MITHYS: Mind the hand you shake - Protecting mobile devices from SSL usage vulnerabilities

21Citations
Citations of this article
18Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Recent studies have shown that a significant number of mobile applications, often handling sensitive data such as bank accounts and login credentials, suffers from SSL vulnerabilities. Most of the time, these vulnerabilities are due to improper use of the SSL protocol (in particular, in its handshake phase), resulting in applications exposed to man-in-the-middle attacks. In this paper, we present MITHYS, a system able to: (i) detect applications vulnerable to man-in-the-middle attacks, and (ii) protect them against these attacks. We demonstrate the feasibility of our proposal by means of a prototype implementation in Android, named MITHYSApp. A thorough set of experiments assesses the validity of our solution in detecting and protecting mobile applications from man-in-the-middle attacks, without introducing significant overheads. Finally, MITHYSApp does not require any special permissions nor OS modifications, as it operates at the application level. These features make MITHYSApp immediately deployable on a large user base. © 2013 Springer-Verlag.

Cite

CITATION STYLE

APA

Conti, M., Dragoni, N., & Gottardo, S. (2013). MITHYS: Mind the hand you shake - Protecting mobile devices from SSL usage vulnerabilities. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8203 LNCS, pp. 65–81). https://doi.org/10.1007/978-3-642-41098-7_5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free