首页> 外文会议>International Workshop on Cryptographic Hardware and Embedded Systems >Hacking in the Blind: (Almost) Invisible Runtime User Interface Attacks
【24h】

Hacking in the Blind: (Almost) Invisible Runtime User Interface Attacks

机译:在盲人中攻击:(差不多)隐形运行时用户界面攻击

获取原文

摘要

We describe novel, adaptive user interface attacks, where the adversary attaches a small device to the interface that connects user input peripherals to the target system. The device executes the attack when the authorized user is performing safety-, or security-critical operations, by modifying or blocking user input, or injecting new events. Although the adversary fully controls the user input channel, to succeed he needs to overcome a number of challenges, including the inability to directly observe the state of the user interface and avoiding being detected by the legitimate user. We present new techniques that allow the adversary to do user interface state estimation and fingerprinting, and thus attack a new range of scenarios that previous UI attacks do not apply to. We evaluate our attacks on two different types of platforms: e-banking on general-purpose PCs, and dedicated medical terminals. Our evaluation shows that such attacks can be implemented efficiently, are hard for the users to detect, and would lead to serious violations of input integrity.
机译:我们描述了新颖的,自适应用户界面攻击,其中对手将小设备附加到将用户输入外围设备连接到目标系统的接口。当授权用户正在执行安全性或安全关键操作时,该设备通过修改或阻止用户输入,或注入新事件时执行攻击。虽然对手完全控制了用户输入通道,但是成功地需要克服许多挑战,包括无法直接观察用户界面的状态并避免由合法用户检测到的状态。我们呈现新技术,允许对手进行用户界面状态估计和指纹识别,从而攻击以前的UI攻击不适用的新方案。我们评估了对两种不同类型的平台的攻击:通用PC上的电子银行,专用医疗终端。我们的评估表明,这种攻击可以有效地实现,对用户来说很难检测,并导致严重违反输入完整性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号