Are Thermal Attacks a Realistic Threat? Investigating the Preconditions of Thermal Attacks in Users’ Daily Lives

Bekaert, P., Alotaibi, N. , Mathis, F., Gerber, N., Rafferty, A., Khamis, M. and Marky, K. (2022) Are Thermal Attacks a Realistic Threat? Investigating the Preconditions of Thermal Attacks in Users’ Daily Lives. In: NordiCHI '22: Nordic Human-Computer Interaction Conference, Aarhus, Denmark, 8-12 October 2022, p. 76. ISBN 9781450396998 (doi: 10.1145/3546155.3546706)

[img] Text
278660.pdf - Published Version
Available under License Creative Commons Attribution Non-commercial Share Alike.

730kB

Abstract

Thermal attacks refer to the possibility of capturing heat traces that result from interacting with user interfaces to reveal sensitive input, such as passwords. The technical feasibility and effectiveness of thermal attacks have already been demonstrated. Yet, several preconditions have to be met for successful thermal attacks. In this paper, we investigate user awareness of thermal attacks and to which extent the attack’s preconditions are met in the users’ daily lives. We present results from an online study with 101 participants showing that users are frequently at risk of thermal attacks based on their behavior, e.g., due to leaving devices unattended, or their choice of authentication method. Further, only 7 of our 101 participants had heard of thermal attacks. Based on our results, we discuss the implications on user security, operators of public spaces, and the development of thermal attack-resistant input methods.

Item Type:Conference Proceedings
Additional Information:This work was supported by the University of Edinburgh and the University of Glasgow jointly funded PhD studentships, by an EPSRC New Investigator award (EP/V008870/1) and by the PETRAS National Centre of Excellence for IoT Systems Cybersecurity, which has been funded by the UK EPSRC under grant number EP/S035362/1.
Status:Published
Refereed:Yes
Glasgow Author(s) Enlighten ID:Marky, Dr Karola and Alotaibi, Norah Mohsen T and Mathis, Mr Florian and Khamis, Dr Mohamed
Authors: Bekaert, P., Alotaibi, N., Mathis, F., Gerber, N., Rafferty, A., Khamis, M., and Marky, K.
College/School:College of Science and Engineering > School of Computing Science
ISBN:9781450396998
Copyright Holders:Copyright © 2022 The Authors
First Published:First published in NordiCHI '22: Nordic Human-Computer Interaction Conference: 76
Publisher Policy:Reproduced under a Creative Commons License
Related URLs:

University Staff: Request a correction | Enlighten Editors: Update this record

Project CodeAward NoProject NamePrincipal InvestigatorFunder's NameFunder RefLead Dept
310627TAPS: Assessing, Mitigating and Raising Awareness of the Security and Privacy Risks of Thermal ImagingMohamed KhamisEngineering and Physical Sciences Research Council (EPSRC)EP/V008870/1Computing Science
313490Preventing THErmal ATtacks using AI-driven ApproachesMohamed KhamisEngineering and Physical Sciences Research Council (EPSRC)5676417 -PETRASComputing Science