首页> 外文期刊>Mobile Computing, IEEE Transactions on >Characterizing the Security Implications of Third-Party Emergency Alert Systems over Cellular Text Messaging Services
【24h】

Characterizing the Security Implications of Third-Party Emergency Alert Systems over Cellular Text Messaging Services

机译:表征蜂窝文本消息服务上的第三方紧急警报系统的安全隐患

获取原文
获取原文并翻译 | 示例
           

摘要

Cellular text messaging services are increasingly being relied upon to disseminate critical information during emergencies. Accordingly, a wide range of organizations including colleges and universities now partner with third-party providers that promise to improve physical security by rapidly delivering such messages. Unfortunately, these products do not work as advertised due to limitations of cellular infrastructure and therefore provide a false sense of security to their users. In this paper, we perform the first extensive investigation and characterization of the limitations of an Emergency Alert System (EAS) using text messages as a security incident response mechanism. We show emergency alert systems built on text messaging not only can meet the 10 minute delivery requirement mandated by the WARN Act, but also potentially cause other voice and SMS traffic to be blocked at rates upward of 80 percent. We then show that our results are representative of reality by comparing them to a number of documented but not previously understood failures. Finally, we analyze a targeted messaging mechanism as a means of efficiently using currently deployed infrastructure and third-party EAS. In so doing, we demonstrate that this increasingly deployed security infrastructure does not achieve its stated requirements for large populations.
机译:在紧急情况下,越来越多地依赖蜂窝文本消息服务来分发关键信息。因此,包括学院和大学在内的广泛组织现在与第三方提供商合作,这些第三方提供商承诺通过快速传递此类消息来提高物理安全性。不幸的是,由于蜂窝基础设施的限制,这些产品无法像宣传的那样工作,因此给用户带来了错误的安全感。在本文中,我们使用文本消息作为安全事件响应机制,对紧急警报系统(EAS)的局限性进行了首次广泛的调查和表征。我们展示了基于文本消息的紧急警报系统,不仅可以满足WARN法案规定的10分钟交付要求,而且还可能以80%的速率阻止其他语音和SMS流量。然后,通过将它们与许多已记录但先前未理解的故障进行比较,我们证明了我们的结果可以代表现实。最后,我们分析目标消息传递机制,作为有效利用当前部署的基础架构和第三方EAS的一种手段。通过这样做,我们证明了这种日益部署的安全基础架构无法满足其针对大量人群的要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号