My smartphone knows your health data: Exploiting android-based deception attacks against smartbands

Jun Xie, Sha Wu, Yansong Li, Jun Guo, Wen Sun, Jiajia Liu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Although a number of vulnerabilities have been reported for smart wearables and lots of efforts have been taken to strengthen their security, wearable devices face still significant threats of privacy leakage due to their own inherent characteristics. Towards this end, we re-investigate in this paper the security concerns of smartbands. In particular, we first introduce our detailed methodology for security analysis, including log analysis, Hook technology, and Android reverse engineering. Then, we apply it to popular commercial smartbands of three different brands the concrete information of which is omitted, identify their common vulnerabilities, and develop accordingly a fake Android application (App) utilizing the identified loopholes, given the protection measures of shelling, obfuscation, as well as forcible pairing and resetting. By installing the fake App, we are able to conduct deception attacks against the targeted smartbands, succeeding to remotely activate/deactivate shaking function, to adjust/modify time (including value and format), and to obtain the smartband owner’s sensitive/health data. During our deception attacks, no cooperation from the smartband owner is required, neither the pairing process between the targeted smartbands and our fake App.

Original languageEnglish
Title of host publicationCyberspace Safety and Security - 9th International Symposium, CSS 2017, Proceedings
EditorsWei Wu, Aniello Castiglione, Sheng Wen
PublisherSpringer Verlag
Pages291-306
Number of pages16
ISBN (Print)9783319694702
DOIs
StatePublished - 2017
Externally publishedYes
Event9th International Symposium on Cyberspace Safety and Security, CSS 2017 - Xi'an, China
Duration: 23 Oct 201725 Oct 2017

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10581 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th International Symposium on Cyberspace Safety and Security, CSS 2017
Country/TerritoryChina
CityXi'an
Period23/10/1725/10/17

Keywords

  • Android APP
  • Commercial smartband
  • Privacy leakage
  • Wearable devices

Fingerprint

Dive into the research topics of 'My smartphone knows your health data: Exploiting android-based deception attacks against smartbands'. Together they form a unique fingerprint.

Cite this