节点文献

移动终端环境若干典型协议的安全分析技术研究

Research on Security Analysis Technologies of Several Typical Protocols on Smart Mobile Devices

【作者】 王晖;

【导师】 谷大武;

【作者基本信息】 上海交通大学 , 信息安全与密码学, 2020, 博士

【摘要】 随着移动智能终端和移动互联网的迅速发展,大量厂商在移动平台提供社交网络、电子商务、即时通信等多种服务,将用户的身份信息与设备紧密绑定,很多安全敏感的数据都在移动平台上传输。但同时,把移动智能终端作为处理移动业务和存储用户个人信息的载体也带来了很大的安全隐患,每年由于移动智能设备安全问题引发的信息泄漏、诱骗欺诈造成的经济损失高达百亿。而导致这些安全问题的一个主要因素是移动智能设备通信协议安全的脆弱性。移动智能终端所使用的各类通信协议需要能够保障通信信道的安全性及用户个人信息的机密性、完整性,这些通信协议往往是建立在密码体制基础上,使用密码算法和协议逻辑来实现安全目标。但是现实生活中通信协议的设计、实现常常不能满足规定的安全需求,近年来曝出的重大安全漏洞中很大一部分与通信协议有关。移动智能终端中所使用的安全传输协议,认证授权协议,虚拟专用网络协议等通信协议受到越来越多的关注,它们的安全性研究也成为学术领域的最为重要的研究课题之一。本文的研究主要围绕移动智能终端开放授权协议的安全性分析、单点登录协议的安全性分析、单点登录系统安全性分析和虚拟专用网络协议安全性分析四个方面展开。针对移动智能终端开放授权协议的实现,我们提出了一种基于模型匹配的安全审计方法,并设计实现了一个系统化的安全审计框架。针对应用OAuth协议作为三方认证协议的单点登录系统实现,我们提出了一种由不同攻击者视角引导的分析方案,能够识别OAuth应用在实现单点登录时在不同阶段引入的安全漏洞。针对基于OIDC协议构建的单点登录系统的实现安全性,我们提出了一种自动化差分流量分析方案,能够有效检测单点登录系统中服务器端存在的安全和隐私问题。最后,针对移动平台虚拟专用网络协议的实现,我们提出了代码分析和流量分析结合的分析方案,可以从SSL/TLS协议实现、OpenVPN客户端配置、协议代码实现三个方面系统分析协议实现的安全性。本文的主要贡献如下:1.对于Android平台上的OAuth协议实现,提出了一种基于模型匹配的安全分析方法。我们提出的五方模型能够包含协议流程中涉及的所有参与者,并覆盖协议生命周期的全部3个阶段。同时,我们设计实现了一个系统化的安全审计框架。该框架能够半自动化地审计Android应用中5种典型的错误实现。我们利用该框架对中国Android应用市场中的1300多个实现了OAuth协议的应用进行分析,发现86%的应用存在至少一种安全漏洞。2.针对基于OAuth协议的单点登录方案,设计了一种由不同攻击者视角引导的分析方法。该方法能够对Web、Android和i OS平台上使用OAuth协议进行用户身份认证的应用进行分析,自动化提取协议规范,并识别现实应用在认证凭据选择、认证凭据传输和服务器校验阶段可能存在的5类漏洞。我们对这3个平台上650个最流行的应用进行分析,发现这3个平台分别有32.9%,47.1%,41.6%的应用存在安全漏洞。同时我们分析了这些漏洞产生的根本原因以帮助指导开发者设计更安全的认证方案。3.针对基于OpenID Connect协议的单点登录系统,提出了一种自动化差分流量分析方案,通过检测服务提供商和服务使用商的服务器端实现,分析单点登录系统中访问控制机制的安全和隐私保护问题。我们对Google Play和应用宝两个Android应用市场中的400个流行应用以及8个流行SSO服务提供商进行分析,发现四类新型漏洞,62.5%的服务提供商和31.9%的流行应用的服务器端实现存在至少一种安全漏洞,破坏了系统访问控制的安全性。我们进一步分析了这些漏洞的产生原因并提出了相应修复方案。4.针对移动智能终端的OpenVPN协议实现,提出了静态代码分析和动态流量分析相结合的分析方法。该方法能够从SSL/TLS协议实现、OpenVPN客户端配置、协议代码实现这三个方面分析Android平台流行VPN应用的安全性。我们的分析发现了4类新型漏洞:SSL/TLS协议加固缺失、客户端密码算法误用、客户端弱认证、服务器端弱认证,我们对Google Play应用市场中102个OpenVPN应用进行了测试,测试结果表明42.9%的应用至少存在一种安全漏洞,能够导致通信被中间人攻击或者加密流量被解密。

