Niffler: A Context-Aware and User-Independent Side-Channel Attack System for Password Inference

Joint Authors

Tang, Benxiao
Wang, Run
Zhao, Lei
Wang, Lina
Wang, Zhibo

Source

Wireless Communications and Mobile Computing

Issue

Vol. 2018, Issue 2018 (31 Dec. 2018), pp.1-19, 19 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2018-05-08

Country of Publication

Egypt

No. of Pages

19

Main Subjects

Information Technology and Computer Science

Abstract EN

Digital password lock has been commonly used on mobile devices as the primary authentication method.

Researches have demonstrated that sensors embedded on mobile devices can be employed to infer the password.

However, existing works focus on either each single keystroke inference or entire password sequence inference, which are user-dependent and require huge efforts to collect the ground truth training data.

In this paper, we design a novel side-channel attack system, called Niffler, which leverages the user-independent features of movements of tapping consecutive buttons to infer unlocking passwords on smartphones.

We extract angle features to reflect the changing trends and build a multicategory classifier combining the dynamic time warping algorithm to infer the probability of each movement.

We further use the Markov model to model the unlocking process and use the sequences with the highest probabilities as the attack candidates.

Moreover, the sensor readings of successful attacks will be further fed back to continually improve the accuracy of the classifier.

In our experiments, 100,000 samples collected from 25 participants are used to evaluate the performance of Niffler.

The results show that Niffler achieves 70% and 85% accuracy with 10 attempts in user-independent and user-dependent environments with few training samples, respectively.

American Psychological Association (APA)

Tang, Benxiao& Wang, Zhibo& Wang, Run& Zhao, Lei& Wang, Lina. 2018. Niffler: A Context-Aware and User-Independent Side-Channel Attack System for Password Inference. Wireless Communications and Mobile Computing،Vol. 2018, no. 2018, pp.1-19.
https://search.emarefa.net/detail/BIM-1216039

Modern Language Association (MLA)

Tang, Benxiao…[et al.]. Niffler: A Context-Aware and User-Independent Side-Channel Attack System for Password Inference. Wireless Communications and Mobile Computing No. 2018 (2018), pp.1-19.
https://search.emarefa.net/detail/BIM-1216039

American Medical Association (AMA)

Tang, Benxiao& Wang, Zhibo& Wang, Run& Zhao, Lei& Wang, Lina. Niffler: A Context-Aware and User-Independent Side-Channel Attack System for Password Inference. Wireless Communications and Mobile Computing. 2018. Vol. 2018, no. 2018, pp.1-19.
https://search.emarefa.net/detail/BIM-1216039

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1216039