Forum for Science, Industry and Business
Sponsored by:     Siemens  n-tv 
Search our Site:

Topic (optional):

 

Home Reports Information Technology Content

Georgia Tech Turns iPhone Into spiPhone

next article
19.10.2011

It’s a pattern that no doubt repeats itself daily in hundreds of millions of offices around the world: People sit down, turn on their computers, set their mobile phones on their desks and begin to work. What if a hacker could use that phone to track what the person was typing on the keyboard just inches away?

 

A research team at Georgia Tech has discovered how to do exactly that, using a smartphone accelerometer—the internal device that detects when and how the phone is tilted—to sense keyboard vibrations and decipher complete sentences with up to 80 percent accuracy. The procedure is not easy, they say, but is definitely possible with the latest generations of smartphones.


“We first tried our experiments with an iPhone 3GS, and the results were difficult to read,” said Patrick Traynor, assistant professor in Georgia Tech’s School of Computer Science. “But then we tried an iPhone 4, which has an added gyroscope to clean up the accelerometer noise, and the results were much better. We believe that most smartphones made in the past two years are sophisticated enough to launch this attack.”

Previously, Traynor said, researchers have accomplished similar results using microphones, but a microphone is a much more sensitive instrument than an accelerometer. A typical smartphone’s microphone samples vibration roughly 44,000 times per second, while even newer phones’ accelerometers sample just 100 times per second—two full orders of magnitude less often. Plus, manufacturers have installed security around a phone’s microphone; the phone’s operating system is programmed to ask users whether to give new applications access to most built-in sensors, including the microphone. Accelerometers typically are not protected in this way.

The technique works through probability and by detecting pairs of keystrokes, rather than individual keys (which still is too difficult to accomplish reliably, Traynor said). It models “keyboard events” in pairs, then determines whether the pair of keys pressed is on the left versus right side of the keyboard, and whether they are close together or far apart. After the system has determined these characteristics for each pair of keys depressed, it compares the results against a preloaded dictionary, each word of which has been broken down along similar measurements (i.e., are the letters left/right, near/far on a standard QWERTY keyboard). Finally, the technique only works reliably on words of three or more letters.

For example, take the word “canoe,” which when typed breaks down into four keystroke pairs: “C-A, A-N, N-O and O-E.” Those pairs then translate into the detection system’s code as follows: Left-Left-Near, Left-Right-Far, Right-Right-Far and Right-Left-Far, or LLN-LRF-RRF-RLF. This code is then compared to the preloaded dictionary and yields “canoe” as the statistically probable typed word. Working with dictionaries comprising about 58,000 words, the system reached word-recovery rates as high as 80 percent.

“The way we see this attack working is that you, the phone’s owner, would request or be asked to download an innocuous-looking application, which doesn’t ask you for the use of any suspicious phone sensors,” said Henry Carter, a PhD student in computer science and one of the study’s co-authors. “Then the keyboard-detection malware is turned on, and the next time you place your phone next to the keyboard and start typing, it starts listening.”

Mitigation strategies for this vulnerability are pretty simple and straightforward, Traynor said. First, since the study found an effective range of just three inches from a keyboard, phone users can simply leave their phones in their purses or pockets, or just move them further away from the keyboard. But a fix that puts less onus on users is to add a layer of security for phone accelerometers.

“The sampling rate for accelerometers is already pretty low, and if you cut it in half, you start to approach theoretical limitations that prevent eavesdropping. The malware simply does not have the data to work with,” Traynor said. “But most phone applications can still function even with that lower accelerometer rate. So manufacturers could set that as the default rate, and if someone downloads an application like a game that needs the higher sampling rate, that would prompt a permission question to the user to reset the accelerometer.”

In the meantime, Traynor said, users shouldn’t be paranoid that hackers are tracking their keystrokes through their iPhones.

“The likelihood of someone falling victim to an attack like this right now is pretty low,” he said. “This was really hard to do. But could people do it if they really wanted to? We think yes.”

The finding is reported in the paper, “(sp)iPhone: Decoding Vibrations From Nearby Keyboards Using Mobile Phone Accelerometers,” and will be presented Thursday, Oct. 20, at the 18th ACM Conference on Computer and Communications Security in Chicago. In addition to Carter, Traynor’s coauthors include Georgia Tech graduate student Arunabh Verman and Philip Marquardt of the MIT Lincoln Laboratory.

