PILOT: Password and PIN Information Leakage from Obfuscated Typing Videos

PILOT: Password and PIN Information Leakage from Obfuscated Typing Videos
复制标题

DOI:
10.3233/jcs-191289
复制
发表时间:
2019-03
期刊:
ArXiv
影响因子:
--
通讯作者:
K. Balagani;M. Cardaioli;M. Conti;Paolo Gasti;Martin Georgiev;Tristan Gurtler;Daniele Lain;C. Miller;Kendall Molas;N. Samarin;Eugen Saraci;G. Tsudik;Lynn Wu
K. Balagani;M. Cardaioli;M. Conti;Paolo Gasti;Martin Georgiev;Tristan Gurtler;Daniele Lain;C. Miller;Kendall Molas;N. Samarin;Eugen Saraci;G. Tsudik;Lynn Wu
中科院分区:
其他
文献类型:
--
作者:
K. Balagani;M. Cardaioli;M. Conti;Paolo Gasti;Martin Georgiev;Tristan Gurtler;Daniele Lain;C. Miller;Kendall Molas;N. Samarin;Eugen Saraci;G. Tsudik;Lynn Wu

文献摘要

被引文献

相似文献

本文研究了用户密码和个人识别码的泄漏,这些用户密码和个人识别码是通过观察屏幕上或投影仪上以掩码字符形式表示击键的打字反馈来实现的。为此,我们开发了一种名为从混淆的打字视频中泄漏密码和个人识别码信息的攻击(试点)。我们的攻击从用户在计算机上输入密码或在自动取款机上输入PIN时显示的密码掩蔽字符的视频中提取击键间计时信息。我们在不同的攻击场景中进行了几次实验。结果表明,虽然在某些情况下泄漏很小,但在其他情况下却相当严重。通过利用击键间计时,Pilot只需19次尝试即可恢复8个字符的字母数字密码。在猜测PIN时,Pilot在随机猜测和我们先前工作中采用的攻击策略上都有显著改进[4]。特别是,我们在10次尝试中猜到了大约3%的PIN。与随机猜测相比,这相当于提高了26倍。我们的结果有力地表明,安全口令掩蔽图形用户界面必须考虑本文所识别的信息泄漏。
This paper studies leakage of user passwords and PINs based on observations of typing feedback on screens or from projectors in the form of masked characters that indicate keystrokes. To this end, we developed an attack called Password and Pin Information Leakage from Obfuscated Typing Videos (PILOT). Our attack extracts inter-keystroke timing information from videos of password masking characters displayed when users type their password on a computer, or their PIN at an ATM. We conducted several experiments in various attack scenarios. Results indicate that, while in some cases leakage is minor, it is quite substantial in others. By leveraging inter-keystroke timings, PILOT recovers 8-character alphanumeric passwords in as little as 19 attempts. When guessing PINs, PILOT significantly improved on both random guessing and the attack strategy adopted in our prior work [4]. In particular, we were able to guess about 3% of the PINs within 10 attempts. This corresponds to a 26-fold improvement compared to random guessing. Our results strongly indicate that secure password masking GUIs must consider the information leakage identified in this paper.