Don ’ t touch a word ! A practical input eavesdropping attack against mobile touchscreen devices

نویسندگان

  • Federico Maggi
  • Alberto Volpatto
  • Simone Gasparini
  • Giacomo Boracchi
  • Stefano Zanero
چکیده

Spying on a person is a subtle, yet easy and reliable method to obtain sensitive information. Even if the victim is well protected from digital attacks, spying may be a viable option. In addition, the pervasiveness of mobile devices increases an attacker’s opportunities to observe the victims while they are accessing or entering sensitive information. This risk is exacerbated by the remarkable user-friendliness of modern, mobile graphical interfaces, which, for example, display visual feedback to improve the user experience and make common tasks, e.g., typing, more natural. Unfortunately, this turns into the well-known trade-off between usability and security. In this work, we focus on how usability of modern mobile interfaces may affect the users’ privacy. In particular, we describe a practical eavesdropping attack, able to recognize the sequence of keystrokes from a low-resolution video, recorded while the victim is typing on a touchscreen. Our attack exploits the fact that modern virtual keyboards, as opposed to mechanical ones, often display magnified, virtual keys in predictable positions. To demonstrate the feasibility of this attack we implemented it against 2010’s most popular smart-phone, i.e., the iPhone. Our approach works under realistic conditions, because it tracks and rectifies the target screen according to the victim’s natural movements, before performing the keystroke recognition. On real-world settings, our attack can automatically recognize up to 97.07% (91.03% on average) of the keystrokes, with a 1.15% error rate and a speed between 37 and 51 keystrokes per minute. This work confirms that touchscreen keyboards that magnify keys make automatic eavesdropping attacks easier than in classic mobile keyboards.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Features Extraction Scheme for Behavioural Biometric Authentication in Touchscreen Mobile Devices

Today, mobile devices are being widely used in personal and professional life. By increasing the popularity of touchscreen platform as an input method in mobiles phones, touch gesture behaviour is becoming more significantly important in interaction with the phone. Due to increasing demand for safer access in touchscreen mobile phones, old strategies like pins, tokens, or passwords have failed ...

متن کامل

Evaluation of User Interface Design and Input Methods for Applications on Mobile Touch Screen Devices

With the advent of touch screen phones, good UI design and simplified input methods for applications running on such devices are important factors that contribute to its popularity and success. The goal of this research is to evaluate different user interface designs and input methods for mobile phones with touch screen capability. In order to do this, two prototypes of a simple social networki...

متن کامل

Expanding the Vocabulary of Multitouch Input using Magnetic Fingerprints

We present magnetic fingerprints; an input technique for mobile touchscreen devices that uses a small magnet attached to a user’s fingernail in order to differentiate between a normal touch and a magnetic touch. The polarity of the magnet can be used to create different magnetic fingerprints where this technique takes advantage of the rich vocabulary offered by the use of multitouch input. User...

متن کامل

Learning from HCI: Understanding Children’s Input Behaviors on Mobile Touchscreen Devices

We posit that building effective educational technology requires elements from two fields of research: learning sciences (LS), for effective pedagogical interventions, and humancomputer interaction (HCI), for usable interactive experiences. In this paper, we present our work, grounded in HCI methods, to understand patterns in children's input behaviors in both the touch and gesture modalities o...

متن کامل

Augmenting Surface Interaction through Context-Sensitive Mobile Devices

We discuss the benefits of using a mobile device to expand and improve the interactions on a large touch-sensitive surface. The mobile device’s denser arrangement of pixels and touch-sensor elements, and its rich set of mechanical on-board input controls, can be leveraged for increased expressiveness, visual feedback and more precise direct-manipulation. We also show how these devices can suppo...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011