PIN skimmer: inferring PINs through the camera and microphone

PIN skimmer: inferring PINs through the camera and microphone
复制标题

DOI:
10.1145/2516760.2516770
复制
发表时间:
2013-11
期刊:
--
影响因子:
--
通讯作者:
Laurent Simon;Ross J. Anderson
Laurent Simon;Ross J. Anderson
中科院分区:
其他
文献类型:
--
作者:
Laurent Simon;Ross J. Anderson

文献摘要

被引文献

相似文献

今天的智能手机提供的服务和用途,在不久前还需要一整套专用设备。与他们一起,我们听音乐、玩游戏或与朋友聊天;但我们也阅读公司电子邮件和文件,管理我们的网上银行;我们已经开始直接将它们用作一种支付手段。在这篇文章中,我们的目标是提高对旁路攻击的认识,即使在强隔离保护敏感应用的情况下也是如此。以前的工作已经研究了使用手机加速度计和陀螺仪作为侧通道数据来推断PIN。在这里,我们描述了一种新的侧通道攻击,它利用摄像机和麦克风来推断在智能手机上仅限数字的软键盘上输入的PIN。麦克风用于检测触摸事件,而摄像头用于估计智能手机的方位,并将其与用户点击的手指位置相关联。我们介绍了PIN Skimmer的设计、实现和早期评估,它包含一个移动应用程序和一个服务器组件。移动应用程序收集触摸事件取向模式,然后使用学习的模式来推断在敏感应用程序中输入的PIN。当从50个4位PIN的测试集中进行选择时,在基于安卓系统的Nexus S和Galaxy S3手机上,PIN Skimmer在2次尝试后正确推断出30%以上的PIN,并在5次尝试后正确推断超过50%的PIN。当从一组200个8位PIN中选择时,PIN Skimmer在5次尝试后正确推断出约45%的PIN,在10次尝试后正确推断出60%的PIN。事实证明,很难防止这样的旁路攻击,所以我们为开发人员提供了指导方针,以减轻目前和未来对PIN输入的旁路攻击。
Today's smartphones provide services and uses that required a panoply of dedicated devices not so long ago. With them, we listen to music, play games or chat with our friends; but we also read our corporate email and documents, manage our online banking; and we have started to use them directly as a means of payment. In this paper, we aim to raise awareness of side-channel attacks even when strong isolation protects sensitive applications. Previous works have studied the use of the phone accelerometer and gyroscope as side channel data to infer PINs. Here, we describe a new side-channel attack that makes use of the video camera and microphone to infer PINs entered on a number-only soft keyboard on a smartphone. The microphone is used to detect touch events, while the camera is used to estimate the smartphone's orientation, and correlate it to the position of the digit tapped by the user. We present the design, implementation and early evaluation of PIN Skimmer, which has a mobile application and a server component. The mobile application collects touch-event orientation patterns and later uses learnt patterns to infer PINs entered in a sensitive application. When selecting from a test set of 50 4-digit PINs, PIN Skimmer correctly infers more than 30% of PINs after 2 attempts, and more than 50% of PINs after 5 attempts on android-powered Nexus S and Galaxy S3 phones. When selecting from a set of 200 8-digit PINs, PIN Skimmer correctly infers about 45% of the PINs after 5 attempts and 60% after 10 attempts. It turns out to be difficult to prevent such side-channel attacks, so we provide guidelines for developers to mitigate present and future side-channel attacks on PIN input.