Towards best secure coding practice for implementing SSL/TLS
Mohannad Alhanahnah, Qiben Yan · 2018
Developers often make mistakes while incorporating SSL/TLS functionality in their applications due to the complication in implementing SSL/TLS and their fast prototyping requirement. Insecure implementations of SSL/TLS are subject to different types of Man in The Middle (MiTM) attacks, which ultimately makes the communication between the two parties vulnerable to eavesdropping and hijacking attacks, thereby violating confidentiality and integrity of the exchanged information. This paper aims to support developers in detecting insecure SSL/TLS implementation in their codes by utilizing a low-cost cross-language static analysis tool called PMD. In the end, two insecure implementations of SSL/TLS have been identified, and subsequently a new PMD rule set is created. This rule set consists of three rules for addressing hostname validation vulnerability and certificate validation vulnerability. The rules have been evaluated over 1,517 code snippets obtained from Stack Overflow, and the results show that 71% of the code snippets contain insecure SSL/TLS patterns. The detection rate of our approach is 100%, while it detects 165 violations inside the vulnerable code snippets in total.