Cracking Android Pattern Lock in Five Attempts

Cracking Android Pattern Lock in Five Attempts
复制标题

DOI:
10.14722/ndss.2017.23130
复制
发表时间:
2017-02
期刊:
--
影响因子:
--
通讯作者:
Guixin Ye;Zhanyong Tang;Dingyi Fang;Xiaojiang Chen;Kwang In Kim;Ben Taylor;Z. Wang
Guixin Ye;Zhanyong Tang;Dingyi Fang;Xiaojiang Chen;Kwang In Kim;Ben Taylor;Z. Wang
中科院分区:
其他
文献类型:
--
作者:
Guixin Ye;Zhanyong Tang;Dingyi Fang;Xiaojiang Chen;Kwang In Kim;Ben Taylor;Z. Wang

文献摘要

被引文献

相似文献

模式锁被广泛用作Android设备上的身份验证和授权机制。本文提出了一种新的基于视频的攻击,从使用移动的手机摄像头拍摄的视频片段中重建Android锁模式。与先前对模式锁的攻击不同,我们的方法不需要视频捕获屏幕上显示的任何内容。相反,我们采用计算机视觉算法来跟踪指尖运动,以推断模式。使用从跟踪的指尖运动中提取的几何信息,我们的方法是能够准确地识别少量(通常是一个)候选模式进行测试的对手。我们使用从215名独立用户收集的120种独特模式对我们的方法进行了彻底的评估,并将其应用于从使用智能手机摄像头拍摄的视频片段中重建模式。实验结果表明,我们的方法可以打破超过95%的模式,在五次尝试之前,设备被自动锁定的Android操作系统。我们发现,与许多人的看法相反,复杂的模式在我们的攻击场景下并不能提供更强的保护。这一点可以通过这样一个事实来证明:除了一个复杂的模式之外,我们能够打破所有的复杂模式(成功率为97.5%),而在第一次尝试中,简单模式的成功率为60%。由于我们的威胁模型在日常生活中很常见,本文呼吁社区重新审视使用Android模式锁保护敏感信息的风险。
Pattern lock is widely used as a mechanism for authentication and authorization on Android devices. This paper presents a novel video-based attack to reconstruct Android lock patterns from video footage filmed using a mobile phone camera. Unlike prior attacks on pattern lock, our approach does not require the video to capture any content displayed on the screen. Instead, we employ a computer vision algorithm to track the fingertip movements to infer the pattern. Using the geometry information extracted from the tracked fingertip motions, our approach is able to accurately identify a small number of (often one) candidate patterns to be tested by an adversary. We thoroughly evaluated our approach using 120 unique patterns collected from 215 independent users, by applying it to reconstruct patterns from video footage filmed using smartphone cameras. Experimental results show that our approach can break over 95% of the patterns in five attempts before the device is automatically locked by the Android operating system. We discovered that, in contrast to many people’s belief, complex patterns do not offer stronger protection under our attacking scenarios. This is demonstrated by the fact that we are able to break all but one complex patterns (with a 97.5% success rate) as opposed to 60% of the simple patterns in the first attempt. Since our threat model is common in day-to-day life, this paper calls for the community to revisit the risks of using Android pattern lock to protect sensitive information.