An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications

The digital contact tracing applications are one of the many initiatives to fight the COVID-19 virus. Some of these Apps use the Exposure Notification (EN) system available on Google and Apple’s operating systems. However, EN-based contact tracing Apps depend on the availability of Blueto...

Full description

Bibliographic Details
Main Authors: Henrique Faria, Sara Paiva, Pedro Pinto
Format: Article
Language:English
Published: IEEE 2021-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9492122/
id doaj-3a1571d79da94400a08cf4a4f43fe66e
record_format Article
spelling doaj-3a1571d79da94400a08cf4a4f43fe66e2021-07-27T23:00:29ZengIEEEIEEE Access2169-35362021-01-01910336510337510.1109/ACCESS.2021.30990179492122An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing ApplicationsHenrique Faria0https://orcid.org/0000-0002-7210-6918Sara Paiva1https://orcid.org/0000-0002-0041-8939Pedro Pinto2https://orcid.org/0000-0003-1856-6101Instituto Politécnico de Viana do Castelo, Rua Escola Industrial e Comercial Nun’Álvares, Viana do Castelo, PortugalADiT-LAB, Instituto Politécnico de Viana do Castelo, Rua Escola Industrial e Comercial Nun’Álvares, Viana do Castelo, PortugalADiT-LAB, Instituto Politécnico de Viana do Castelo, Rua Escola Industrial e Comercial Nun’Álvares, Viana do Castelo, PortugalThe digital contact tracing applications are one of the many initiatives to fight the COVID-19 virus. Some of these Apps use the Exposure Notification (EN) system available on Google and Apple’s operating systems. However, EN-based contact tracing Apps depend on the availability of Bluetooth interfaces to exchange proximity identifiers, which, if compromised, directly impact their effectiveness. This paper discloses and details the Advertising Overflow attack, a novel internal Denial of Service (DoS) attack targeting the EN system on Android devices. The attack is performed by a malicious App that occupies all the Bluetooth advertising slots in an Android device, effectively blocking any advertising attempt of EN or other Apps. The impact of the disclosed attack and other previously disclosed DoS-based attacks, namely Battery Exhaustion and Storage Drain, were tested using two target smartphones and other six smartphones as attackers. The results show that the Battery Exhaustion attack imposes a battery discharge rate 1.95 times higher than in the normal operation scenario. Regarding the Storage Drain, the storage usage increased more than 30 times when compared to the normal operation scenario results. The results of the novel attack reveal that a malicious App can prevent any other App to place their Bluetooth advertisements, for any chosen time period, thus canceling the operation of the EN system and compromising the efficiency of any COVID contact tracing App using this system.https://ieeexplore.ieee.org/document/9492122/Attackapplicationsandroiddenial of serviceCOVID-19contact tracing
collection DOAJ
language English
format Article
sources DOAJ
author Henrique Faria
Sara Paiva
Pedro Pinto
spellingShingle Henrique Faria
Sara Paiva
Pedro Pinto
An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications
IEEE Access
Attack
applications
android
denial of service
COVID-19
contact tracing
author_facet Henrique Faria
Sara Paiva
Pedro Pinto
author_sort Henrique Faria
title An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications
title_short An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications
title_full An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications
title_fullStr An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications
title_full_unstemmed An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications
title_sort advertising overflow attack against android exposure notification system impacting covid-19 contact tracing applications
publisher IEEE
series IEEE Access
issn 2169-3536
publishDate 2021-01-01
description The digital contact tracing applications are one of the many initiatives to fight the COVID-19 virus. Some of these Apps use the Exposure Notification (EN) system available on Google and Apple’s operating systems. However, EN-based contact tracing Apps depend on the availability of Bluetooth interfaces to exchange proximity identifiers, which, if compromised, directly impact their effectiveness. This paper discloses and details the Advertising Overflow attack, a novel internal Denial of Service (DoS) attack targeting the EN system on Android devices. The attack is performed by a malicious App that occupies all the Bluetooth advertising slots in an Android device, effectively blocking any advertising attempt of EN or other Apps. The impact of the disclosed attack and other previously disclosed DoS-based attacks, namely Battery Exhaustion and Storage Drain, were tested using two target smartphones and other six smartphones as attackers. The results show that the Battery Exhaustion attack imposes a battery discharge rate 1.95 times higher than in the normal operation scenario. Regarding the Storage Drain, the storage usage increased more than 30 times when compared to the normal operation scenario results. The results of the novel attack reveal that a malicious App can prevent any other App to place their Bluetooth advertisements, for any chosen time period, thus canceling the operation of the EN system and compromising the efficiency of any COVID contact tracing App using this system.
topic Attack
applications
android
denial of service
COVID-19
contact tracing
url https://ieeexplore.ieee.org/document/9492122/
work_keys_str_mv AT henriquefaria anadvertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications
AT sarapaiva anadvertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications
AT pedropinto anadvertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications
AT henriquefaria advertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications
AT sarapaiva advertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications
AT pedropinto advertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications
_version_ 1721279255822729216