Device Risk Analysis Protocol for SMS-Based OTP Authentication

被引:0
|
作者
Bartlomiejczyk, Maciej [1 ]
El Fray, Imed [1 ]
机构
[1] West Pomeranian Univ Technol, Fac Comp Sci & Informat Technol, PL-70310 Szczecin, Poland
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Authentication; Codes; Malware; Phishing; Protocols; Message services; Brute force attacks; Mobile security; malware attacks; mobile device security; risk assessment protocol; SMS one-time password (OTP); two-factor authentication (2FA); ANDROID MALWARE DETECTION; TIME PASSWORD; SECURITY;
D O I
10.1109/ACCESS.2024.3445931
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Two-factor authentication (2FA) is widely recognized as a secure authentication method. Despite the availability of multiple authentication methods, SMS one-time password (OTP) remains popular. However, SMS OTP is vulnerable to several attacks that pose a significant threat to the authentication process. Due to the risk of attacks, particularly those based on social engineering and malware related to endpoint compromise, the National Institute of Standards and Technology (NIST) has removed SMS OTP as a recommended delivery channel. This paper analyses two different variants of passive and active malware attacks on SMS OTP for Android mobile devices. In response to the identified threats, a risk assessment protocol is proposed. This protocol includes a malware detection algorithm to assess device risk and determine whether SMS OTP can be used for user authentication. The security level of the authentication process depends on the user's specific device. The proposed malware detection algorithm was tested on publicly available applications provided by users participating in the research. Two application datasets were scanned during the research. The first dataset consisted of 520 applications available on the Play Store, and the second dataset consisted of 1,200 applications provided by users who participated in the research.
引用
收藏
页码:123177 / 123192
页数:16
相关论文
共 50 条
  • [31] Evaluation of MyTeen - a SMS-based mobile intervention for parents of adolescents: a randomised controlled trial protocol
    Chu, Joanna Ting Wai
    Whittaker, Robyn
    Jiang, Yannan
    Wadham, Angela
    Stasiak, Karolina
    Shepherd, Matthew
    Bullen, Chris
    BMC PUBLIC HEALTH, 2018, 18
  • [32] Evaluation of MyTeen – a SMS-based mobile intervention for parents of adolescents: a randomised controlled trial protocol
    Joanna Ting Wai Chu
    Robyn Whittaker
    Yannan Jiang
    Angela Wadham
    Karolina Stasiak
    Matthew Shepherd
    Chris Bullen
    BMC Public Health, 18
  • [33] OTP_SAM: DHCP security authentication model based on OTP
    Zhang, Fuqiang
    Chen, Lin
    2016 IEEE 20th International Conference on Computer Supported Cooperative Work in Design (CSCWD), 2016, : 346 - 350
  • [34] The Design and Implementation of a SMS-Based Mobile Learning System
    Shan, L. -L.
    Zhang, Long
    Wang, J. -H.
    2010 SECOND INTERNATIONAL CONFERENCE ON E-LEARNING, E-BUSINESS, ENTERPRISE INFORMATION SYSTEMS, AND E-GOVERNMENT (EEEE 2010), VOL II, 2010, : 186 - 189
  • [35] SMS Goes Nuclear: Fortifying SMS-Based MFA in Online Account Ecosystem
    Jin, Weizhao
    Ji, Xiaoyu
    He, Ruiwen
    Zhuang, Zhou
    Xu, Wenyuan
    Tian, Yuan
    51ST ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN-W 2021), 2021, : 7 - 14
  • [36] Trusted SMS - A novel framework for non-repudiable SMS-based processes
    Grillo, Antonio
    Lentini, Alessandro
    Me, Gianlugi
    Rulli, Giuliano
    HEALTHINF 2008: PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON HEALTH INFORMATICS, VOL 1, 2008, : 43 - +
  • [37] Business Model for SMS-Based Government Services: an Analysis from Configuration Theory
    Brasileiro Lanza, Beatriz Barreto
    9TH INTERNATIONAL CONFERENCE ON THEORY AND PRACTICE OF ELECTRONIC GOVERNANCE (ICEGOV 2016), 2016, : 420 - 423
  • [38] A SMS-Based Platform for Cardiovascular Tele-monitoring
    Triventi, M.
    Mattei, E.
    Censi, F.
    Calcagnini, G.
    Strano, Stefano
    Bartolini, P.
    WORLD CONGRESS ON MEDICAL PHYSICS AND BIOMEDICAL ENGINEERING, VOL 25, PT 5, 2009, 25 : 295 - +
  • [39] Impact of SMS-Based Agricultural Information on Indian Farmers
    Fafchamps, Marcel
    Minten, Bart
    WORLD BANK ECONOMIC REVIEW, 2012, 26 (03): : 383 - 414
  • [40] The RFID Mutual Authentication scheme Based on FCC and OTP Authentication
    Chen, Chunling
    Wang, Yang
    Yu, Han
    Qiang, Xiao-Hui
    2016 IEEE INTERNATIONAL CONFERENCE ON UBIQUITOUS WIRELESS BROADBAND (ICUWB2016), 2016,