Authors:
João Amarante
1
and
João Paulo Barros
2
Affiliations:
1
Polytechnic Institute of Beja, Portugal
;
2
Polytechnic Institute of Beja and UNINOVA-CTS, Portugal
Keyword(s):
Vulnerability, USB, Smartphone, Mobile Device, Computer Security, Physical Attack, Internet of Things, IoT, Mobile Cyber-physical Systems.
Related
Ontology
Subjects/Areas/Topics:
Data and Application Security and Privacy
;
Data Protection
;
Information and Systems Security
;
Security and Privacy in Mobile Systems
;
Security and Privacy in Pervasive/Ubiquitous Computing
Abstract:
The complexity of avoiding vulnerabilities in the modern mobile operating systems makes them vulnerable to many types of attacks. This paper presents preliminary work in the creation of scenarios to surreptitiously extract private data from smartphones running different versions of the Android Operating System. Three scenarios were already identified and a proof of concept script was developed, all based on the use of the Android Debug Bridge tool. When running in a computer, the script is able to extract private data from a USB connected smartphone. In two scenarios it was possible to extract the information in a totally surreptitious way, without the user knowledge. In the third scenario, using a newer version of the Android operating system, a user action is needed which makes the attack less likely to succeed, but still possible.