【24h】

Beware, Your Hands Reveal Your Secrets

机译:小心,你的手揭示你的秘密

获取原文

摘要

Research on attacks which exploit video-based side-channels to decode text typed on a smartphone has traditionally assumed that the adversary is able to leverage some information from the screen display (say, a reflection of the screen or a low resolution video of the content typed on the screen). This paper introduces a new breed of side-channel attack on the PIN entry process on a smartphone which entirely relies on the spatio-temporal dynamics of the hands during typing to decode the typed text. Implemented on a dataset of 200 videos of the PIN entry process on an HTC One phone, we show, that the attack breaks an average of over 50% of the PINs on the first attempt and an average of over 85% of the PINs in ten attempts. Because the attack can be conducted in such a way not to raise suspicion (i.e., since the adversary does not have to direct the camera at the screen), we believe that it is very likely to be adopted by adversaries who seek to stealthily steal sensitive private information. As users conduct more and more of their computing transactions on mobile devices in the open, the paper calls for the community to take a closer look at the risks posed by the now ubiquitous camera-enabled devices.
机译:利用基于视频的侧视通道的攻击的研究传统上假设对手能够从屏幕显示中利用一些信息(例如,屏幕的反射或内容的低分辨率视频键入屏幕)。本文介绍了一种关于智能手机上的引脚进入过程的新品种,它们完全依赖于打字期间双手的时空动态来解码键入的文本。我们在HTC一部手机上的200个视频的数据集上实施,我们展示了,攻击在第一次尝试中平均平均超过50%的引脚,并且平均超过85%的引脚尝试。因为攻击可以以这样的方式进行,而不是举起怀疑(即,由于对手不必在屏幕上指示相机),我们相信,这是寻求悄悄地窃取敏感的对手采用私人信息。随着用户在开放的移动设备上进行越来越多的计算事务,纸质呼吁社区仔细看看现在无处不在的相机设备所带来的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号