data ta ove ver sou ound
play

Data ta ove ver Sou ound Risks ks and and Chan Chance ces of - PowerPoint PPT Presentation

Data ta ove ver Sou ound Risks ks and and Chan Chance ces of of an an emerging C Com ommunication on C Channel el Dr. Matthias Zeppelzauer St. Plten University of Applied Sciences matthias.zeppelzauer@fhstp.ac.at Reversing and


  1. Data ta ove ver Sou ound Risks ks and and Chan Chance ces of of an an emerging C Com ommunication on C Channel el Dr. Matthias Zeppelzauer St. Pölten University of Applied Sciences matthias.zeppelzauer@fhstp.ac.at Reversing and Offensive-oriented Trends Symposium (ROOTS) DeepSec Conference 2018, Vienna , 30.11.2018 Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  2. Who ho k kno nows abo about ul ultrasoun und c communication? n? Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  3. Tracking Interaction Creating What is meant by Ultrasonic Communication? Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  4. Tracking Interaction Creating What is Ultrasound? inaudible Time Frequen ency r range: 18-22kHz Why in this c cha hannel? Inaudible (almost) Frequency Low noise level Higher data rates Time Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  5. Tracking Interaction Creating Can We Receive Ultrasound?  Lab experiment  Piezo Tweeter @ room volume  Frequency response of smartphone mics Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  6. Tracking Interaction Creating Range of Ultrasound  Lab experiment  Tweeter + Samsung Galaxy S2  Omnidirectional data transmission  Distance up to 8 Meter  Stops ps at at wa walls! Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  7. Tracking Interaction Creating How does data transmission work?  Most often: Frequency Shift Keying (FSK)  compare fax machine / old school modem Example: Lisnr  Send  Rec Sending: ecei eiving:  Loudspeaker  Microphone  No  On No per ermissi ssion One-time per ermissi ssion nec ecess ssary nec ecess ssary Credits: yahoo.com; Arp et. Al [1] Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  8. Do Does s someone ne u use it? Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  9. Tracking Interaction Creating Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  10. Tracking Interaction Creating Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  11. Tracking Interaction Creating Why Audio (and not BT / WLAN / NFC...) Low hardware High downwards requirements compatibility Instant Controllable communication range (no pairing) Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  12. Tracking Interaction Creating Who develops this technology? Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  13. Tracking Interaction Creating Google Nearby  “Pairing” devices, e,g, Chromecast  Location-based services  SDK available – any app can use it Credits: google.com, giga.de Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  14. Tracking Interaction Creating Lisnr  FSK-based protocol (18.7 – 19.5 kHz)  Offline data exchange  Location-based services Authentification  Payments  Unlock doors  SDK available (for all recent platforms) Credit: lisnr.com Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  15. Tracking Interaction Creating Shopkick  Reward system for commerce  “Ultrasonic Beacons” at shop entry  Bonus points on entry in exchange for ads  via „Shopkick App“ Credits: www.rfidjournal.com www. http://teleautomaton.com Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  16. Tracking Interaction Creating SilverPush  Cross-device tracking between TV and smartphone  Goal: placing ads  SDK available  Classified as malware in the meanwhile Silverpush.c .com: “Customer ers are m e matched ed across first st a and t third p party data u using o our proprietary technology.” Credits: Pierluigi Paganini, securityaffairs.co https://www.silverpush.co Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  17. Tracking Interaction Creating Source: D., Quiring, E., Wressnegger, C., & Rieck, K. Privacy Threats through Ultrasonic Side Channels on Mobile Devices, Technical Report, TU Braunschweig, Germany, http://vamos-project.org/docs/2017a-eurosp.pdf Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  18. Focus RISKS AND CHANCES OF ULTRASOUND COMMUNICATION Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  19. Tracking Interaction Creating Cross-de device ce Media a Tr Tracking Tracking Tr RISKS De De- Loc Location An Anonym ymisation Tr Tracking Credit: D., Quiring, E., Wressnegger, C., & Rieck, K. Privacy Threats through Ultrasonic Side Channels on Mobile Devices, Technical Report, TU