标签归档 杭州西湖阁

This "hot attack" can read the password from the residual heat left at your fingertips.

1. Thermal imaging shows the thermal trace left by the fingertips on the keyboard. Researchers say that the password can be cracked by using the thermal trace (Source: Glasgow University)

Computer security researchers say that they have developed a system based on artificial intelligence, which can guess the passwords of computers and smart phones in just a few seconds by checking the characteristics of heat left by fingertips on the keyboard and screen when inputting data.

Researchers at the School of Computational Science at the University of Glasgow in the UK have developed this system called ThermoSecure to show how the falling price of thermal imaging cameras and the increasing popularity of machine learning and artificial intelligence algorithms create new opportunities for what they describe as thermal attacks.

By looking at the computer keyboard, smartphone screen or ATM keyboard with a thermal imaging camera, a photo can be taken to show the thermal characteristics of the recent finger touching the device.

The brighter the area appearing in thermal imaging, the closer it is to being touched by people-this means that the image can be used to crack passwords or PIN codes by analyzing the location and time of touching the keyboard or screen.

Early research on heat attacks in Glasgow University showed that people without professional knowledge can guess passwords just by looking at heat images. Now, with artificial intelligence, professional attackers can crack passwords more quickly.

If ThermoSecure is used to analyze images with artificial intelligence, 86% of passwords can be revealed if thermal images are taken within 20 seconds. If the thermal image is taken within 30 seconds, 76% of the passwords can be revealed. If the thermal image is taken after 60 seconds, 62% passwords can still be revealed.

The longer the password, the more difficult it will be to leak, but in most cases it can still be proved to be leaked. ThermoSecure can crack two thirds of passwords with 16 characters; The shorter the password, the higher the success rate of the system-82% for the 12-character password and 93% for the 8-character password.

100% of passwords consisting of 6 characters or less are successfully cracked, which may be used to protect ATM PIN codes of smart phones or shorter passwords are particularly vulnerable to attacks.

Malicious attackers looking for potential victims can take hot images of keyboards, smart phones or ATMs and use them to guess the passwords as long as they use this clever technology. In some cases, they need physical access devices themselves, but the target of attack may be left unattended by the computer.

It is also possible that the attacker already knows the user name of the online account of the target, or they may use the hot attack to find the user name.

This paper on ThermoSecure was written by Dr. Mohamed Kham, Dr. John Williamson and Norah Alotaibi of Glasgow University and has been published. They hope that the paper will show the world the potential risks of thermal imaging attacks, because the technologies used to support such attacks have become cheaper and more popular.

Dr Mohamed Khamis, who led the development of ThermoSecure, is a senior lecturer in the Department of Computer Science at Glasgow University. He said that it is more convenient than ever to use thermal imaging cameras. Their price is less than 200 pounds, and machine learning is becoming more and more popular. This makes it possible for people all over the world to develop systems along the lines of ThermoSeucre in order to steal passwords.

He said: "Computer security research should keep pace with these development trends in order to find new ways to reduce risks; We will continue to develop our technology and try to be one step ahead of the attackers, which is very important. "

However, although the research shows some advanced technologies that can be used to crack passwords, it is relatively simple for users to protect their accounts by using stronger passwords.

Dr. Khamis said that longer passphrases take longer to enter, which also makes it more difficult to get accurate readings on thermal imaging cameras, especially if users are blind. He also said that the verification mechanism using biometric identification has also increased protection.

Users can adopt alternative authentication methods (such as fingerprint or face recognition), which can eliminate many risks of hot attacks, thus helping to improve the security of their devices and keyboards.

And reference source: https://www.zdnet.com/article/this-thermal-attack-can-read-your-password-from-the-heat-your-fingertips-leave-behind/

Help TA Zan

Invitation letter The Aerospace Intelligent Manufacturing Industry Development Alliance invites you to attend the Global Industrial Internet Conference.

2022 Global Industrial Internet Conference will be held inNovember 7th-8th, 2022Held in Shenyang!

The conference was co-sponsored by the Ministry of Industry and Information Technology, China Association for Science and Technology and Liaoning Provincial People’s Government, and jointly hosted by Shenyang Municipal People’s Government, China Industrial Internet Research Institute, Liaoning Communications Administration, Liaoning Provincial Department of Industry and Information Technology and Liaoning Provincial Association for Science and Technology.

Continuing the theme of "Empowering High Quality and Creating New Kinetic Energy", the conference will hold a series of heavy activities such as the opening ceremony, conference report, special meeting and night talk, global forum of digital economy for small and medium-sized enterprises, investment promotion meeting for digital industrialization of industry, and the 4th China Industrial Internet Professional Competition.

Exhibition of Industrial Innovation Achievements

China Academy of Launch Vehicle TechnologyOrganizeAvenue Company, Aerospace Topology Company, Starr Company, Changgao Company, Equipment Company, Ami Company and Aohai Company.Waiting for intelligent manufacturing industry companies, in"4A-2" exhibition areaConduct a joint exhibition.

Booth renderings

Key displayLiaoning Province focuses on cultivating the provincial industrial Internet platform-"Long March Cloud" empowers the fields of intelligent manufacturing of high-end equipment, smart energy, smart tobacco, smart chemical fiber and smart ocean.Related achievements.

And relying on the "Long March Cloud" industrial Internet platform, using 5G, Internet of Things, artificial intelligence and other technologies, the command and dispatch system for the opening and closing ceremonies of the Beijing Winter Olympics, the command and communication system, the world’s largest LED display system and other core technology systems are developed and constructed.Show the space power behind the Winter Olympics.

Location: 4A-2

Theme forum

In addition to the Industrial Internet Innovation Exhibition, this conference will hold 16 thematic forums. It is jointly organized by Aerospace Avenue and Shenyang Municipal People’s Government, and co-organized by Liaoning Distributed Monitoring and Control System Professional Technology Innovation Center and Liaoning Industrial Control Information Security Industry-University-Research Alliance.Internet plus Industrial Equipment Manufacturing Theme ForumYuAt 14:00 on November 8th, in Conference Room 201 of Shenyang New World Expo. Hold.

At that time, experts, professors, scholars and representatives of manufacturing enterprises will be invited to discuss the understanding of the high-quality and sustainable development of equipment manufacturing industry, as well as the challenges faced by equipment manufacturing enterprises in the process of digital transformation and successful response practices, and plan the future layout and route planning of digitalization.

To better serve intelligent manufacturing application scenarios, create brand-new business modeling tools and high-performance IoT engines,The forum will also hold the launching ceremony of "Long March Cloud 5.0" new product simultaneously.Stay tuned.

The Founding Ceremony of the Alliance of Intelligent Manufacturing Industry Development

To promote the development of aerospace intelligent manufacturing industry and improve the overall competitiveness.

Relying on the 2022 Global Industrial Internet Conference, enterprises, universities and research institutes in the middle and lower reaches of aerospace intelligent manufacturing related industries are the main members.The Alliance for the Development of Intelligent Manufacturing Industry will hold its inaugural ceremony..

Give full play to the capabilities and technological advantages of each unit, realize resource sharing and mutual benefit, and jointly empower the intelligent transformation and upgrading of aerospace equipment manufacturing industry.

The 2022 Global Industrial Internet Conference is an industry conference to promote the digital and intelligent integrated development of manufacturing industry, which has strong influence and appeal.Intelligent Manufacturing Industry Development Alliance Enterprise-Beijing Aerospace Topology High-tech Co., Ltd. sincerely invites all of you to come and jointly explore a new path of integration and development of the new generation of information technology and manufacturing industry, and strive to create a new journey of building a manufacturing power and a network power!