• DocumentCode
    3704067
  • Title

    CaptureMe: Attacking the User Credential in Mobile Banking Applications

  • Author

    Mohamed El-Serngawy;Chamseddine Talhi

  • Author_Institution
    Dept. of Software Eng., Ecole de Technol. Super., Montreal, QC, Canada
  • Volume
    1
  • fYear
    2015
  • Firstpage
    924
  • Lastpage
    933
  • Abstract
    Recently, the wide use of smart devices (phones and tablets) encourage financial institution to consider mobile banking applications as a necessity service to their clients. In this paper, we propose a screenshot attack "CaptureMe" to investigate the security risks of the password visibility feature on Android platform with the mobile banking applications. In CaptureMe attack we used different known techniques to take screenshot images and we applied highly efficient Optical Character Recognition (OCR) analysis using tesseract-ocr engine to extract the user credential from the taken screenshot images. We also explore the possible protection mechanisms against CaptureMe with more than 130 mobile banking applications exist in Google play store.
  • Keywords
    "Mobile communication","Smart phones","Banking","Androids","Humanoid robots","Security"
  • Publisher
    ieee
  • Conference_Titel
    Trustcom/BigDataSE/ISPA, 2015 IEEE
  • Type

    conf

  • DOI
    10.1109/Trustcom.2015.466
  • Filename
    7345374