...
首页> 外文期刊>International Journal of Information Security >Keyboard acoustic side channel attacks: exploring realistic and security-sensitive scenarios
【24h】

Keyboard acoustic side channel attacks: exploring realistic and security-sensitive scenarios

机译:键盘声侧通道攻击:探索现实且对安全性敏感的方案

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This research takes a closer look at keyboard acoustic emanations specifically for the purpose of eavesdropping over random passwords. In this scenario, dictionary and HMM language models are not applicable; the attacker can only utilize the raw acoustic information which has been recorded. This work investigates several existing signal processing techniques for this purpose and introduces a novel technique-time-frequency decoding-that improves the detection accuracy compared to previous techniques. It also carefully examines the effect of typing style-a crucial variable largely ignored by prior research-on the detection accuracy. The results show that using the same typing style (hunt and peck) for both training and decoding the data, the best case success rate for detecting correctly the typed key is 64 % per character. The results also show that changing the typing style, to touch typing, during the decoding stage reduces the success rate, but using the time-frequency technique, it is still possible to achieve a success rate of around 40 % per character. In these realistic scenarios, where the password is random, the approach described here can reduce the entropy of the search space by up to 57 % per character. This brings keyboard acoustic attack one step closer to a full-fledged vulnerability.
机译:这项研究专门针对窃听随机密码的目的,仔细研究了键盘的声音散发。在这种情况下,词典和HMM语言模型不适用。攻击者只能利用已记录的原始声学信息。这项工作为此目的研究了几种现有的信号处理技术,并介绍了一种新颖的技术-时频解码-与以前的技术相比提高了检测精度。它还仔细检查了键入样式(这是一个被先前研究广泛忽略的关键变量)对检测准确性的影响。结果表明,使用相同的键入样式(hunt和peck)来训练和解码数据,正确检测键入的密钥的最佳案例成功率是每个字符64%。结果还表明,在解码阶段将键入样式更改为触摸键入会降低成功率,但是使用时频技术,仍然有可能获得每个字符40%左右的成功率。在这些现实的情况下,密码是随机的,此处介绍的方法可以将每个字符的搜索空间熵降低多达57%。这使键盘声学攻击更接近成熟的漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号