首页> 外文会议>IEEE Symposium on Security and Privacy >Sending Out an SMS: Characterizing the Security of the SMS Ecosystem with Public Gateways
【24h】

Sending Out an SMS: Characterizing the Security of the SMS Ecosystem with Public Gateways

机译:发送SMS:使用公共网关表征SMS生态系统的安全性

获取原文

摘要

Text messages sent via the Short Message Service (SMS) have revolutionized interpersonal communication. Recent years have also seen this service become a critical component of the security infrastructure, assisting with tasks including identity verification and second-factor authentication. At the same time, this messaging infrastructure has become dramatically more open and connected to public networks than ever before. However, the implications of this openness, the security practices of benign services, and the malicious misuse of this ecosystem are not well understood. In this paper, we provide the first longitudinal study to answer these questions, analyzing nearly 400,000 text messages sent to public online SMS gateways over the course of 14 months. From this data, we are able to identify not only a range of services sending extremely sensitive plaintext data and implementing low entropy solutions for one-use codes, but also offer insights into the prevalence of SMS spam and behaviors indicating that public gateways are primarily used for evading account creation policies that require verified phone numbers. This latter finding has significant implications for research combatting phone-verified account fraud and demonstrates that such evasion will continue to be difficult to detect and prevent.
机译:通过短消息服务(SMS)发送的文本消息彻底改变了人际通信。近年来,该服务已成为安全基础结构的重要组成部分,可协助完成身份验证和二级身份验证等任务。同时,此消息传递基础结构比以往任何时候都更加开放和连接到公共网络。但是,这种开放性,良性服务的安全性实践以及对该生态系统的恶意滥用的含义尚未得到很好的理解。在本文中,我们提供了第一个纵向研究来回答这些问题,分析了在14个月内发送到公共在线SMS网关的近40万条短信。从这些数据中,我们不仅能够识别出发送极其敏感的纯文本数据并为一次性代码实施低熵解决方案的一系列服务,还能够洞悉SMS垃圾邮件的流行情况以及表明主要使用公共网关的行为。规避需要验证电话号码的帐户创建政策。后一个发现对于打击电话验证的帐户欺诈行为的研究具有重要意义,并表明这种逃避行为将继续难以发现和防止。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号