Utilize este identificador para referenciar este registo: http://hdl.handle.net/20.500.11960/2967
Registo completo
Campo DCValorIdioma
dc.contributor.authorFaria, Henrique-
dc.contributor.authorPaiva, Sara-
dc.contributor.authorPinto, Pedro-
dc.date.accessioned2022-12-12T13:03:00Z-
dc.date.available2022-12-12T13:03:00Z-
dc.date.issued2021-
dc.identifier.citationFaria, H., Paiva, S., & Pinto, P. (2021). An advertising overflow attack against android exposure notification system impacting COVID-19 contact tracing application. IEEE Access, 9, 103365-103375. https://doi.org/10.1109/ACCESS.2021.3099017pt_PT
dc.identifier.issn2169-3536-
dc.identifier.urihttp://hdl.handle.net/20.500.11960/2967-
dc.description.abstractThe digital contact tracing applications are one of the many initiatives to fight the COVID-19 virus. Some of these Apps use the Exposure Notification (EN) system available on Google and Apple’s operating systems. However, EN-based contact tracing Apps depend on the availability of Bluetooth interfaces to exchange proximity identifiers, which, if compromised, directly impact their effectiveness. This paper discloses and details the Advertising Overflow attack, a novel internal Denial of Service (DoS) attack targeting the EN system on Android devices. The attack is performed by a malicious App that occupies all the Bluetooth advertising slots in an Android device, effectively blocking any advertising attempt of EN or other Apps. The impact of the disclosed attack and other previously disclosed DoS-based attacks, namely Battery Exhaustion and Storage Drain, were tested using two target smartphones and other six smartphones as attackers. The results show that the Battery Exhaustion attack imposes a battery discharge rate 1.95 times higher than in the normal operation scenario. Regarding the Storage Drain, the storage usage increased more than 30 times when compared to the normal operation scenario results. The results of the novel attack reveal that a malicious App can prevent any other App to place their Bluetooth advertisements, for any chosen time period, thus canceling the operation of the EN system and compromising the efficiency of any COVID contact tracing App using this system.pt_PT
dc.language.isoengpt_PT
dc.rightsopenAccesspt_PT
dc.subjectAttackpt_PT
dc.subjectApplicationspt_PT
dc.subjectAndroidpt_PT
dc.subjectDenial of servicept_PT
dc.subjectCOVID-19pt_PT
dc.subjectContact tracingpt_PT
dc.subjectExposure notificationpt_PT
dc.titleAn advertising overflow attack against android exposure notification system impacting COVID-19 contact tracing applicationspt_PT
dc.typearticlept_PT
dc.date.updated2022-10-20T15:20:31Z-
dc.description.version5311-8814-F0ED | Sara Maria da Cruz Maia de Oliveira Paiva-
dc.description.versionN/A-
dc.identifier.slugcv-prod-2709098-
dc.peerreviewedyespt_PT
degois.publication.firstPage103365pt_PT
degois.publication.lastPage103375pt_PT
degois.publication.volume9pt_PT
degois.publication.titleIEEE Accesspt_PT
dc.identifier.doi10.1109/ACCESS.2021.3099017-
dc.identifier.eid2-s2.0-85111048123-
Aparece nas colecções:ESTG - Publicações indexadas à WoS/Scopus

Ficheiros deste registo:
Ficheiro Descrição TamanhoFormato 
2021_3.pdf1.43 MBAdobe PDFVer/Abrir


Todos os registos no repositório estão protegidos por leis de copyright, com todos os direitos reservados.