免费android vpn的取证和行为分析

Q4 Engineering
T. Wangchuk, Digvijaysingh Rathod
{"title":"免费android vpn的取证和行为分析","authors":"T. Wangchuk, Digvijaysingh Rathod","doi":"10.54417/jaetm.v1i1.27","DOIUrl":null,"url":null,"abstract":"Millions of users worldwide use VPN clients to either circumvent censorship or to access geo-blocked content, and specifically for privacy and security purposes. In the pretext of secured communication and privacy, numerous free android-based VPNs are being pushed up in the Google Play store. However, the users aren’t sure or aware of whether the VPN is truly secure or just leaking their data. So, the forensic and behavior analysis of selected free android VPNs was carried out to study the usability of free android-based VPNs in terms of providing security and privacy; specifically, the presence of dangerous permissions, malware presence, traffic encryption, the DNS leaks, and the possibility of leaving forensic artifacts on the device after the VPN use. The study revealed considerable portion of the sample free VPNs were flagged malicious and had dangerous levels of permissions in use. While some failed the DNS leak test and some VPNs even did not encrypt the traffic. Given the availability of a huge number of Free VPNs in the Google Play store, it was found important that the users must be aware of the inherent risks put by the use of these Free VPNs.","PeriodicalId":38544,"journal":{"name":"Journal of Technology, Management, and Applied Engineering","volume":"62 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2021-06-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"FORENSIC AND BEHAVIOR ANALYSIS OF FREE ANDROID VPNS\",\"authors\":\"T. Wangchuk, Digvijaysingh Rathod\",\"doi\":\"10.54417/jaetm.v1i1.27\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Millions of users worldwide use VPN clients to either circumvent censorship or to access geo-blocked content, and specifically for privacy and security purposes. In the pretext of secured communication and privacy, numerous free android-based VPNs are being pushed up in the Google Play store. However, the users aren’t sure or aware of whether the VPN is truly secure or just leaking their data. So, the forensic and behavior analysis of selected free android VPNs was carried out to study the usability of free android-based VPNs in terms of providing security and privacy; specifically, the presence of dangerous permissions, malware presence, traffic encryption, the DNS leaks, and the possibility of leaving forensic artifacts on the device after the VPN use. The study revealed considerable portion of the sample free VPNs were flagged malicious and had dangerous levels of permissions in use. While some failed the DNS leak test and some VPNs even did not encrypt the traffic. Given the availability of a huge number of Free VPNs in the Google Play store, it was found important that the users must be aware of the inherent risks put by the use of these Free VPNs.\",\"PeriodicalId\":38544,\"journal\":{\"name\":\"Journal of Technology, Management, and Applied Engineering\",\"volume\":\"62 1\",\"pages\":\"\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-06-30\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Technology, Management, and Applied Engineering\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.54417/jaetm.v1i1.27\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"Engineering\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Technology, Management, and Applied Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.54417/jaetm.v1i1.27","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"Engineering","Score":null,"Total":0}
引用次数: 3

摘要

全球数百万用户使用VPN客户端绕过审查或访问地理封锁的内容,特别是出于隐私和安全目的。以保护通信和隐私为借口,Google Play商店中出现了大量基于android的免费vpn。然而,用户不确定或意识到VPN是否真正安全或只是泄漏他们的数据。因此,本文对选定的免费android vpn进行取证和行为分析,研究基于android的免费vpn在提供安全和隐私方面的可用性;具体来说,包括危险权限的存在、恶意软件的存在、流量加密、DNS泄漏以及在使用VPN后在设备上留下取证工件的可能性。研究显示,相当一部分免费vpn样本被标记为恶意,并且在使用中具有危险级别的权限。而有些DNS泄漏测试失败,有些vpn甚至没有加密流量。鉴于Google Play商店中大量免费vpn的可用性,我们发现用户必须意识到使用这些免费vpn所带来的内在风险。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
FORENSIC AND BEHAVIOR ANALYSIS OF FREE ANDROID VPNS
Millions of users worldwide use VPN clients to either circumvent censorship or to access geo-blocked content, and specifically for privacy and security purposes. In the pretext of secured communication and privacy, numerous free android-based VPNs are being pushed up in the Google Play store. However, the users aren’t sure or aware of whether the VPN is truly secure or just leaking their data. So, the forensic and behavior analysis of selected free android VPNs was carried out to study the usability of free android-based VPNs in terms of providing security and privacy; specifically, the presence of dangerous permissions, malware presence, traffic encryption, the DNS leaks, and the possibility of leaving forensic artifacts on the device after the VPN use. The study revealed considerable portion of the sample free VPNs were flagged malicious and had dangerous levels of permissions in use. While some failed the DNS leak test and some VPNs even did not encrypt the traffic. Given the availability of a huge number of Free VPNs in the Google Play store, it was found important that the users must be aware of the inherent risks put by the use of these Free VPNs.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
0.60
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信