中大首揭「單點登錄」4漏洞

智慧城市世代,不同類型的網絡服務繁多且五花八門,當中不少都有採用「單點式登錄」方式,只需要於社交網站進行一次身份認證,就能夠轉駁登錄第三方應用程式或網站,省卻另設新賬號及密碼,為用家帶來便利。中文大學團隊研發新的檢測系統,成功揭示現時市場上常見「單點式登錄」的7種開發漏洞,其中4種更是首次發現,駭客有機會藉以直接控制受害者的賬號,後果不容忽視!團隊亦因此於日前舉行的第二十七屆網絡安全會議獲頒「互聯網防禦獎」第三名。

Date: 
Wednesday, August 29, 2018
Media: 
Wen Wei Po

借社交帳戶登錄網站有保安漏洞

不少網站均會要求用戶透過社交平台如FB等登錄,讓用戶可少記一個用戶帳號,但中大研究發現,這類透過社交網站的帳號,登入第三方網站(如OpenRice、IMDb等)的「單點式登錄」,都有出現安全漏洞,用戶的個人私隱可能會遭盜用。負責研究的中大信息工程學系副教授劉永昌更指,不排除電子支付系統都會出現類似的安全漏洞,團隊未來將借鑑現時系統的概念,設計針對電子支付的檢測系統,保障用戶免受金錢上的損失。

Date: 
Wednesday, August 29, 2018
Media: 
AM730

中大團隊尋單點式登入漏洞 獲Facebook互聯網防禦獎

不少網民為了方便,都會用Facebook等個人社交帳戶登入應用程式或網站,稱之為單點式登入(Single Sign-On,簡稱SSO)但中大信息工程學系教授劉永昌表示,SSO普遍存在漏洞,黑客可利用漏洞騎劫用戶帳戶,登入使用SSO的其他網站,影響數以億計網民。

Date: 
Tuesday, August 28, 2018
Media: 
Topick

中大科研揭單點式登入漏洞

不少網民會透過facebook等社交帳戶登入其他應用程式,中文大學信息工程學系成功研發S3KVetter系統,發現使用單點式登入(SSO)的軟件開發套件(SDKs)存有四種程式登錄漏洞。黑客可利用漏洞入侵用戶使用的網站,預計影響數以億計網民。

Date: 
Wednesday, August 29, 2018
Media: 
Headline Daily

防黑客盜個人資料 中大研程式 5秒揭社交網登入漏洞

現時不少網站容許網民使用社交網站帳戶登入,毋須於網站申請帳戶,方便網民不需記住大量帳戶登入資料。香港中文大學信息工程學系研發的自動測試工具,在相關軟件開發套件中發現了4種過去未被發現的漏洞,有可能讓黑客由此竊取網民在其他網站的私人資料。

Date: 
Wednesday, August 29, 2018
Media: 
Ming Pao Daily News

Name: 
HAN Dongkun
Title ( post ): 
Lecturer
Department: 
Mechanical and Automation Engineering
email: 
dkhan [at] mae.cuhk.edu.hk
phone: 
3943 3537
website: 
https://www4.mae.cuhk.edu.hk/peoples/han-dongkun/
Avatar: 
Class: 
faculty_member
Chinese Name: 
韓東昆
glossary_index: 
H

Information Engineering Team Discovers Vulnerabilities of Single Sign Code

Date: 
2018-08-28
Thumbnail: 
Body: 

A team of the Department of Information Engineering has recently won the third place of the 2018 Internet Defense Prize and a research grant of US$40,000 funded by Facebook at the 27th USENIX Security Symposium held in the US. Their award was for their contribution to the critical analysis of the security of Single Sign-On (SSO) Software Development Kits (SDKs) deployed in practice. The team comprised of Dr. Ronghai Yang, Prof. Wing Cheong Lau, Mr. Jiongyi Chen, and Prof. Kehuan Zhang of the Department of Information Engineering, CUHK. This is the first time for researchers from an Asian institution to receive this international award.

The winning paper authored by the CUHK team was titled Vetting Single Sign-On SDK Implementations via Symbolic Reasoning. SSO provides a partial solution to the Internet’s over-reliance on passwords. It enables users to use their Online Social Networking accounts/ credentials (such as those from Facebook, Google, Sina, Tencent and Baidu), to log into other third-party applications/ websites (such as OpenRice and IMDb) and thus providing a more convenient way for users to sign up and access different online services and applications. Since SSO has been serving hundreds of millions of Internet users every day, the security of related software development kits (SDKs) is of critical importance to online security.

SSO involves cooperation and coordination between ID providers, users and third-party applications/websites. The technology is complicated and poses many challenges in analysing  the security of SSO SDKs. The CUHK research team designed and implemented S3KVetter (Single-Sign-On SDK Vetter), an automated, efficient testing tool, to check the logical correctness and identify vulnerabilities of SSO SDKs in practice. To demonstrate the efficacy of S3KVetter, the team applied S3KVetter to test ten popular SSO SDKs which have been downloaded for millions of times by web-service/ application developers.

Among the SSO SDKs examined, S3KVetter has discovered 7 classes of logic flaws, 4 of which were previously unknown. The new vulnerabilities can lead to severe consequences, ranging from the sniffing of user activities to the hijacking of user accounts.

The team was thrilled with their work. Dr. Ronghai Yang, an alumnus of CUHK Department of Information Engineering said, “We have discovered multiple zero-day exploits among several popular SSO SDKs in practice. Until the vulnerabilities are mitigated, hackers can exploit them to cause severe breaches of the security and privacy of online users world-wide. This is an important issue that the industry must address.”

“Internet communications and cybersecurity have long been two of the key research areas of the CUHK Engineering Faculty. The award is a great encouragement to our team and a recognition of CUHK’s strength in cybersecurity research.  We will scale new heights in our ongoing work on applied cryptography, security and privacy in cyber systems, with the aim of making the cyberworld a safer place,” said Prof. Lau Wing Cheong of the Department of Information Engineering, CUHK.

For more details of the paper, please go to www.usenix.org/system/files/conference/usenixsecurity18/sec18-yang.pdf


About the Internet Defense Prize

Created in 2014, the Internet Defense Prize is funded by Facebook and offered in partnership with USENIX. It aims to celebrate technical contributions to the protection and defense of the Internet. 

(From left) Prof. Wing Cheong Lau, Mr. Jiongyi Chen of the Department of Information Engineering, and Dr. Nektarios Leontiadis, Threat Research Scientist, Facebook

 

 

Filter: Dept: 
Faculty
IE
Media Release

借鏡澳洲 推創新服務需釋疑慮

澳洲政府是全球最早推行個人健康紀錄數碼化的國家之一。
在過去6年已有約6萬名市民登記參與「我的健康紀錄」(My Health Record)計劃,佔全國人口之2.5%。但當地政府於今年7月推出「退出」(opt-out)政策,容許已登記市民取消其網上數碼建康紀錄。該項政策一出台便引發全國各地傳媒重新檢視「我的健康紀錄」的利與弊。
Date: 
Saturday, August 11, 2018
Media: 
HKET

港男北上搞電子支付|「錢方」創辦人:港人到國內工作沒核心優勢

在港搞初創企業雖不至受人白眼,但深感難以應付生活的80後港人李英豪(Tim),七年後的今天可謂衣錦榮歸。其帶著2011年於北京創立的移動支付平台「錢方好近」回港。公司除了是第一批跟微信支付及支付寶合作的企業外,更將申請成為香港首批虛擬銀行,讓FinTech真正落地。

Date: 
Wednesday, August 8, 2018
Media: 
Apple Daily

Pages