CRII: SaTC: Towards Understanding Typing Privacy: Vulnerabilities and Protection
CRII: SaTC: Towards Understanding Typing Privacy: Vulnerabilities and Protection
批准号:
1948547
负责人:
Song Fang
金额:
$17.48万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-03-01 至 2023-12-31
中文摘要
打字无处不在,在人与计算机设备的交互中扮演着重要的角色。新出现的研究发现了一类攻击,这种攻击可以以非侵入性的方式窃听按键,而不会预先用恶意软件感染目标计算机。它们共同的基本原理是,按下键盘上的某个键会导致该键特有的微妙环境影响,所有键都可以观察到这一点并进行关联。然而,这些技术需要一个培训阶段,以确定观察到的环境变化与按下特定键的动作之间的关系。这样的训练阶段对于大多数攻击场景来说是不切实际的。该项目发现了一种不需要训练阶段的新型非侵入性击键推理技术。该项目的目标是系统地利用键盘打字过程中的副作用,了解新的安全威胁,并设计有效的防御机制来抵御此类攻击。该研究将开发一种新型的针对现实场景中字母和数字等输入的打字隐私推理技术,并建立相应的防御措施来保护打字隐私免受击键窃听攻击。该项目将提供一个亟需的洞察力,以了解打字隐私泄露的安全风险,并大幅提高各种带有键盘接口的计算机系统的安全性。这项研究的结果将公开分享。该项目还将为研究生和本科生提供在安全和隐私领域获得研究经验的机会。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Typing is ubiquitous and plays a significantly important role in the interaction between humans and computer devices. Emerging work has identified a class of attacks that can eavesdrop keystrokes in a non-invasive way without pre-infecting the target computer with malware. Their common underlying principle is that pressing a key on a keyboard causes subtle environmental impacts unique to that key, which can be observed and correlated for all keys. However, those techniques require a training phase to establish the relationship between an observed environmental change and the action of pressing a specific key. Such a training phase is impractical for most attack scenarios. This project identifies a new type of non-invasive keystroke inference technique without requiring the training phase. The goal of this project is to systematically exploit the side effects associated with the typing process via a keyboard, understand new security threats, and design effective defense mechanisms against such attacks.This research will develop a novel type of typing privacy inference technique targeting various input such as letters and numbers in real-world scenarios and build corresponding defenses to protect typing privacy against those keystroke eavesdropping attacks. The project will provide a much-needed insight into the security risks of typing privacy disclosure, and also substantially improve the security of various computer systems with keyboard interfaces. The results from this research will be openly shared. This project will also offer graduate and undergraduate students opportunities to gain research experience in security and privacy areas.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(14)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1016/j.smhl.2023.100400
发表时间:
2023-03
期刊:
Smart Health
影响因子:
--
作者:
[Jinmiao Chen;Zhaohe (John) Zhang;Shangqing Zhao;Song Fang;Thomas M. Peters;Evan L. Floyd;Changjie Cai-Chang]
通讯作者:
Jinmiao Chen;Zhaohe (John) Zhang;Shangqing Zhao;Song Fang;Thomas M. Peters;Evan L. Floyd;Changjie Cai-Chang
DOI:
10.1109/tdsc.2022.3141406
发表时间:
2023-01
期刊:
IEEE Transactions on Dependable and Secure Computing
影响因子:
7.3
作者:
[Qiuye He;Song Fang;Tao Wang;Yao-Hong Liu;Shangqing Zhao;Zhuo Lu]
通讯作者:
Qiuye He;Song Fang;Tao Wang;Yao-Hong Liu;Shangqing Zhao;Zhuo Lu
DOI:
10.1145/3576915.3623083
发表时间:
2023-11
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Yan He;Qiuye He;Song Fang;Yao Liu]
通讯作者:
Yan He;Qiuye He;Song Fang;Yao Liu
DOI:
10.1109/tmc.2023.3333272
发表时间:
2024-06
期刊:
IEEE Transactions on Mobile Computing
影响因子:
7.9
作者:
[Yan He;Qiuye He;Song Fang;Yao Liu]
通讯作者:
Yan He;Qiuye He;Song Fang;Yao Liu
DOI:
10.1145/3580252.3589420
发表时间:
2023-06
期刊:
2023 IEEE/ACM Conference on Connected Health: Applications, Systems and Engineering Technologies (CHASE)
影响因子:
--
作者:
[Jinmiao Chen;Zhaohe (John) Zhang;Shangqing Zhao;Song Fang;T. Peters;Evan L. Floyd;Changjie Cai]
通讯作者:
Jinmiao Chen;Zhaohe (John) Zhang;Shangqing Zhao;Song Fang;T. Peters;Evan L. Floyd;Changjie Cai
共 13 条
Travel: NSF Student Travel Grant for 2023 IEEE Symposium on Security and Privacy (IEEE S&P)
-
批准号:2311917
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2023
-
负责人:Song Fang
-
依托单位:
SaTC: CORE: Small: Exploiting Stimulus-response Correlation for Wireless Hidden Device Localization
-
批准号:2155181
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2022
-
负责人:Song Fang
-
依托单位:
Travel: NSF Student Travel Grant for 2022 IEEE Symposium on Security and Privacy (IEEE S&P)
-
批准号:2207471
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2022
-
负责人:Song Fang
-
依托单位:
海外基金