Title :
CaptureMe: Attacking the User Credential in Mobile Banking Applications
Author :
Mohamed El-Serngawy;Chamseddine Talhi
Author_Institution :
Dept. of Software Eng., Ecole de Technol. Super., Montreal, QC, Canada
Abstract :
Recently, the wide use of smart devices (phones and tablets) encourage financial institution to consider mobile banking applications as a necessity service to their clients. In this paper, we propose a screenshot attack "CaptureMe" to investigate the security risks of the password visibility feature on Android platform with the mobile banking applications. In CaptureMe attack we used different known techniques to take screenshot images and we applied highly efficient Optical Character Recognition (OCR) analysis using tesseract-ocr engine to extract the user credential from the taken screenshot images. We also explore the possible protection mechanisms against CaptureMe with more than 130 mobile banking applications exist in Google play store.
Keywords :
"Mobile communication","Smart phones","Banking","Androids","Humanoid robots","Security"
Conference_Titel :
Trustcom/BigDataSE/ISPA, 2015 IEEE
DOI :
10.1109/Trustcom.2015.466