【Abstract】 With the rapid development of smart mobile devices and mobile Internet,large numbers of Internet companies provide social networking,ecommerce,mobile payment and many other services on the mobile platform.Users’ identity information are bound to their mobile devices,and lots of security sensitive data are transmitted through the mobile platform.However,using smart mobile devices for handling mobile services and storing personal information of users can pose a great security risk.The annual economic losses caused by fraudulent fraud and information leakage are as high as tens of billions of dollars due to security problems of smart mobile devices.A major factor contributing to these security issues is the vulnerability of the communication protocols used on smart mobile devices.The various communication protocols used on smart mobile devices need to be able to guarantee the security of the communication channel and the confidentiality and integrity of the user’s personal information.Generally,they are based on cryptosystem,using cryptographic algorithms and protocol logic to achieve security goals.However,the design and implementation of communication protocols in real life often fail to meet the specified security requirements.A large part of the major security vulnerabilities exposed in recent years are related to communications protocols.Popular communication protocols such as the secure transmission protocols,authentication and authorization protocols,and virtual private network protocols used on smart mobile devices are receiving more and more attention.The security research of these protocols has become one of the most important research topics in the academic field.This paper mainly focuses on the security analysis of the open authorization protocol and the virtual private network protocol used on the mobile platform,and the security analysis of the Single Sign-On systems.First,we propose a model-based analysis method to analyze the security of the OAuth implementation on the Android platform,and implement a systematic vulnerability assessment framework to audit the OAuth implementations in real world Android applications.Second,we propose an attacker-guided analysis method to identify the vulnerabilities introduced by developers when implementing OAuth for authentication in Android applications.Third,we propose a differential traffic analysis method to automatically identify the security and privacy problems existed on the server-side implementations of the Single Sign-On systems.Finally,we combine static code analysis and dynamic traffic analysis to assess the security of the OpenVPN implementations in Android applications.Our analysis method is able to identify vulnerabilities of OpenVPN applications in the aspects of SSL/TLS implementation,cryptographic algorithm implementation,authentication.The main contributions of this dissertation are:1.A model-based security analysis method is proposed.To analyze the security of OAuth implementations on the Android platform,we propose a five-party,three-stage model to detect vulnerabilities of popular OAuth implementation in Android apps.We also design and implement a systematic vulnerability assessment framework for OAuth implementations on Android platform.Our assessment can cover all the three phases in an OAuth transaction and detect five typical incorrect OAuth implementations in Android applications.Our analysis show that 86.2% of the apps incorporating OAuth services in the Myapp Android app market are vulnerable.2.An attacker-guided security analysis method is proposed.To analyze the security of the OAuth-based authentication mechanisms used by real world websites and mobile applications,we dissect the traffic from different attackers’ perspectives to recover the authentication mechanisms employed by websites and apps,and identify exploitable vulnerabilities.Our analysis shows that 32.9%,47.1%,41.6% of the analyzed authentication mechanisms on the Web,Android,i OS platform are vulnerable.We also categorize the root causes of these vulnerabilities and make practical recommendations for developers.This is the first security study of OAuth-based authentication mechanisms on multi-platforms,including Web,Android and i OS.3.A novel differential traffic analysis method is proposed.To analyze the security of the server-side implementations of real world SSO systems,we employ a set of lightweight techniques including differential traffic analysis,fuzzing test,protocol field semantic inference,to extract the protocol specifications and pinpoint exploitable vulnerabilities,and we discover four novel vulnerabilities.Our study shows that the uncovered vulnerabilities exist prevalently in the server-side implementations of real world SSO systems,62.5% of the tested identity providers and 31.9% of the SSO-capable applications suffer from at least one security flaw.4.An in-depth security analysis of OpenVPN implementation on Android platform is conducted.We combine the static code analysis and dynamic traffic analysis method to analyze the OpenVPN implementations in Android applications.Our methodology is capable to identify vulnerabilities of OpenVPN in the aspects of code implementation,client profile and permission management.We discover four previously unknown vulnerabilities: problematic SSL/TLS implementation,insecure cryptographic algorithm implementation,weak client authentication,weak server authentication.We analyze 102 OpenVPN apps in Google Play and 42.9% of them suffer from at least one vulnerability,which can lead to man-in-the-middle attack or traffic decryption.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络