首页> 外文期刊>ACM Transaction on Information and System Security >Characterizing the Security of the SMS Ecosystem with Public Gateways
【24h】

Characterizing the Security of the SMS Ecosystem with Public Gateways

机译:使用公共网关表征SMS生态系统的安全性

获取原文
获取原文并翻译 | 示例

摘要

Recent years have seen the Short Message Service (SMS) become a critical component of the security infrastructure, assisting with tasks including identity verification and second-factor authentication. At the same time, this messaging infrastructure has become dramatically more open and connected to public networks than ever before. However, the implications of this openness, the security practices of benign services, and the malicious misuse of this ecosystem are not well understood. In this article, we provide a comprehensive longitudinal study to answer these questions, analyzing over 900,000 text messages sent to public online SMS gateways over the course of 28 months. From this data, we uncover the geographical distribution of spam messages, study SMS as a transmission medium of malicious content, and find that changes in benign and malicious behaviors in the SMS ecosystem have been minimal during our collection period. The key takeaways of this research show many services sending sensitive security-based messages through an unencrypted medium, implementing low entropy solutions for one-use codes, and behaviors indicating that public gateways are primarily used for evading account creation policies that require verified phone numbers. This latter finding has significant implications for combating phone-verified account fraud and demonstrates that such evasion will continue to be difficult to detect and prevent.
机译:近年来,短消息服务(SMS)成为安全基础结构的重要组成部分,可协助完成身份验证和二级身份验证等任务。同时,此消息传递基础结构比以往任何时候都更加开放和连接到公共网络。但是,人们对这种开放性,良性服务的安全性实践以及对该生态系统的恶意滥用的含意尚不清楚。在本文中,我们提供了一个全面的纵向研究来回答这些问题,并分析了在28个月内发送到公共在线SMS网关的900,000条文本消息。从这些数据中,我们发现了垃圾邮件的地理分布,研究了SMS作为恶意内容的传输媒介,并发现在我们的收集期间,SMS生态系统中良性和恶意行为的变化很小。这项研究的主要成果表明,许多服务通过未加密的媒体发送敏感的基于安全性的消息,为一次性代码实现低熵解决方案,以及表明公用网关主要用于逃避需要经过验证的电话号码的帐户创建策略的行为。后一个发现对于打击通过电话验证的帐户欺诈行为具有重要意义,并表明这种逃避行为将继续难以发现和防止。

著录项

  • 来源
  • 作者单位

    North Carolina State Univ, Raleigh, NC 27695 USA|890 Oval Dr, Raleigh, NC 27695 USA;

    Univ Florida, Gainesville, FL USA|E301 CSE Bldg,POB 116120, Gainesville, FL 32611 USA;

    Univ Florida, Gainesville, FL USA|E301 CSE Bldg,POB 116120, Gainesville, FL 32611 USA;

    Univ Florida, Gainesville, FL USA|E301 CSE Bldg,POB 116120, Gainesville, FL 32611 USA;

    Univ Florida, Gainesville, FL USA|E301 CSE Bldg,POB 116120, Gainesville, FL 32611 USA;

    Univ Florida, Gainesville, FL USA|E301 CSE Bldg,POB 116120, Gainesville, FL 32611 USA;

    Univ Florida, Gainesville, FL USA|E301 CSE Bldg,POB 116120, Gainesville, FL 32611 USA;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Multifactor authentication; SMS; SMS abuse; SMS spam;

    机译:多因素身份验证;SMS;SMS滥用;SMS垃圾邮件;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号