{"id":"https://openalex.org/W2906194244","doi":"https://doi.org/10.1109/ccst.2018.8585431","title":"An Empirical Study of SSL Usage in Android Apps","display_name":"An Empirical Study of SSL Usage in Android Apps","publication_year":2018,"publication_date":"2018-10-01","ids":{"openalex":"https://openalex.org/W2906194244","doi":"https://doi.org/10.1109/ccst.2018.8585431","mag":"2906194244"},"language":"en","primary_location":{"id":"doi:10.1109/ccst.2018.8585431","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ccst.2018.8585431","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 International Carnahan Conference on Security Technology (ICCST)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5059068557","display_name":"Dongwan Shin","orcid":"https://orcid.org/0000-0002-2151-3986"},"institutions":[{"id":"https://openalex.org/I207123951","display_name":"New Mexico Institute of Mining and Technology","ror":"https://ror.org/005p9kw61","country_code":"US","type":"education","lineage":["https://openalex.org/I207123951"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Dongwan Shin","raw_affiliation_strings":["Computer Science and Engineering Department, New Mexico Institute of Mining and Technology, Socorro, NM, USA"],"affiliations":[{"raw_affiliation_string":"Computer Science and Engineering Department, New Mexico Institute of Mining and Technology, Socorro, NM, USA","institution_ids":["https://openalex.org/I207123951"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5033959484","display_name":"Jiangfeng Sun","orcid":null},"institutions":[{"id":"https://openalex.org/I207123951","display_name":"New Mexico Institute of Mining and Technology","ror":"https://ror.org/005p9kw61","country_code":"US","type":"education","lineage":["https://openalex.org/I207123951"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jiangfeng Sun","raw_affiliation_strings":["Computer Science and Engineering Department, New Mexico Institute of Mining and Technology, Socorro, NM, USA"],"affiliations":[{"raw_affiliation_string":"Computer Science and Engineering Department, New Mexico Institute of Mining and Technology, Socorro, NM, USA","institution_ids":["https://openalex.org/I207123951"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5059068557"],"corresponding_institution_ids":["https://openalex.org/I207123951"],"apc_list":null,"apc_paid":null,"fwci":0.1651,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.483856,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"5"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.8451138734817505},{"id":"https://openalex.org/keywords/transport-layer-security","display_name":"Transport Layer Security","score":0.8069823384284973},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7209789156913757},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6128333806991577},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.5845537185668945},{"id":"https://openalex.org/keywords/information-sensitivity","display_name":"Information sensitivity","score":0.4497945308685303},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.4473794102668762},{"id":"https://openalex.org/keywords/de-facto","display_name":"De facto","score":0.4456242620944977},{"id":"https://openalex.org/keywords/android-app","display_name":"Android app","score":0.43502798676490784},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.42306506633758545},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.18176689743995667},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.17852413654327393}],"concepts":[{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.8451138734817505},{"id":"https://openalex.org/C148176105","wikidata":"https://www.wikidata.org/wiki/Q206494","display_name":"Transport Layer Security","level":3,"score":0.8069823384284973},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7209789156913757},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6128333806991577},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.5845537185668945},{"id":"https://openalex.org/C137822555","wikidata":"https://www.wikidata.org/wiki/Q2587068","display_name":"Information sensitivity","level":2,"score":0.4497945308685303},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.4473794102668762},{"id":"https://openalex.org/C2992317946","wikidata":"https://www.wikidata.org/wiki/Q712144","display_name":"De facto","level":2,"score":0.4456242620944977},{"id":"https://openalex.org/C2988045736","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android app","level":3,"score":0.43502798676490784},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.42306506633758545},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.18176689743995667},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.17852413654327393},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ccst.2018.8585431","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ccst.2018.8585431","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 International Carnahan Conference on Security Technology (ICCST)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":11,"referenced_works":["https://openalex.org/W1972447841","https://openalex.org/W2008251338","https://openalex.org/W2025440653","https://openalex.org/W2103370348","https://openalex.org/W2129426180","https://openalex.org/W2145994642","https://openalex.org/W2146752727","https://openalex.org/W2214173928","https://openalex.org/W2536255411","https://openalex.org/W2555115505","https://openalex.org/W2604595700"],"related_works":["https://openalex.org/W2894765413","https://openalex.org/W769484497","https://openalex.org/W2506128599","https://openalex.org/W2794864670","https://openalex.org/W2922039621","https://openalex.org/W4383744737","https://openalex.org/W2940442438","https://openalex.org/W2949757294","https://openalex.org/W2773184731","https://openalex.org/W2581685432"],"abstract_inverted_index":{"SSL/TLS":[0,66,136],"(Secure":[1],"Socket":[2],"Layer/Transport":[3],"Layer":[4],"Security)":[5],"has":[6],"been":[7],"used":[8,68],"as":[9,79],"a":[10,147],"de":[11],"facto":[12],"security":[13,56,100],"protocol":[14,57,101],"to":[15,26,31,46,53,63,73,86,123,143],"protect":[16,74],"users'":[17,75],"sensitive":[18,76],"information":[19,77],"in":[20,102,138,150],"Android":[21,43,106,139,155],"apps,":[22],"which":[23],"often":[24],"need":[25],"communicate":[27],"with":[28,34],"servers":[29],"online":[30],"provide":[32],"users":[33,44],"some":[35,88],"of":[36,50,98,118,135,154],"their":[37],"functionalities":[38],"and":[39,70,130],"services.":[40],"Since":[41],"most":[42,104],"tend":[45],"be":[47],"either":[48],"unaware":[49],"or":[51],"unable":[52],"understand":[54],"the":[55,96,99,128,144,158],"well,":[58],"it":[59],"is":[60,67],"critically":[61],"important":[62,92],"investigate":[64],"if":[65],"properly":[69],"implemented":[71],"correctly":[72],"such":[78],"credentials.":[80],"In":[81],"this":[82,91,131],"paper,":[83],"we":[84],"seek":[85],"shine":[87],"light":[89],"into":[90],"issue":[93],"by":[94],"studying":[95],"usage":[97,137],"200":[103],"popular":[105],"apps":[107,120,140,156],"downloaded":[108],"from":[109,146],"Google":[110],"Play.":[111],"We":[112],"found":[113],"out":[114],"that":[115],"only":[116],"4%":[117],"these":[119],"are":[121],"vulnerable":[122],"two":[124],"well-known":[125],"attacks":[126],"against":[127],"protocol,":[129],"shows":[132],"huge":[133],"improvement":[134],"when":[141],"compared":[142],"results":[145],"study":[148,159],"conducted":[149],"2012,":[151],"where":[152],"100%":[153],"under":[157],"were":[160],"vulnerable.":[161]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1},{"year":2020,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
