DocumentCode
3704067
Title
CaptureMe: Attacking the User Credential in Mobile Banking Applications
Author
Mohamed El-Serngawy;Chamseddine Talhi
Author_Institution
Dept. of Software Eng., Ecole de Technol. Super., Montreal, QC, Canada
Volume
1
fYear
2015
Firstpage
924
Lastpage
933
Abstract
Recently, the wide use of smart devices (phones and tablets) encourage financial institution to consider mobile banking applications as a necessity service to their clients. In this paper, we propose a screenshot attack "CaptureMe" to investigate the security risks of the password visibility feature on Android platform with the mobile banking applications. In CaptureMe attack we used different known techniques to take screenshot images and we applied highly efficient Optical Character Recognition (OCR) analysis using tesseract-ocr engine to extract the user credential from the taken screenshot images. We also explore the possible protection mechanisms against CaptureMe with more than 130 mobile banking applications exist in Google play store.
Keywords
"Mobile communication","Smart phones","Banking","Androids","Humanoid robots","Security"
Publisher
ieee
Conference_Titel
Trustcom/BigDataSE/ISPA, 2015 IEEE
Type
conf
DOI
10.1109/Trustcom.2015.466
Filename
7345374
Link To Document