About the Georgia Tech College of Computing

The Georgia Tech College of Computing is a national leader in the creation of real-world computing breakthroughs that drive social and scientific progress. With its graduate program ranked 10th nationally by U.S. News and World Report, the College’s unconventional approach to education is defining the new face of computing by expanding the horizons of traditional computer science students through interdisciplinary collaboration and a focus on human-centered solutions. For more information about the Georgia Tech College of Computing, its academic divisions and research centers, please visit http://www.cc.gatech.edu.

Contact
Michael Terrazas
Assistant Director of Communications
College of Computing at Georgia Tech
mterraza@cc.gatech.edu

Michael Terrazas | Source: EurekAlert!
Further information: www.cc.gatech.edu

next article

More articles from Information Technology:

nachricht The elusive capacity of networks
16.05.2012 | Massachusetts Institute of Technology

nachricht New research could mean faster computers and better mobile phones
15.05.2012 | University of Gothenburg

All articles from Information Technology >>>
The most recent press releases about innovation >>>

Overview of the latest five Focus news of the innovations-report:
In the focus: A supernova cocoon breakthrough

The first evidence in X-rays of a supernova shock wave breaking through a cocoon of gas around the star has been found.

This discovery may help explain why some supernova explosions are more powerful than others.

This supernova is called SN 2010jl and is found in a galaxy about 160 million light years from Earth.

SN 2010jl was first spotted by astronomers on November 3, 2010, and probably exploded about a month before that.

Observations with NASA's Chandra X-ray Observatory have provided the first X-ray evidence of a supernova shock wave breaking through a cocoon of gas surrounding the star that exploded. This discovery may help astronomers understand why some supernovas are much more powerful than others.

On November 3, 2010, a supernova was ...

In the focus: Fuel for the black hole

An international research team led by Gerd Weigelt from the Max-Planck-Institut für Radioastronomie in Bonn reports on high-resolution studies of an active galactic nucleus.

The use of near-infrared interferometry allowed the team to resolve a ring-shaped dust distribution (generally called "dust torus") in the inner region of the nucleus of the active galaxy NGC 3783. This method is able to achieve an angular resolution equivalent to the resolution of a telescope with a diameter ...

In the focus: Big-mouthed babies drove the evolution of giant island snakes

Some populations of tiger snakes stranded for thousands of years on tiny islands surrounding Australia have evolved to be giants, growing to nearly twice the size of their mainland cousins. Now, new research in The American Naturalist suggests that the enormity of these elapids was driven by the need to have big-mouthed babies.

Mainland tiger snakes, which generally max out at 35 inches (89 cm) long, patrol swampy areas in search of frogs, their dietary staple. When sea levels rose around 10,000 years ago, some tiger snakes found themselves marooned on islands that would become dry and frog-free. With their favorite food gone, ...

In the focus: Black holes turn up the heat for the Universe

HITS astrophysicists discover a new heating source in cosmological structure formation

So far, astrophysicists thought that super-massive black holes can only influence their immediate surroundings. A collaboration of scientists at the Heidelberg Institute for Theoretical Studies (HITS) and in Canada and the US now discovered that diffuse gas in the universe can absorb luminous gamma-ray emission from black holes, heating it ...

In the focus: German astronomers finish Europe’s largest solar telescope on Tenerife

After ten years of development, the new German solar telescope GREGOR will start operating at the Spanish Observatorio del Teide of the Instituto de Astrofísica de Canarias on Tenerife. It is the largest solar telescope in Europe and number three worldwide.

It will provide the German and the international community of solar physicists with new and better instrumentation which will enable them to investigate our home star in unprecedented detail.

Studying the Sun is a key to understand the physical processes on and in the majority of stars. Moreover, there is ...

All Focus news of the innovations-report >>>

B2B Search

Product / Service
Company / Organisation

Latest News

New 'metamaterial' practical for optical advances

16.05.2012 | Materials Sciences

Timely discovery: Physics research sheds new light on quantum dynamics

16.05.2012 | Physics and Astronomy

The use of acoustic inversion to estimate the bubble size distribution in pipelines

16.05.2012 | Process Engineering

VideoLinks
B2B-VideoLinks
More VideoLinks >>>

Event News

SecureCloud 2012 in Frankfurt

10.05.2012 | Event News

WWU hosts Germany’s Biggest Giftedness Congress

09.05.2012 | Event News

Neuroscientists Discuss Latest Research Results in Potsdam

08.05.2012 | Event News