報告簡介:
In this presentation, we introduce a novel computer vision based attack that automatically discloses inputs on a touch enabled device. Our spying camera, including Google Glass, can take a video of the victim tapping on the touch screen and automatically recognize more than 90% of the tapped passcodes from three meters away, even if our naked eyes cannot see those passcodes or anything on the touch screen. The basic idea is to track the movement of the fingertip and use the fingertip's relative position on the touch screen to recognize the touch input. We carefully analyze the shadow formation around the fingertip, apply the optical flow, deformable part-based model (DPM) object detector, k-means clustering and other computer vision techniques to automatically track the touching fingertip and locate the touched points. Planar homography is then applied to map the estimated touched points to a software keyboard in a reference image. Our work is substantially different from related work on blind recognition of touch inputs. We target passcodes where no language model can be applied to correct estimated touched keys. We are interested in scenarios such as conferences and similar gathering places where a Google Glass, webcam, or smartphone can be used for a stealthy attack. Extensive experiments were performed to demonstrate the impact of this attack. As a countermeasure, we design a context aware Privacy Enhancing Keyboard (PEK) which pops up a randomized keyboard on Android systems for sensitive information such as password inputs and shows a conventional QWERTY keyboard for normal inputs.
報告人簡介:
付新文博士是馬薩諸塞大學洛厄爾分校(University of Massachusetts Lowell)計算機系副教授,網絡取證中心主任。他于1995年在中國西安交通大學獲得電子工程學士學位,1998年 在中國科技大學獲得電子工程碩士學位,2005年在美國德克薩斯A&M大學獲得計算機工程博士學位。他的主要研究方向為網絡安全與隐私,數字取 證,信息保障,系統可靠性與網絡QoS,無線網絡。
付新文博士在2008年由于在北達科他州立大學傑出的科研工作他獲得了Merrill Hunter Award。他在IEEE ICC 2008,2013和WASA 2013獲得最佳論文獎,在2011年獲得馬薩諸塞大學洛厄爾分校計算機系教學獎,同年他指導的博士生在ACM MobiCom獲得ACM 研究生研究競賽的銀牌。
付新文教授已在安全學術會議和期刊發表了100餘篇研究論文,其中在IEEE S&P (Oakland),ACM CCS,ACM Mobihoc,IEEE INFOCOM以及ICDCS等 國際頂級會議以及 ACM/IEEE Transactions on Networking (ToN),IEEE Transactions on Parallel and Distributed Systems (TPDS),IEEE Transactions on Computers (TC),IEEE Transaction on Mobile Computing (TMC),IEEE Transactions on Vehicular Technology (TVT)等國際期刊上發表論文數十篇。他撰寫網絡流量分析書籍1本,參與撰寫相關網絡安全書籍5本。 他在各種知名技術安全會議上發表演講,包括Black Hat。在2005-2014年期間他的研究工作獲得了10餘個項目資助,其中得到了美國NSF 130餘萬美元項目的資助。
付新文教授是ACM、IEEE會員,擔任IEEE TrustCom2010,Globecom2011國際會議程序委員會副主席,ICNC2015安全分會程序委員會主席和IEEE INFOCOM、IEEE ICDCS、SecureComm和DFRWS國際會議的程序委員會委員。