IntegriScreen: Visually Supervising Remote User Interactions on Compromised Clients

11/27/2020
by   Ivo Sluganovic, et al.
0

Remote services and applications that users access via their local clients (laptops or desktops) usually assume that, following a successful user authentication at the beginning of the session, all subsequent communication reflects the user's intent. However, this is not true if the adversary gains control of the client and can therefore manipulate what the user sees and what is sent to the remote server. To protect the user's communication with the remote server despite a potentially compromised local client, we propose the concept of continuous visual supervision by a second device equipped with a camera. Motivated by the rapid increase of the number of incoming devices with front-facing cameras, such as augmented reality headsets and smart home assistants, we build upon the core idea that the user's actual intended input is what is shown on the client's screen, despite what ends up being sent to the remote server. A statically positioned camera enabled device can, therefore, continuously analyze the client's screen to enforce that the client behaves honestly despite potentially being malicious. We evaluate the present-day feasibility and deployability of this concept by developing a fully functional prototype, running a host of experimental tests on three different mobile devices, and by conducting a user study in which we analyze participants' use of the system during various simulated attacks. Experimental evaluation indeed confirms the feasibility of the concept of visual supervision, given that the system consistently detects over 98 evaluated attacks, while study participants with little instruction detect the remaining attacks with high probability.

READ FULL TEXT

page 6

page 9

research
09/04/2017

Feasibility of Corneal Imaging for Handheld Augmented Reality

Smartphones are a popular device class for mobile Augmented Reality but ...
research
11/05/2017

Trustware: A Device-based Protocol for Verifying Client Legitimacy

Online services commonly attempt to verify the legitimacy of users with ...
research
10/26/2020

Client-Server Sessions in Linear Logic

We introduce coexponentials, a new set of modalities for Classical Linea...
research
08/30/2023

Telepresence Lantern – Designing an Immersive Video-Mediated Communication Device for Older Adults

We present the Telepresence Lantern concept, developed to provide opport...
research
12/19/2020

TOPCAT Visualisation over the Web

The desktop GUI catalogue analysis tool TOPCAT, and its command-line cou...
research
07/31/2018

Revisiting Client Puzzles for State Exhaustion Attacks Resilience

In this paper, we address the challenges facing the adoption of client p...
research
03/21/2020

An Online Framework to Interact and Efficiently Compute Linear Layouts of Graphs

We present a prototype online system to automate the procedure of comput...

Please sign up or login with your details

Forgot password? Click here to reset