Abstract:
In this paper, we draw attention to the problem of account association attacks designed to determine whether a target mobile phone number is associated with a particular ...Show MoreMetadata
Abstract:
In this paper, we draw attention to the problem of account association attacks designed to determine whether a target mobile phone number is associated with a particular online account. In the case of 4G/LTE, the adversary launches an account association attack by sending SMS messages to the target phone number and analyzing patterns in traffic related to the online account. We evaluate the proposed attacks in both a local 4G/LTE testbed and a major commercial 4G/LTE network. Our extensive experiments show that the proposed attacks can successfully identify account association with near-perfect accuracy. Our experiments also illustrate that the proposed attacks can be launched in a way that the victim receives no indication of being under attack.
Published in: IEEE Transactions on Dependable and Secure Computing ( Volume: 20, Issue: 4, 01 July-Aug. 2023)