透過您的圖書館登入
IP:18.222.115.179
  • 學位論文

手機應用程式隱私窺探報告 ― 以 MitmProxy 實作

A Report on Mobile Apps Privacy Invasion using MitmProxy

指導教授 : 洪朝貴
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


隨著平板電腦、智慧型手機的普及與成長,帶動近年來手機應用程式(App)的快速興起,各式各樣的應用程式可以幫助使用者的工作變得更加簡單方便、迅速了解所有的最新資訊,也能帶來更多娛樂性。開發人員不斷地創新開發與改善手機應用程式,使得手機應用程式已是我們生活中不可或缺的一部分,但是隱私洩漏問題則是隨之而生且被熱烈討論的話題。雖然現在多數人都比較有隱私意識了,但多數使用者往往還是會同意任何在手機上出現的權限要求,因為他們只想要儘快開始使用那些手機軟體。 本篇論文先以Wireshark來做手機APP隱私洩漏偵測與分類,接著以Mitmproxy分析手機APP發送之HTTP(S)網路封包內容,監測這些手機APP是否在使用者未授權情況下擅自傳送敏感資料封包給伺服器,並進一步觀察這些APP傳送的封包是否含有不該取得之資料。

關鍵字

封包分析 隱私洩漏 手機APP

並列摘要


Mobile applications have been developed rapidly in recent years. A wide variety of applications can help us organize our work, let us see all the latest information at a glance. So life becomes easier and more fun. Developers are working to improve their mobile applications constantly, making these applications occupy a large part of our lives. However, the issue of data privacy has also emerged, and it has become a hot topic of discussion. Even everyone has become conscious of privacy, many users often click on any message that appears on their phone because they only want to be able to start using their phone software as soon as possible. In this paper, we use Wireshark to detect and classify the privacy risks of mobile applications. Then, we use Mitmproxy (man-in-the-middle) to analyze HTTP (S) packets sent by the mobile applications, monitoring whether these mobile apps send sensitive data to the server without the user's authorization, and observe whether packets sent by these Apps contain information that should not be obtained.

並列關鍵字

packet analysis privacy leak mobile apps

參考文獻


[1]GoldenMr(2015),Ingress Hacking,部落格文章,檢自:
http://hkgoldenmra.blogspot.tw/
[2]iThome(2014),HTTPS網站居主流,資安重新定義,檢自:
https://www.ithome.com.tw/tech/93108
[3]Jack Chen(2017),Android 系統架構和應用元件那些事,中文技術分享平台,檢自:https://itw01.com/FGR9EBX.html

延伸閱讀