No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your Typing

No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your Typing
复制标题

DOI:
10.1145/3243734.3243755
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Song Fang;Ian D. Markwood;Yao Liu;Shangqing Zhao;Zhuo Lu;Haojin Zhu
Song Fang;Ian D. Markwood;Yao Liu;Shangqing Zhao;Zhuo Lu;Haojin Zhu
中科院分区:
其他
文献类型:
--
作者:
Song Fang;Ian D. Markwood;Yao Liu;Shangqing Zhao;Zhuo Lu;Haojin Zhu

文献摘要

相似文献

窃听击键的传统方法利用目标计算机中安装的一些恶意软件来记录对手的击键。现有的研究工作已经确定了一类新的攻击,可以以非侵入性的方式窃听击键,而不会感染目标计算机以安装恶意软件。普遍的想法是,按下键盘上的某个键会引起独特且微妙的环境变化,窃听者可以捕获并分析该变化以了解击键。然而,对于这些攻击,必须完成训练阶段,以建立观察到的环境变化与按下特定键的操作之间的关系。这极大地限制了这些攻击的影响和实用性。在本文中,我们发现无需训练阶段即可设计击键窃听攻击。我们根据从无线信号中提取的信道状态信息来创建这种攻击。为了窃听击键,我们通过利用观察到的变化和字典单词的已知结构之间的相关性,在键入每个字母与其各自的环境变化之间建立映射。我们在软件定义的无线电平台上实施了这种攻击,并进行了一系列实验来验证这种攻击的影响。我们指出,本文并不建议使用无线信号来推断击键,因为此类工作已经存在。相反,本文的主要目标是提出新技术来消除培训过程,这可能使现有的工作变得不切实际。
Traditional methods to eavesdrop keystrokes leverage some malware installed in a target computer to record the keystrokes for an adversary. Existing research work has identified a new class of attacks that can eavesdrop the keystrokes in a non-invasive way without infecting the target computer to install a malware. The common idea is that pressing a key of a keyboard can cause a unique and subtle environmental change, which can be captured and analyzed by the eavesdropper to learn the keystrokes. For these attacks, however, a training phase must be accomplished to establish the relationship between an observed environmental change and the action of pressing a specific key. This significantly limits the impact and practicality of these attacks. In this paper, we discover that it is possible to design keystroke eavesdropping attacks without requiring the training phase. We create this attack based on the channel state information extracted from wireless signal. To eavesdrop keystrokes, we establish a mapping between typing each letter and its respective environmental change by exploiting the correlation among observed changes and known structures of dictionary words. We implement this attack on software-defined radio platforms and conduct a suite of experiments to validate the impact of this attack. We point out that this paper does not propose to use wireless signal for inferring keystrokes, since such work already exists. Instead, the main goal of this paper is to propose new techniques to remove the training process, which can make existing work unpractical.