Device Risk Analysis Protocol for SMS-Based OTP Authentication

被引:0
|
作者
Bartlomiejczyk, Maciej [1 ]
El Fray, Imed [1 ]
机构
[1] West Pomeranian Univ Technol, Fac Comp Sci & Informat Technol, PL-70310 Szczecin, Poland
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Authentication; Codes; Malware; Phishing; Protocols; Message services; Brute force attacks; Mobile security; malware attacks; mobile device security; risk assessment protocol; SMS one-time password (OTP); two-factor authentication (2FA); ANDROID MALWARE DETECTION; TIME PASSWORD; SECURITY;
D O I
10.1109/ACCESS.2024.3445931
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Two-factor authentication (2FA) is widely recognized as a secure authentication method. Despite the availability of multiple authentication methods, SMS one-time password (OTP) remains popular. However, SMS OTP is vulnerable to several attacks that pose a significant threat to the authentication process. Due to the risk of attacks, particularly those based on social engineering and malware related to endpoint compromise, the National Institute of Standards and Technology (NIST) has removed SMS OTP as a recommended delivery channel. This paper analyses two different variants of passive and active malware attacks on SMS OTP for Android mobile devices. In response to the identified threats, a risk assessment protocol is proposed. This protocol includes a malware detection algorithm to assess device risk and determine whether SMS OTP can be used for user authentication. The security level of the authentication process depends on the user's specific device. The proposed malware detection algorithm was tested on publicly available applications provided by users participating in the research. Two application datasets were scanned during the research. The first dataset consisted of 520 applications available on the Play Store, and the second dataset consisted of 1,200 applications provided by users who participated in the research.
引用
收藏
页码:123177 / 123192
页数:16
相关论文
共 50 条
  • [41] GEMS: SMS-based app store for Growth Economies
    Risi, Daniel
    Teofilo, Mauro Ricardo da S.
    Silva, Thomaz Philippe C.
    2013 IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE (CCNC), 2013, : 855 - 856
  • [42] SMS-Based Platform for Cardiovascular Tele-Monitoring
    Triventi, M.
    Mattei, E.
    Censi, F.
    Calcagnini, G.
    Mastrantonio, F.
    Giansanti, D.
    Maccioni, G.
    Macellari, V.
    Bartolini, P.
    COMPUTERS IN CARDIOLOGY 2008, VOLS 1 AND 2, 2008, : 1009 - +
  • [43] The design and implementation of a SMS-based mobile learning system
    Zhang, Long
    Shan, Linlin
    Wang, Jianhua
    Lecture Notes in Electrical Engineering, 2012, 137 LNEE : 107 - 113
  • [44] A SMS-Based Mobile Botnet Using Flooding Algorithm
    Hua, Jingyu
    Sakurai, Kouichi
    INFORMATION SECURITY THEORY AND PRACTICE: SECURITY AND PRIVACY OF MOBILE DEVICES IN WIRELESS COMMUNICATION, 2011, 6633 : 264 - 279
  • [45] An Efficient SMS-Based Framework for Public Health Surveillance
    Mondal, Prasenjit
    Desai, Prashant
    Ghosh, Soumya K.
    Mukherjee, Jayanta
    2013 IEEE POINT-OF-CARE HEALTHCARE TECHNOLOGIES (PHT), 2013, : 244 - 247
  • [46] The Design and Implementation of a SMS-Based Mobile Learning System
    Shan, L-L.
    Zhang, Long
    Wang, J-H.
    2011 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION AND INDUSTRIAL APPLICATION (ICIA2011), VOL IV, 2011, : 523 - 526
  • [47] SMS-based reconfigurable automatic meter reading system
    Abdollahi, Ali
    Dehghani, Marjan
    Zamanzadeh, Negar
    PROCEEDINGS OF THE 2007 IEEE CONFERENCE ON CONTROL APPLICATIONS, VOLS 1-3, 2007, : 471 - 475
  • [48] Multilingual SMS-based author profiling: Data and methods
    Fatima, Mehwish
    Anwar, Saba
    Naveed, Amna
    Arshad, Waqas
    Nawab, Rao Muhammad Adeel
    Iqbal, Muntaha
    Masood, Alia
    NATURAL LANGUAGE ENGINEERING, 2018, 24 (05) : 695 - 724
  • [49] SMS-Based Urban Public Traffic Query Service
    Wan, Benting
    2008 SECOND INTERNATIONAL CONFERENCE ON FUTURE GENERATION COMMUNICATION AND NETWORKING SYMPOSIA, VOLS 1-5, PROCEEDINGS, 2008, : 61 - 64
  • [50] Poster: Testing the Efficacy of an SMS-Based Tutoring System
    Mahmood, Rashid
    Naseem, Mustafa
    Waqar, Yasira
    MOBISYS'16: COMPANION COMPANION PUBLICATION OF THE 14TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS, APPLICATIONS, AND SERVICES, 2016, : 52 - 52