Physical presence verification: A test to detect whether a computer is remotely controlled

Tsung Teng Chen, Chun-Ying Huang, Chen Chi Wu, Kuan Ta Chen*

*Corresponding author for this work

研究成果: Article

摘要

As broadband Internet access has become ubiquitously available, the thin client technology is now widely adopted. Unfortunately, the old saying "the same knife cuts bread and fingers" applies to the thin client technology perfectly. While it makes people's life easier, malicious attackers are ever happier. Once an attacker compromises a victim's computer and installs a remote controllable backdoor on it, the attacker can do virtually anything the victim can do on his own computer. As far as we know, there are no general solutions for detecting whether a system is remotely controlled or not. In this paper, we propose Physical Presence Verification (PPV), a test to ensure a system is controlled by a local user. If an application is considered critical, it can invoke a PPV test to ensure the user is locally present and prevent an attacker from performing mission-critical actions and accessing private information remotely. Our user studies indicate that PPV tests are effective, reliable, and adoptable in real life. We also discuss potential attacks to PPV tests and our countermeasures.

原文English
頁(從 - 到)943-963
頁數21
期刊Journal of Information Science and Engineering
31
發行號3
DOIs
出版狀態Published - 1 五月 2015

指紋 深入研究「Physical presence verification: A test to detect whether a computer is remotely controlled」主題。共同形成了獨特的指紋。

  • 引用此