首页> 外文会议>ACM conference on security and privacy in wireless and mobile networks >TapLogger: Inferring User Inputs On Smartphone Touchscreens Using On-board Motion Sensors
【24h】

TapLogger: Inferring User Inputs On Smartphone Touchscreens Using On-board Motion Sensors

机译:Taplogger:使用板上运动传感器推断在智能手机触摸屏上的用户输入

获取原文

摘要

Today's srnartphoues are shipped with various embedded motion sensors, such as the accelerometer. gyroscope, and orientation sensors. These motion sensors are useful in supporting the mobile UI innovation and motion-based commands. However, they also bring potential risks of leaking user's private information as they allow third party applications to monitor the motion changes of smartphones. In this paper, we study the feasibility of inferring a user's tap inputs to a smartphone with its integrated motion sensors. Specifically, we utilize an installed trojan application to stealthily monitor the movement and gesture changes of a smartphone using its on-board motion sensors. When the user is interacting with the trojan application, it learns the motion change patterns of tap events. Later, when the user is performing sensitive inputs, such as entering passwords on the touchscreen, the trojan application applies the learnt pattern to infer the occurrence of tap events on the touchscreen as well as the tapped positions on the touchscreen. For demonstration, we present the design and implementation of TapLogger. a trojan application for the Android platform, which stealthily logs the password of screen lock and the numbers entered during a phone call (e.g.. credit card and PIN numbers). Statistical results are presented to show the feasibility of such inferences and attacks.
机译:今天的Srnartphoues配备各种嵌入式运动传感器,如加速度计。陀螺和定向传感器。这些运动传感器可用于支持移动UI创新和基于运动的命令。但是,它们还会带来泄漏用户私人信息的潜在风险,因为它们允许第三方应用来监控智能手机的运动变化。在本文中,我们研究了使用其集成运动传感器的智能手机推断用户抽头输入的可行性。具体而言,我们利用安装的特洛伊木马应用程序使用其板载运动传感器悄悄地监控智能手机的移动和手势变化。当用户与特洛伊木马应用程序交互时,它会学习挖掘事件的运动变化模式。稍后,当用户执行敏感的输入时,例如在触摸屏上输入密码,特洛伊木马应用程序适用于学习模式以推断触摸屏上的挖掘事件的发生以及触摸屏上的禁点位置。为了演示,我们展示了Taplogger的设计和实现。 Android平台的特洛伊木马应用程序,它悄悄地记录屏幕锁的密码和电话通话期间输入的号码(例如,信用卡和PIN号)。提出了统计结果以表明这种推动和攻击的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号