Braunschweig, Germany, http://vamos-project.org/docs/2017a-eurosp.pdf Credit: Arp et. al Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  20. Tracking Interaction Creating Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  21. Tracking Interaction Creating Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  22. Tracking Interaction Creating SoniControl Son SoniCon ontrol ol Detection of Continuous different monitoring of transmission ultrasound band technologies Notification of Active blocking user (spoofing) http://sonicontrol ol.fhstp.ac ac.at Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  23. Tracking Interaction Creating Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  24. Tracking Interaction Creating  How does it work?  Continuous capturing ultrasonic channel in the background  Spectral decomposition (FFT)  Spectral normalization (  remove noise)  Statistical modeling of background (  model environment)  Anomaly detection by statistical analysis  Compare spectral distributions of background model and current signal Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  25. Tracking Interaction Creating  How does it work? Zeppelzauer, M., Ringot, A. and Taurer, F. (2018) SoniControl - A Mobile Ultrasonic Firewall. In 2018 ACM Multimedia Conference (MM’18), October 22–26, 2018, Seoul, Republic of Korea. ACM, New York, NY, USA, https://arxiv.org/abs/1807.07617. Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  26. Tracking Interaction Creating http tps:// //play.goog ogle.c e.com om/st or ore/ e/apps/d /details?id=at.a t.ac. fhstp.son onicontrol ol Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  27. Focus RISKS AND CH CHAN ANCE CES OF ULTRASOUND COMMUNICATION Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  28. Tracking Interaction Creating Potential of Ultrasound Communication Data Exchange IoT Security Local and offline Multi-device Networking exchange of sensitive communication and Additional side data networking channel for: Device Authentication, synchronization, Verification, Device pairing, Location-based Multimedia Payments, Adhoc networking, Services Key exchange (RSA / Mesh networks Second screen, Blockchains) Object tracking, Smart home Navigation, NFC automation Secure Communication Layer Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  29. Tracking Interaction Creating ...a secure and privacy-oriented protocol for ultrasonic communication Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  30. Tracking Interaction Creating  To date: SoniTalk Son  No free protocol / sdk Permission  No standardized protocol Open source system on App- protocol  No compatibility between technologies Level  No privacy protection integrated Free of charge / Concurrent Extensible communication Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  31. Tracking Interaction Creating ASK USER ACK? App A SEND SoniTalk App B Manager App C Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  32. Tracking Interaction Creating ASK USER ACK? App A SoniTalk App B Manager SCAN & DECODE App C Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  33. Tracking Interaction Creating  State of the research  Protocol Specification  Error Checking  Encoding & Sending (Android)  Receive & Decoding (Matlab)  Next steps  Decoder in Android  Permission system  SDK development & release Mor ore e info formation: : https://sonitalk.fhstp.ac. c.at Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  34. Tracking Interaction Creating Lates est ne news: Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  35. Tracking Interaction Creating Applications of Ultrasound Communication Data Exchange IoT / Industry 4.0 Security Local and offline Networking Device tracking exchange of sensitive Additional side Device sync. data channel for: Device Authentication, synchronization, Verification, Device pairing, Multimedia Location-based Payments, Adhoc networking, Services Key exchange (RSA / Mesh networks Second screen, Blockchains) Smart home Indoor Navigation, NFC automation Common and Secure Communication Layer Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  36. Than Th ank yo you fo for yo your att ttention! son onital alk.fhstp.ac.at sonicontrol ol.fh fhstp.ac ac.at Contact: Co matthias.zeppelzauer@fhstp.ac.at Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

  37. All co code & & res esults public licly ly availa ilable https://git.nwt.fhstp.ac ac.at/m.zep eppel elzau auer er/SoniCon ontrol ol Contact: Co matthias.zeppelzauer@fhstp.ac.at Matthias Zeppelzauer | ROOTS DeepSec 2018 | 30.11.2018

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend