Acoustic Keystroke Leakage on Smart Televisions (Accompanying Artifact)
收藏资源简介:
Smart Televisions (TVs) are internet-connected TVs that support video streaming applications and web browsers. Users enter information into Smart TVs through on-screen virtual keyboards. These keyboards require users to navigate between keys with directional commands from a remote controller. Given the extensive functionality of Smart TVs, users type sensitive information (e.g., passwords) into these devices, making keystroke privacy necessary. This work develops and demonstrates a new side-channel attack that exposes keystrokes from the audio of two popular Smart TVs: Apple and Samsung. This side-channel attack exploits how Smart TVs make different sounds when selecting a key, moving the cursor, and deleting a character. These properties allow an attacker to extract the number of cursor movements between selections from the TV's audio. Our attack uses this extracted information to identify the likeliest typed strings. Against realistic users, the attack finds up to 33.33% of credit card details and 60.19% of common passwords within 100 guesses. This vulnerability has been acknowledged by Samsung and highlights how Smart TVs must better protect sensitive data.
智能电视(Smart Televisions,TVs)是一类接入互联网、支持视频流媒体应用与网页浏览器的电视设备。用户可通过屏幕虚拟键盘向智能电视输入各类信息,此类键盘需用户借助遥控器的方向指令在按键间移动光标,方可完成输入操作。鉴于智能电视具备丰富的功能,用户会在此类设备上输入敏感信息(如密码),因此按键隐私保护至关重要。本研究开发并验证了一种新型侧信道攻击方法,可通过苹果、三星两款主流智能电视的音频信号还原用户的按键操作。该侧信道攻击利用了智能电视在按下按键、移动光标与删除字符时发出不同声响的特性,攻击者可借此从电视音频中提取两次按键选择之间的光标移动次数。本攻击方法依托提取得到的此类信息,可还原出最有可能的输入字符串。针对真实用户的测试结果显示,该攻击在100次猜测范围内,可成功识别出33.33%的信用卡卡号与60.19%的常用密码。三星公司已确认该漏洞,这也凸显出智能电视亟需进一步强化敏感数据保护的必要性。



