Wrong Siren! A Location Spoofing Attack on Indoor Positioning Systems: The Starbucks Case Study

被引:12
作者
Cho, Junsung [1 ]
Yu, Jaegwan [2 ]
Oh, Sanghak [2 ]
Ryoo, Jungwoo [4 ]
Song, JaeSeung [5 ]
Kim, Hyoungshick [3 ]
机构
[1] Sungkyunkwan Univ, Dept Comp Sci & Engn, Seoul, South Korea
[2] Sungkyunkwan Univ, Dept Platform Software, Seoul, South Korea
[3] Sungkyunkwan Univ, Dept Software, Seoul, South Korea
[4] Penn State Univ, Informat Sci & Technol, University Pk, PA 16802 USA
[5] Sejong Univ, Comp & Informat Secur Dept, Seoul, South Korea
关键词
Location based services - Retail stores - Indoor positioning systems - Sales - Internet of things - Risk assessment - Sirens;
D O I
10.1109/MCOM.2017.1600595CM
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Internet of Things interconnects a mass of billions devices, from smartphones to cars, to provide convenient services to people. This gives immediate access to various data about the objects and the environmental context - leading to smart services and increased efficiency. A number of retail stores have started to adopt IoT enabled services to attract customers. In particular, thanks to indoor proximity technologies, it is possible to introduce location-based smart services to customers, for example, transmitting identifiable signals that represent the locations of stores. In this article, we investigate a potential security risk involved in such technologies: physical signals used as identifiers can be captured and forged easily with today's widely available IoT software for implementing location spoofing attacks. We highlight this security risk by providing a case study: an in-depth security analysis of the recently launched Starbucks service called Siren Order.
引用
收藏
页码:132 / 137
页数:6
相关论文
共 10 条
[1]  
[Anonymous], 2010, 5905 RFC IETF
[2]  
Brands S., 1993, P WKSP THEOR APPL CR
[3]  
Capkun S., 2005, P 24 ANN C IEEE COMP
[4]  
DESMEDT Y, 1988, SECURICOM
[5]   A Survey of Indoor Positioning Systems for Wireless Personal Networks [J].
Gu, Yanying ;
Lo, Anthony ;
Niemegeers, Ignas .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2009, 11 (01) :13-32
[6]  
Hancke GP, 2005, P 1 INT C SEC PRIV E
[7]  
Lazos L., 2005, P 4 INT S INF PROC S
[8]  
Reid J., 2007, P 2 ACM S INF COMP C
[9]   TOWARD A STANDARDIZED COMMON M2M SERVICE LAYER PLATFORM: INTRODUCTION TO ONEM2M [J].
Swetina, Joerg ;
Lu, Guang ;
Jacobs, Philip ;
Ennesser, Francois ;
Song, JaeSeung .
IEEE WIRELESS COMMUNICATIONS, 2014, 21 (03) :20-26
[10]  
Tippenhauer Nils Ole, 2009, P 7 INT C MOB SYST A