Device Risk Analysis Protocol for SMS-Based OTP Authentication

被引:0
|
作者
Bartlomiejczyk, Maciej [1 ]
El Fray, Imed [1 ]
机构
[1] West Pomeranian Univ Technol, Fac Comp Sci & Informat Technol, PL-70310 Szczecin, Poland
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Authentication; Codes; Malware; Phishing; Protocols; Message services; Brute force attacks; Mobile security; malware attacks; mobile device security; risk assessment protocol; SMS one-time password (OTP); two-factor authentication (2FA); ANDROID MALWARE DETECTION; TIME PASSWORD; SECURITY;
D O I
10.1109/ACCESS.2024.3445931
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Two-factor authentication (2FA) is widely recognized as a secure authentication method. Despite the availability of multiple authentication methods, SMS one-time password (OTP) remains popular. However, SMS OTP is vulnerable to several attacks that pose a significant threat to the authentication process. Due to the risk of attacks, particularly those based on social engineering and malware related to endpoint compromise, the National Institute of Standards and Technology (NIST) has removed SMS OTP as a recommended delivery channel. This paper analyses two different variants of passive and active malware attacks on SMS OTP for Android mobile devices. In response to the identified threats, a risk assessment protocol is proposed. This protocol includes a malware detection algorithm to assess device risk and determine whether SMS OTP can be used for user authentication. The security level of the authentication process depends on the user's specific device. The proposed malware detection algorithm was tested on publicly available applications provided by users participating in the research. Two application datasets were scanned during the research. The first dataset consisted of 520 applications available on the Play Store, and the second dataset consisted of 1,200 applications provided by users who participated in the research.
引用
收藏
页码:123177 / 123192
页数:16
相关论文
共 50 条
  • [1] SMS OTP Security (SOS): Hardening SMS-Based Two Factor Authentication
    Peeters, Christian
    Patton, Christopher
    Munyaka, Imani N. S.
    Olszewski, Daniel
    Shrimpton, Thomas
    Traynor, Patrick
    ASIA CCS'22: PROCEEDINGS OF THE 2022 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2022, : 2 - 16
  • [2] An Enhanced SMS-based OTP Scheme
    Zhou, Yonghe
    Hu, Liang
    Chu, Jianfeng
    PROCEEDINGS OF THE 2017 2ND INTERNATIONAL CONFERENCE ON AUTOMATION, MECHANICAL CONTROL AND COMPUTATIONAL ENGINEERING (AMCCE 2017), 2017, 118 : 1091 - 1094
  • [3] Strengthening SMS-Based Authentication through Usability
    AlZomai, Mohammed
    Josang, Audun
    McCullagh, Adrian
    Foo, Ernest
    PROCEEDINGS OF THE 2008 INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS, 2008, : 683 - +
  • [4] Enhanced Multi-factor Out-of-Band Authentication En Route to Securing SMS-based OTP
    Reyes, Ariel Roy L.
    Festijo, Enrique D.
    Medina, Ruji P.
    INTERNATIONAL JOURNAL OF ENGINEERING AND TECHNOLOGY INNOVATION, 2019, 9 (02) : 145 - 154
  • [5] Resetting Your Password Is Vulnerable: A Security Study of Common SMS-Based Authentication in IoT Device
    Wang, Dong
    Zhang, Xiaosong
    Ming, Jiang
    Chen, Ting
    Wang, Chao
    Niu, Weina
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2018,
  • [6] A Novel Protocol For the Security of SMS-Based Mobile Banking
    Abolghasemi, Meer Soheil
    Rezapour, Taha Yasin
    Atani, Reza Ebrahimi
    2013 5TH CONFERENCE ON INFORMATION AND KNOWLEDGE TECHNOLOGY (IKT), 2013, : 97 - 101
  • [7] A SMS-Based Authentication Approach for Electronic Health Record in Cloud Environment
    Arya, Pradeep Kumar
    Selvamani, K.
    Kannan, A.
    JOURNAL OF MEDICAL IMAGING AND HEALTH INFORMATICS, 2016, 6 (07) : 1625 - 1630
  • [8] A STAND-ALONE AND SMS-BASED APPROACH FOR AUTHENTICATION USING MOBILE PHONE
    Indu, S.
    Sathya, T. N.
    Kumar, Saravana, V
    2013 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2013, : 140 - 145
  • [9] A secure end-to-end SMS-based mobile banking protocol
    Bojjagani, Sriramulu
    Sastry, V. N.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (15)
  • [10] SSMBP: A Secure SMS-based Mobile Banking Protocol with Formal Verification
    Bojjagani, Sriramulu
    Sastry, V. N.
    2015 IEEE 11TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2015, : 252 - 259