[论文解读] Contextual Proximity Detection in the Face of Context-Manipulating Adversaries.
本文研究了上下文接近度检测在上下文操纵型攻击者下的脆弱性——该技术用于防止移动认证中的中继攻击。利用低成本设备,攻击者可一致地操纵声学和物理传感器,从而破坏基于特征融合与决策融合的机器学习方法,尽管在某些场景下决策融合方法表现出更强的鲁棒性。
Contextual proximity detection (or, co-presence detection) is a promising approach to defend against relay attacks in many mobile authentication systems. We present a systematic assessment of co-presence detection in the presence of a context-manipulating attacker. First, we show that it is feasible to manipulate, consistently control and stabilize the readings of different acoustic and physical environment sensors (and even multiple sensors simultaneously) using low-cost, off-the-shelf equipment. Second, based on these capabilities, we show that an attacker who can manipulate the context gains a significant advantage in defeating context-based co-presence detection. For systems that use multiple sensors, we investigate two sensor fusion approaches based on machine learning techniques: features-fusion and decisions-fusion, and show that both are vulnerable to contextual attacks but the latter approach can be more resistant in some cases.
研究动机与目标
- 评估利用环境传感器操纵移动共存检测系统可行性的目标。
- 分析对手通过上下文操纵对基于传感器的接近度检测造成的破坏。
- 比较在上述攻击下特征融合与决策融合机器学习方法的鲁棒性。
- 识别多传感器共存检测中的攻击面与系统弱点。
提出的方法
- 使用低成本、市售设备操纵声学与物理传感器的读数。
- 在多种传感器类型上一致控制并稳定传感器输出。
- 评估两种机器学习融合策略:特征融合与决策融合。
- 设计并执行受控实验,评估传感器操纵下的检测失败情况。
- 测量在对手上下文操纵下系统性能的退化程度。
- 分析两种融合方法的攻击成功率与检测绕过概率。
实验结果
研究问题
- RQ1攻击者能否使用低成本工具在共存检测系统中一致操纵多种环境传感器?
- RQ2攻击者对上下文的操纵如何影响基于传感器融合的共存检测可靠性?
- RQ3在抵抗基于上下文的攻击时,特征融合与决策融合方法相比如何?
- RQ4在绕过接近度检测方面,上下文操纵的实际限制与成功率如何?
主要发现
- 攻击者可利用低成本、市售设备可靠地操纵多种声学与物理传感器的读数。
- 上下文操纵显著降低了共存检测系统的性能。
- 特征融合方法易受上下文操纵影响,导致高误报率。
- 在某些配置下,决策融合方法对基于上下文的攻击表现出更强的抵抗能力。
- 本研究证明,即使多传感器系统也易受协同上下文操纵的影响。
- 结果凸显了当前共存检测机制中的关键安全漏洞。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。