The Eye as a New Side Channel Threat on Smartphones

被引:0
|
作者
Al-Haiqi, Ahmed [1 ]
Ismail, Mahamod [1 ]
Nordin, Rosdiadee [1 ]
机构
[1] Natl Univ Malaysia, Elect Elect & Syst Dept, Bangi, Malaysia
关键词
eye-based keystrokes inference; eye-tracking; side-channel; smartphone security; Android;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Eye tracking is not a new idea in human-computer interaction research. Since at least as early as 1990s, researchers have tried to utilize eye movement to drive or monitor user interaction with computers. The new idea is using eye movement tracking to breach the privacy of mobile users. In this paper, we study the feasibility of exploiting consumer-grade cameras built onto current smartphones to log eye gazes, and then estimating the keypad numbers being tapped by the user. Assuming Trojan applications with camera use permissions, this process could be implemented without the user contest or knowledge, imposing a potential new threat to the security and privacy of mobile users. Our approach does not involve machine learning methods. In these first preliminary proof-of-concept experiments, we mainly rely on a human attacker to manually analyze the collected images from the smartphone. Utilizing basic dimensionality and motion flow calculations, our results show a promising attack vector with more than 60% of taps inference accuracy.
引用
收藏
页码:475 / 479
页数:5
相关论文
共 50 条
  • [1] Side Channel Analysis On Android Smartphones
    Davarci, Erhan
    Soysal, Betul
    Erguler, Imran
    Anarim, Emin
    2016 24TH SIGNAL PROCESSING AND COMMUNICATION APPLICATION CONFERENCE (SIU), 2016, : 553 - 556
  • [2] Keyboard Side Channel Attacks on Smartphones using Sensor Fusion
    Murali, Nithin
    Appaiah, Kumar
    2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [3] Hybrid Side-Channel/Machine-Learning Attacks on PUFs: A New Threat?
    Xu, Xiaolin
    Burleson, Wayne
    2014 DESIGN, AUTOMATION AND TEST IN EUROPE CONFERENCE AND EXHIBITION (DATE), 2014,
  • [4] Smartphones and teenagers, threat or opportunity
    Guenaga, Mariluz
    Mentxaka, Iratxe
    Eguiluz, Andoni
    Romero, Susana
    Garcia Zubia, Javier
    2012 15TH INTERNATIONAL CONFERENCE ON INTERACTIVE COLLABORATIVE LEARNING (ICL), 2012,
  • [5] Threat on Physical Layer Security: Side Channel vs. Wiretap Channel
    Luo, Peng
    Li, Huiyun
    Xu, Guoqing
    Peng, Lei
    2013 IEEE 16TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE 2013), 2013, : 295 - 300
  • [6] Forensic Insights From Smartphones Through Electromagnetic Side-Channel Analysis
    Sayakkara, Asanka P.
    Le-Khac, Nhien-An
    IEEE ACCESS, 2021, 9 : 13237 - 13247
  • [7] Side Channel Attacks on Smartphones and Embedded Devices Using Standard Radio Equipment
    Gollerl, Gabriel
    Sigl, Georg
    CONSTRUCTIVE SIDE-CHANNEL ANALYSIS AND SECURE DESIGN, COSADE 2015, 2015, 9064 : 255 - 270
  • [8] Defensive Charging: Mitigating Power Side-Channel Attacks on Charging Smartphones
    Matovu, Richard
    Serwadda, Abdul
    Bilbao, Argenis V.
    Griswold-Steiner, Isaac
    PROCEEDINGS OF THE TENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, CODASPY 2020, 2020, : 179 - 190
  • [9] Side-Channel Analysis of Weierstrass and Koblitz Curve ECDSA on Android Smartphones
    Belgarric, Pierre
    Fouque, Pierre-Alain
    Macario-Rat, Gilles
    Tibouchi, Mehdi
    TOPICS IN CRYPTOLOGY - CT-RSA 2016, 2016, 9610 : 236 - 252
  • [10] Static Power Consumption as a New Side-Channel Analysis Threat to Elliptic Curve Cryptography Implementations
    Kabin, Ievgen
    Dyka, Zoya
    Sigourou, Alkistis-Aikaterini
    Langendoerfer, Peter
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 884 - 889