{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T12:35:42Z","timestamp":1725885342857},"publisher-location":"Cham","reference-count":31,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319577074"},{"type":"electronic","value":"9783319577081"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-57708-1_7","type":"book-chapter","created":{"date-parts":[[2017,4,20]],"date-time":"2017-04-20T08:03:37Z","timestamp":1492675417000},"page":"101-120","source":"Crossref","is-referenced-by-count":0,"title":["E-SSL: An SSL Security-Enhanced Method for Bypassing MITM Attacks in Mobile Internet"],"prefix":"10.1007","author":[{"given":"Ren","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaohong","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guangquan","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiyong","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianye","family":"Hao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,4,21]]},"reference":[{"key":"7_CR1","doi-asserted-by":"publisher","unstructured":"Song, Y., Yang, C., Gu, G.: Who is peeping at your passwords at Starbucks? To catch an evil twin access point. In: IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 323\u2013332. IEEE (2010)","DOI":"10.1109\/DSN.2010.5544302"},{"key":"7_CR2","doi-asserted-by":"crossref","unstructured":"Freier, A., Karlton, P., Kocher, P.: The secure sockets layer (SSL) protocol version 3.0 (2011)","DOI":"10.17487\/rfc6101"},{"key":"7_CR3","doi-asserted-by":"crossref","unstructured":"Dierks, T., Rescorla, E.: The transport layer security (TLS) protocol version 1.2 (2008)","DOI":"10.17487\/rfc5246"},{"key":"7_CR4","doi-asserted-by":"publisher","unstructured":"Fahl, S., Harbach, M., Muders, T.: Why eve and mallory love android: an analysis of android SSL (in) security. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 50\u201361. ACM (2012)","DOI":"10.1145\/2382196.2382205"},{"key":"7_CR5","doi-asserted-by":"crossref","unstructured":"Clark, J., van Oorschot, P.C.: SoK: SSL and HTTPS: revisiting past challenges and evaluating certificate trust model enhancements. In: Security and Privacy (SP), pp. 511\u2013525. IEEE (2013)","DOI":"10.1109\/SP.2013.41"},{"key":"7_CR6","volume-title":"Temporal Logic and Temporal Logic Programming","author":"Z Duan","year":"2005","unstructured":"Duan, Z.: Temporal Logic and Temporal Logic Programming. Science Press, Beijing (2005)"},{"issue":"1","key":"7_CR7","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1007\/s00236-007-0062-z","volume":"45","author":"Z Duan","year":"2008","unstructured":"Duan, Z., Tian, C., Zhang, L.: A decision procedure for propositional projection temporal logic with infinite models. Acta Informatica 45(1), 43\u201378 (2008)","journal-title":"Acta Informatica"},{"key":"7_CR8","doi-asserted-by":"publisher","unstructured":"Egners, A., Marschollek, B., Meyer, U.: Messing with Android\u2019s permission model. In: Proceedings of the IEEE TrustCom, pp. 1\u201322 (2012)","DOI":"10.1109\/TrustCom.2012.203"},{"key":"7_CR9","unstructured":"Bugiel, S., Davi, L., Dmitrienko, A., Fischer, T., Sadeghi, A.-R., Shastry, B.: Towards taming privilege-escalation attacks on android. In: Proceedings of NDSS (2012)"},{"key":"7_CR10","doi-asserted-by":"crossref","unstructured":"Becher, M., Freiling, F., Hoffmann, J., Holz, T., Uellenbeck, S., Wolf, C.: Mobile security catching up? revealing the nuts and bolts of the security of mobile devices. In: IEEE Security and Privacy (SP), pp. 96\u2013111 (2011)","DOI":"10.1109\/SP.2011.29"},{"key":"7_CR11","unstructured":"Marlinspike, M.: New tricks for defeating SSL in practice. In: BlackHat DC, February 2009"},{"key":"7_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/978-3-319-21966-0_9","volume-title":"Information and Communications Security","author":"H Liu","year":"2015","unstructured":"Liu, H., Zhang, Y., Wang, H., Yang, W., Li, J., Gu, D.: TagDroid: hybrid SSL certificate verification in android. In: Hui, L.C.K., Qing, S.H., Shi, E., Yiu, S.M. (eds.) ICICS 2014. LNCS, vol. 8958, pp. 120\u2013131. Springer, Cham (2015). doi: 10.1007\/978-3-319-21966-0_9 . 16th International Conference, ICICS 2014, Hong Kong, China, December 16-17, 2014"},{"key":"7_CR13","doi-asserted-by":"publisher","unstructured":"Sounthiraraj, D., Sahs, J., Greenwood, G.: Smv-hunter: large scale, automated detection of SSL\/TLS man-in-the-middle vulnerabilities in android apps. In: Proceedings of the 21st Annual Network and Distributed System Security Symposium (2014)","DOI":"10.14722\/ndss.2014.23205"},{"key":"7_CR14","doi-asserted-by":"publisher","unstructured":"Durumeric, Z., Kasten, J., Bailey, M.: Analysis of the HTTPS certificate ecosystem. In: Proceedings of the 2013 Conference on Internet Measurement Conference, pp. 291\u2013304. ACM (2013)","DOI":"10.1145\/2504730.2504755"},{"key":"7_CR15","doi-asserted-by":"publisher","unstructured":"Holz, R., Braun, L., Kammenhuber, N.: