices (Entropy)
 




The use of mobile devices has undergone rapid growth in recent years. However, on some occasions, security has been neglected when developing applications. SSL/TLS has been used for years to secure communications although it is not a vulnerability-free protocol. One of the most common vulnerabilities is SSL pinning bypassing. This paper first describes some security controls to help protect against SSL pinning bypassing. Subsequently, some existing methods for bypassing are presented and two new methods are defined. We performed some experiments to check the use of security controls in widely used applications, and applied SSL pinning bypassing methods. Finally, we created an applicability framework, relating the implemented security controls and the methods that are applicable. This framework provides a guideline for pentesters and app developers.


Del.icio.us Digg Facebook Google StumbleUpon Twitter
 
22 viewsCategory: Informatics, Physics
 
Entropy, Vol. 21, Pages 1137: Influence of the Coupling between Two Qubits in an Open Coherent Cavity: Nonclassical Information via Quasi-Probability Distributions (Entropy)
Entropy, Vol. 21, Pages 1135: A Novel Infrared and Visible Image Information Fusion Method Based on Phase Congruency and Image Entropy (Entropy)
 
 
blog comments powered by Disqus


MyJournals.org
The latest issues of all your favorite science journals on one page

Username:
Password:

Register | Retrieve

Search:

Physics

Use these buttons to bookmark us:
Del.icio.us Digg Facebook Google StumbleUpon Twitter


Valid HTML 4.01 Transitional
Copyright © 2008 - 2019 Indigonet Services B.V.. Contact: Tim Hulsen. Read here our privacy notice.
Other websites of Indigonet Services B.V.: Nieuws Vacatures News Tweets Travel Photos Nachrichten Indigonet Finances Leer Mandarijn