首页> 外文会议>International conference on cryptology and network security >Oh-Pwn-VPN! Security Analysis of Open VPN-Based Android Apps
【24h】

Oh-Pwn-VPN! Security Analysis of Open VPN-Based Android Apps

机译:Oh-Pwn-VPN!基于开放VPN的Android应用程序的安全性分析

获取原文

摘要

Free VPN apps have gained popularity among millions of users due to their convenience, and have been massively used for accessing blocked sites and preventing network eavesdropping. As a popular open-source VPN solution, OpenVPN is widely used by developers to implement their own VPN services. Despite the prevalence of OpenVPN, it can be insecurely customized and deployed by developers in lack of security guide. In this paper, we perform a systematic security analysis of 84 popular OpenVPN-based apps on the Google Play store. We analyze the deployment security of OpenVPN on Android from the aspects of client profile, code implementation, and permission management. Our experiment reveals three types of misconfigurations that exist in several apps: insecure customized protocols, weak authentication at the client side, and incorrect file permissions on Android. The misconfigurations found by us can lead to some serious attacks, such as VPN traffic decryption and Man-in-the-Middle attacks, endangering millions of users' privacy. Our work shows that, although OpenVPN protocol itself has withstood security analysis, insecure custom modification and configuration can still compromise the security of VPN apps. We then discuss potential causes of these misconfigurations and make practical recommendations for developers to securely deploy OpenVPN services.
机译:免费VPN应用程序由于其便利性而在数百万用户中广受欢迎,并且已被广泛用于访问被阻止的站点和防止网络窃听。作为一种流行的开源VPN解决方案,开发人员广泛使用OpenVPN来实现自己的VPN服务。尽管OpenVPN盛行,但在缺乏安全指导的情况下,开发人员可能无法安全地对其进行自定义和部署。在本文中,我们对Google Play商店上的84种流行的基于OpenVPN的应用程序进行了系统的安全性分析。我们从客户端配置文件,代码实现和权限管理等方面分析了Android上OpenVPN的部署安全性。我们的实验揭示了几种应用程序中存在的三种错误配置类型:不安全的自定义协议,客户端的弱身份验证以及Android上不正确的文件权限。我们发现的错误配置会导致一些严重的攻击,例如VPN流量解密和中间人攻击,危及数百万用户的隐私。我们的工作表明,尽管OpenVPN协议本身已经经受了安全性分析,但不安全的自定义修改和配置仍会损害VPN应用程序的安全性。然后,我们讨论这些错误配置的潜在原因,并为开发人员安全部署OpenVPN服务提出实用建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号