skip to main content
10.1145/2508859.2516655acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
research-article

Rethinking SSL development in an appified world

Published: 04 November 2013 Publication History

Abstract

The Secure Sockets Layer (SSL) is widely used to secure data transfers on the Internet. Previous studies have shown that the state of non-browser SSL code is catastrophic across a large variety of desktop applications and libraries as well as a large selection of Android apps, leaving users vulnerable to Man-in-the-Middle attacks (MITMAs). To determine possible causes of SSL problems on all major appified platforms, we extended the analysis to the walled-garden ecosystem of iOS, analyzed software developer forums and conducted interviews with developers of vulnerable apps. Our results show that the root causes are not simply careless developers, but also limitations and issues of the current SSL development paradigm. Based on our findings, we derive a proposal to rethink the handling of SSL in the appified world and present a set of countermeasures to improve the handling of SSL using Android as a blueprint for other platforms. Our countermeasures prevent developers from willfully or accidentally breaking SSL certificate validation, offer support for extended features such as SSL Pinning and different SSL validation infrastructures, and protect users. We evaluated our solution against 13,500 popular Android apps and conducted developer interviews to judge the acceptance of our approach and found that our solution works well for all investigated apps and developers.

References

[1]
P. P. F. Chan, L. C. K. Hui, and S. M. Yiu. DroidChecker: Analyzing Android Applications for Capability Leaks. In WISEC '12: Proceedings of the Fifth ACM Conference on Security and Privacy in Wireless and Mobile Networks. ACM Press, Apr. 2012.
[2]
L. Davi, A. Dmitrienko, A. Sadeghi, and M. Winandy. Privilege Escalation Attacks on Android. In Proceedings of the 13th International Conference on Information Security, pages 346--360, 2011.
[3]
P. Eckersley. Sovereign Key Cryptography for Internet Domains. https://git.eff.org/?p=sovereign-keys.git;a=blob;f=sovereign-key-design.txt;hb=master.
[4]
A. Egners, B. Marschollek, and U. Meyer. Messing with Android's Permission Model. In Proceedings of the IEEE TrustCom, pages 1--22, Apr. 2012.
[5]
S. Fahl, M. Harbach, T. Muders, L. Baumg\"artner, B. Freisleben, and M. Smith. Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security. In Proceedings of the 19th ACM Conference on Computer and Communications Security. ACM Press, Oct. 2012.
[6]
A. Felt, E. Ha, S. Egelman, A. Haney, E. Chin, and D. Wagner. Android Permissions: User Attention, Comprehension, and Behavior. In Proceedings of the Eighth Symposium on Usable Privacy and Security. ACM Press, 2012.
[7]
A. P. Felt, E. Chin, S. Hanna, D. Song, and D. Wagner. Android permissions Demystified. In Proceedings of the 18th ACM Conference on Computer and Communications Security. ACM Press, Oct. 2011.
[8]
M. Georgiev, S. Iyengar, S. Jana, R. Anubhai, D. Boneh, and V. Shmatikov. The Most Dangerous Code in the World: Validating SSL Certificates in Non-Browser Software. In Proceedings of the 2012 ACM Conference on Computer and Communications security. ACM Press, Oct. 2012.
[9]
P. Hoffman and J. Schlyter. The DNS-Based Authentication of Named Entities (DANE) Protocol for Transport Layer Security (TLS): TLSA . https://tools.ietf.org/html/rfc6698, Aug. 2012.
[10]
T. Hyun-Jin Kim, L.-S. Huang, A. Perrig, C. Jackson, and V. Gligor. Accountable Key Infrastructure (AKI): A Proposal for a Public-Key Validation Infrastructure. In Proceedings of the 2013 Conference on World Wide Web, to appear, 2013.
[11]
B. Laurie, A. Langley, and E. Kasper. Certificate Transparency. Network Working Group Internet-Draft, v12, work in progress. http://tools.ietf.org/html/draft-laurie-pki-sunlight-12, Apr. 2013.
[12]
M. Marlinspike. TACK: Trust Assertions for Certificate Keys. http://tack.io/draft.html.
[13]
M. Marlinspike. SSL And The Future Of Authenticity. In BlackHat USA 2011, 2011.
[14]
P. Saint-Andre and J. Hodges. RFC 6125, Mar. 2011.
[15]
R. Schlegel, K. Zhang, X. Zhou, M. Intwala, and e. al. Soundcomber: A Stealthy and Context-aware Sound Trojan for Smartphones. Proceedings of the Network and Distributed System Security Symposium, 2011.
[16]
J. Sunshine, S. Egelman, H. Almuhimedi, N. Atri, and L. Cranor. Crying Wolf: An Empirical Study of SSL Warning Effectiveness. In Proceedings of the 18th USENIX Security Symposium, pages 399--416, 2009.
[17]
T. Vidas, D. Votipka, and N. Christin. All Your Droid Are Belong To Us: A Survey Of Current Android Attacks. In Proceedings of the 5th USENIX Workshop on Offensive Technologies, pages 10--10, 2011.
[18]
D. Wendlandt, D. G. Andersen, and A. Perrig. Perspectives: improving ssh-style host authentication with multi-path probing. In USENIX 2008 Annual Technical Conference on Annual Technical Conference, ATC'08, pages 321--334, Berkeley, CA, USA, 2008. USENIX Association.
[19]
Y. Zhou and X. Jiang. Dissecting android malware: Characterization and evolution. In Security and Privacy (SP), 2012 IEEE Symposium on, pages 95--109, 2012.

Cited By

View all

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Conferences
CCS '13: Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security
November 2013
1530 pages
ISBN:9781450324779
DOI:10.1145/2508859
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 04 November 2013

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. SSL
  2. android
  3. apps
  4. ios
  5. mitma
  6. security

Qualifiers

  • Research-article

Conference

CCS'13
Sponsor:

Acceptance Rates

CCS '13 Paper Acceptance Rate 105 of 530 submissions, 20%;
Overall Acceptance Rate 1,261 of 6,999 submissions, 18%

Upcoming Conference

CCS '25

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)68
  • Downloads (Last 6 weeks)7
Reflects downloads up to 20 Jan 2025

Other Metrics

Citations

Cited By

View all

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media