Characterizing the Security Implications of Third-Party Emergency Alert Systems over Cellular Text Messaging Services

被引:10
|
作者
Traynor, Patrick [1 ]
机构
[1] Georgia Inst Technol, Lab Georgia Tech Informat Secur Ctr GTISC, Converging Infrastruct Secur CISEC, Atlanta, GA 30332 USA
基金
美国国家科学基金会;
关键词
SMS; campus alert; denial of service; security; ATTACKS; NETWORK;
D O I
10.1109/TMC.2011.120
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cellular text messaging services are increasingly being relied upon to disseminate critical information during emergencies. Accordingly, a wide range of organizations including colleges and universities now partner with third-party providers that promise to improve physical security by rapidly delivering such messages. Unfortunately, these products do not work as advertised due to limitations of cellular infrastructure and therefore provide a false sense of security to their users. In this paper, we perform the first extensive investigation and characterization of the limitations of an Emergency Alert System (EAS) using text messages as a security incident response mechanism. We show emergency alert systems built on text messaging not only can meet the 10 minute delivery requirement mandated by the WARN Act, but also potentially cause other voice and SMS traffic to be blocked at rates upward of 80 percent. We then show that our results are representative of reality by comparing them to a number of documented but not previously understood failures. Finally, we analyze a targeted messaging mechanism as a means of efficiently using currently deployed infrastructure and third-party EAS. In so doing, we demonstrate that this increasingly deployed security infrastructure does not achieve its stated requirements for large populations.
引用
收藏
页码:983 / 994
页数:12
相关论文
共 10 条
  • [1] Characterizing the Security Implications of Third-Party Emergency Alert Systems over Cellular Text Messaging Services
    Traynor, Patrick
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, 2010, 50 : 125 - 143
  • [2] Security Implications of Third-Party Accelerators
    Olson, Lena E.
    Sethumadhavan, Simha
    Hill, Mark D.
    IEEE COMPUTER ARCHITECTURE LETTERS, 2016, 15 (01) : 50 - 53
  • [3] Security Implications of Using Third-Party Resources in the World Wide Web
    Podins, Karlis
    Lavrenovs, Arturs
    2018 IEEE 6TH WORKSHOP ON ADVANCES IN INFORMATION, ELECTRONIC AND ELECTRICAL ENGINEERING (AIEEE), 2018,
  • [4] Cloud security in a bioanalytical world: considerations for use of third-party cloud services for bioanalysis
    Davis, Scott
    Mitra-Kaushik, Shibani
    Woolf, Eric
    Evens, John
    Dawes, Michelle
    Kentner, Jason
    Subbarao, Nanda
    Sundman, Phillip
    Rusnak, David
    BIOANALYSIS, 2023, 15 (24) : 1461 - 1468
  • [5] Third-party funding and counselling in New Zealand: Implications for counselling services and professional autonomy
    Miller J.H.
    International Journal for the Advancement of Counselling, 2004, 26 (3) : 285 - 299
  • [6] Datafied mobile markets: Measuring control over apps, data accesses, and third-party services
    Flensburg, Sofie
    Lai, Signe S.
    MOBILE MEDIA & COMMUNICATION, 2022, 10 (01) : 136 - 155
  • [7] Genotype Extraction and False Relative Attacks: Security Risks to Third-Party Genetic Genealogy Services Beyond Identity Inference
    Ney, Peter
    Ceze, Luis
    Kohno, Tadayoshi
    27TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2020), 2020,
  • [8] Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant Systems
    Zhang, Nan
    Mi, Xianghang
    Feng, Xuan
    Wang, XiaoFeng
    Tian, Yuan
    Qian, Feng
    2019 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2019), 2019, : 1381 - 1396
  • [9] Examining the brand trust and willingness to subscribe to third-party add-on services in over-the-top platforms: a brand trust transfer perspective
    Soren, Anup Anurag
    Chakraborty, Shibashish
    ASIA PACIFIC JOURNAL OF MARKETING AND LOGISTICS, 2024,
  • [10] Combined third-party ownership and aggregation business model for the adoption of rooftop solar PV-battery systems: Implications from the case of Miyakojima Island, Japan
    Yamashiro, Ririka
    Mori, Akihisa
    ENERGY POLICY, 2023, 173