Mobile Pickpocketing: Exfiltration of Sensitive Data through NFC-enabled Mobile Devices

نویسندگان

  • Ryan Caney
  • Christopher Dorros
  • Stuart Kennedy
  • Gregory Owens
  • Patrick Tague
چکیده

With the increasing popularity of Near field communication (NFC) in consumer-off-the-shelf devices, more and more applications are taking advantage of the technology in innovative ways. Unfortunately, with the rise of NFC applications, there emerges a variety of vulnerabilities that could leave an unwitting user vulnerable to a data breach. One such potentially devastating attack is mobile pickpocketing, in which an attacker uses a standard NFC-enabled device to read, store, and transmit unprotected personally identifiable information from cards carried by unsuspecting bystanders. In this paper, we detail the mobile pickpocketing threat, describe inherent vulnerabilities in today’s NFC landscape, and explain how easy it is for a malicious user to exploit them. We define physical and distributed models of the attack. We walk through our experience developing a mobile pickpocketing application, including the capabilities of the application on particular NFC-enabled devices. Finally, we explore short-term and long-term defenses against mobile pickpocketing attacks.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Mobile Pickpocketing: Exfiltration of Sensitive Data through NFC-enabled Mobile Devices (CMU-CyLab-13-015)

With the increasing popularity of Near field communication (NFC) in consumer-off-the-shelf devices, more and more applications are taking advantage of the technology in innovative ways. Unfortunately, with the rise of NFC applications, there emerges a variety of vulnerabilities that could leave an unwitting user vulnerable to a data breach. One such potentially devastating attack is mobile pick...

متن کامل

Relay Attacks on Secure Element-Enabled Mobile Devices - Virtual Pickpocketing Revisited

Near Field Communication’s card emulation mode is a way to combine smartcards with a mobile phone. Relay attack scenarios are well-known for contactless smartcards. In the past, relay attacks have only been considered for the case, where an attacker has physical proximity to an NFC-enabled mobile phone. However, a mobile phone introduces a significantly di↵erent threat vector. A mobile phone’s ...

متن کامل

Application of Near Field Communication Technology for Mobile Airline Ticketing

Problem statement: Near Field Communication (NFC) technology opens up exciting new usage scenarios for mobile devices based platform. Users of NFC-enabled devices can simply point or touch their devices to other NFC-enabled elements in the environment to communicate with them (‘contactless’), making application and data usage easy and convenient. Approach: The study describes the characteristic...

متن کامل

Prevention of Relay Attack Using NFC

Near Field Communication (NFC) is one of the emerging and promising technological developments for mobile phones and other contactless devices. NFC technologies allow two active devices embedded with chip transmit small pieces of data between each other via short range wireless connection and at low speed depending on the configurations. It offers low friction process because of the close range...

متن کامل

Connecting Mobile Phones to the Internet of Things: A Discussion of Compatibility Issues Between EPC and NFC

Near Field Communication devices and Electronic Product Code tags are two important RFID based solutions which have matured to market-readiness within the last years. Though both standards are based on the same technological foundation, there are some significant differences as to the goals that their developers intend to achieve through their use. Mobile phones are the most popular personal de...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013