The SSL landscape: a thorough analysis of the x.509 PKI using active and passive measurements. In: Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement Conference, pp. 427\u2013444. ACM (2011)","DOI":"10.1145\/2068816.2068856"},{"key":"7_CR16","doi-asserted-by":"publisher","unstructured":"Akhawe, D., Amann, B., Vallentin, M.: Here\u2019s my cert, so trust me, maybe? understanding TLS errors on the web. In: Proceedings of the 22nd International Conference on World Wide Web, pp. 59\u201370. International World Wide Web Conferences Steering Committee (2013)","DOI":"10.1145\/2488388.2488395"},{"key":"7_CR17","doi-asserted-by":"publisher","unstructured":"Huang, L.S., Rice, A., Ellingsen, E.: Analyzing forged SSL certificates in the wild. In: Security and Privacy (SP), pp. 83\u201397. IEEE (2014)","DOI":"10.1109\/SP.2014.13"},{"key":"7_CR18","doi-asserted-by":"publisher","unstructured":"Georgiev, M., Iyengar, S., Jana, S.: The most dangerous code in the world: validating SSL certificates in non-browser software. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 38\u201349. ACM (2012)","DOI":"10.1145\/2382196.2382204"},{"key":"7_CR19","doi-asserted-by":"publisher","unstructured":"Zheng, C., Zhu, S., Dai, S.: Smartdroid: an automatic system for revealing ui-based trigger conditions in android applications. In: Proceedings of the Second ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, pp. 93\u2013104. ACM (2012)","DOI":"10.1145\/2381934.2381950"},{"key":"7_CR20","doi-asserted-by":"publisher","unstructured":"Zuo, C., Wu, J., Guo, S.: Automatically detecting SSL error-handling vulnerabilities in hybrid mobile web apps. In: Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, pp. 591\u2013596. ACM (2015)","DOI":"10.1145\/2714576.2714583"},{"issue":"1","key":"7_CR21","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1016\/j.scico.2007.09.001","volume":"70","author":"Z Duan","year":"2008","unstructured":"Duan, Z., Yang, X., Koutny, M.: Framed temporal logic programming. Sci. Comput. Program. 70(1), 31\u201361 (2008)","journal-title":"Sci. Comput. Program."},{"key":"7_CR22","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1016\/j.tcs.2011.12.014","volume":"461","author":"C Tian","year":"2012","unstructured":"Tian, C., Duan, Z., Zhang, N.: An efficient approach for abstraction-refinement in model checking. Theoret. Comput. Sci. 461, 76\u201385 (2012)","journal-title":"Theoret. Comput. Sci."},{"key":"7_CR23","doi-asserted-by":"publisher","unstructured":"Benton, K., Jo, J., Kim, Y.: Signaturecheck: a protocol to detect man-in-the-middle attack in SSL. In: Proceedings of the Seventh Annual Workshop on Cyber Security and Information Intelligence Research, p. 60. ACM (2011)","DOI":"10.1145\/2179298.2179365"},{"key":"7_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-642-41098-7_5","volume-title":"Security and Trust Management","author":"M Conti","year":"2013","unstructured":"Conti, M., Dragoni, N., Gottardo, S.: MITHYS: mind the hand you shake - protecting mobile devices from SSL usage vulnerabilities. In: Accorsi, R., Ranise, S. (eds.) STM 2013. LNCS, vol. 8203, pp. 65\u201381. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-41098-7_5 . 9th International Workshop, STM 2013, Egham, UK, September 12-13, 2013"},{"key":"7_CR25","doi-asserted-by":"publisher","unstructured":"Bates, A., Pletcher, J., Nichols, T.: Securing SSL certificate verification through dynamic linking. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, pp. 394\u2013405. ACM (2014)","DOI":"10.1145\/2660267.2660338"},{"key":"7_CR26","doi-asserted-by":"publisher","unstructured":"Fahl, S., Harbach, M., Perl, H.: Rethinking SSL development in an appified world. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, pp. 49\u201360. ACM (2013)","DOI":"10.1145\/2508859.2516655"},{"key":"7_CR27","unstructured":"Tendulkar, V., Enck, W.: An application package configuration approach to mitigating android SSL vulnerabilities (2014)"},{"key":"7_CR28","unstructured":"tcpdump. http:\/\/www.tcpdump.org"},{"key":"7_CR29","unstructured":"hostapd. http:\/\/w1.fi\/hostapd"},{"key":"7_CR30","unstructured":"SSLsplit. http:\/\/www.roe.ch\/SSLsplit"},{"key":"7_CR31","unstructured":"wireshark, https:\/\/www.wireshark.org"}],"container-title":["Lecture Notes in Computer Science","Structured Object-Oriented Formal Language and Method"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-57708-1_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,21]],"date-time":"2019-09-21T07:23:28Z","timestamp":1569050608000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-57708-1_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319577074","9783319577081"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-57708-1_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2017]]}}}