Matches in SemOpenAlex for { <https://semopenalex.org/work/W3163385614> ?p ?o ?g. }
Showing items 1 to 87 of
87
with 100 items per page.
- W3163385614 abstract "A fundamental premise of SMS One-Time Password (OTP) is that the used pseudo-random numbers (PRNs) are uniquely unpredictable for each login session. Hence, the process of generating PRNs is the most critical step in the OTP authentication. An improper implementation of the pseudo-random number generator (PRNG) will result in predictable or even static OTP values, making them vulnerable to potential attacks. In this paper, we present a vulnerability study against PRNGs implemented for Android apps. A key challenge is that PRNGs are typically implemented on the server-side, and thus the source code is not accessible. To resolve this issue, we build an analysis tool, OTP-Lint, to assess implementations of the PRNGs in an automated manner without the source code requirement. Through reverse engineering, OTP-Lint identifies the apps using SMS OTP and triggers each app's login functionality to retrieve OTP values. It further assesses the randomness of the OTP values to identify vulnerable PRNGs. By analyzing 6,431 commercially used Android apps downloaded from Google Play and Tencent Myapp, OTP-Lint identified 399 vulnerable apps that generate predictable OTP values. Even worse, 194 vulnerable apps use the OTP authentication alone without any additional security mechanisms, leading to insecure authentication against guessing attacks and replay attacks." @default.
- W3163385614 created "2021-05-24" @default.
- W3163385614 creator A5016563574 @default.
- W3163385614 creator A5016972157 @default.
- W3163385614 creator A5020082816 @default.
- W3163385614 creator A5058987076 @default.
- W3163385614 creator A5061694501 @default.
- W3163385614 creator A5078797976 @default.
- W3163385614 creator A5082256444 @default.
- W3163385614 date "2021-05-01" @default.
- W3163385614 modified "2023-10-07" @default.
- W3163385614 title "Fine with “1234”? An Analysis of SMS One-Time Password Randomness in Android Apps" @default.
- W3163385614 cites W1496322964 @default.
- W3163385614 cites W1799884017 @default.
- W3163385614 cites W1976476866 @default.
- W3163385614 cites W1985437717 @default.
- W3163385614 cites W1986517320 @default.
- W3163385614 cites W1996780636 @default.
- W3163385614 cites W2011565494 @default.
- W3163385614 cites W2045151734 @default.
- W3163385614 cites W2054989590 @default.
- W3163385614 cites W2075917111 @default.
- W3163385614 cites W2088760879 @default.
- W3163385614 cites W2090206103 @default.
- W3163385614 cites W2095595785 @default.
- W3163385614 cites W2123382811 @default.
- W3163385614 cites W2161573379 @default.
- W3163385614 cites W2163740453 @default.
- W3163385614 cites W2169455260 @default.
- W3163385614 cites W2254700249 @default.
- W3163385614 cites W2293624369 @default.
- W3163385614 cites W2698406033 @default.
- W3163385614 cites W2795590130 @default.
- W3163385614 cites W2930252849 @default.
- W3163385614 cites W2973220656 @default.
- W3163385614 cites W2983730736 @default.
- W3163385614 cites W2991334710 @default.
- W3163385614 cites W3014684725 @default.
- W3163385614 cites W4212851301 @default.
- W3163385614 doi "https://doi.org/10.1109/icse43902.2021.00148" @default.
- W3163385614 hasPublicationYear "2021" @default.
- W3163385614 type Work @default.
- W3163385614 sameAs 3163385614 @default.
- W3163385614 citedByCount "3" @default.
- W3163385614 countsByYear W31633856142022 @default.
- W3163385614 crossrefType "proceedings-article" @default.
- W3163385614 hasAuthorship W3163385614A5016563574 @default.
- W3163385614 hasAuthorship W3163385614A5016972157 @default.
- W3163385614 hasAuthorship W3163385614A5020082816 @default.
- W3163385614 hasAuthorship W3163385614A5058987076 @default.
- W3163385614 hasAuthorship W3163385614A5061694501 @default.
- W3163385614 hasAuthorship W3163385614A5078797976 @default.
- W3163385614 hasAuthorship W3163385614A5082256444 @default.
- W3163385614 hasBestOaLocation W31633856142 @default.
- W3163385614 hasConcept C109297577 @default.
- W3163385614 hasConcept C111919701 @default.
- W3163385614 hasConcept C113324615 @default.
- W3163385614 hasConcept C38652104 @default.
- W3163385614 hasConcept C41008148 @default.
- W3163385614 hasConcept C557433098 @default.
- W3163385614 hasConceptScore W3163385614C109297577 @default.
- W3163385614 hasConceptScore W3163385614C111919701 @default.
- W3163385614 hasConceptScore W3163385614C113324615 @default.
- W3163385614 hasConceptScore W3163385614C38652104 @default.
- W3163385614 hasConceptScore W3163385614C41008148 @default.
- W3163385614 hasConceptScore W3163385614C557433098 @default.
- W3163385614 hasFunder F4320320984 @default.
- W3163385614 hasFunder F4320321001 @default.
- W3163385614 hasFunder F4320335777 @default.
- W3163385614 hasLocation W31633856141 @default.
- W3163385614 hasLocation W31633856142 @default.
- W3163385614 hasOpenAccess W3163385614 @default.
- W3163385614 hasPrimaryLocation W31633856141 @default.
- W3163385614 hasRelatedWork W1605303397 @default.
- W3163385614 hasRelatedWork W2182003324 @default.
- W3163385614 hasRelatedWork W2182657716 @default.
- W3163385614 hasRelatedWork W2186671259 @default.
- W3163385614 hasRelatedWork W2343700560 @default.
- W3163385614 hasRelatedWork W2556693741 @default.
- W3163385614 hasRelatedWork W2888672439 @default.
- W3163385614 hasRelatedWork W3034738955 @default.
- W3163385614 hasRelatedWork W3208256391 @default.
- W3163385614 hasRelatedWork W4214613390 @default.
- W3163385614 isParatext "false" @default.
- W3163385614 isRetracted "false" @default.
- W3163385614 magId "3163385614" @default.
- W3163385614 workType "article" @default.