Cracking Android Pattern Lock in Five Attempts
Guixin Ye, Zhanyong Tang, Dingyi Fang, Xiaojiang Chen, Kwang In Kim, Ben Taylor, Zheng Wang
摘要
Pattern lock is widely used as a mechanism for authentication and authorization on Android devices. This paper presents a novel video-based attack to reconstruct Android lock patterns from video footage filmed using a mobile phone camera. Unlike prior attacks on pattern lock, our approach does not require the video to capture any content displayed on the screen. Instead, we employ a computer vision algorithm to track the fingertip movements to infer the pattern. Using the geometry information extracted from the tracked fingertip motions, our approach is able to accurately identify a small number of (often one) candidate patterns to be tested by an adversary. We thoroughly evaluated our approach using 120 unique patterns collected from 215 independent users, by applying it to reconstruct patterns from video footage filmed using smartphone cameras. Experimental results show that our approach can break over 95% of the patterns in five attempts before the device is automatically locked by the Android operating system. We discovered that, in contrast to many people's belief, complex patterns do not offer stronger protection under our attacking scenarios. This is demonstrated by the fact that we are able to break all but one complex patterns (with a 97.5% success rate) as opposed to 60% of the simple patterns in the first attempt. Since our threat model is common in day-to-day life, this paper calls for the community to revisit the risks of using Android pattern lock to protect sensitive information. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- PatternListener: Cracking Android Pattern Lock Using Acoustic SignalsMan Zhou, Qian Wang, Jingxiao Yang, Qi Li 等CCS 2018 · 被引用 79 次
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 被引用 62 次
- EyeTell: Video-Assisted Touchscreen Keystroke Inference from Eye MovementsYimin Chen, Tao Li, Rui Zhang, Yanchao Zhang 等S&P 2018 · 被引用 60 次
- Listen to Your Fingers: User Authentication Based on Geometry Biometrics of Touch GestureHuijie Chen, Fan Li, Wan Du, Song Yang 等UbiComp 2020 · 被引用 49 次
- WaveSpy: Remote and Through-wall Screen Attack via mmWave SensingZhengxiong Li, Fenglong Ma, Aditya Singh Rathore, Zhuolin Yang 等S&P 2020 · 被引用 40 次
相关 Paper
- Fine-Grained and Context-Aware Behavioral Biometrics for Pattern Lock on SmartphonesDai Shi, Dan Tao, Jiangtao Wang, Muyan Yao 等UbiComp 2021 · 被引用 36 次
- No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisWenrui Diao, Xiangyu Liu, Zhou Li, Kehuan ZhangS&P 2016 · 被引用 79 次
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel 等NDSS 2018 · 被引用 33 次
- SysPal: System-Guided Pattern Locks for AndroidGeumhwan Cho, Jun Ho Huh, Junsung Cho, Seongyeol Oh 等S&P 2017 · 被引用 54 次
- Towards a General Video-based Keystroke Inference AttackZhuolin Yang, Yuxin Chen, Zain Sarwar, Hadleigh Schwartz 等USENIX Security 2023
