An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications
The digital contact tracing applications are one of the many initiatives to fight the COVID-19 virus. Some of these Apps use the Exposure Notification (EN) system available on Google and Apple’s operating systems. However, EN-based contact tracing Apps depend on the availability of Blueto...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2021-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/9492122/ |
id |
doaj-3a1571d79da94400a08cf4a4f43fe66e |
---|---|
record_format |
Article |
spelling |
doaj-3a1571d79da94400a08cf4a4f43fe66e2021-07-27T23:00:29ZengIEEEIEEE Access2169-35362021-01-01910336510337510.1109/ACCESS.2021.30990179492122An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing ApplicationsHenrique Faria0https://orcid.org/0000-0002-7210-6918Sara Paiva1https://orcid.org/0000-0002-0041-8939Pedro Pinto2https://orcid.org/0000-0003-1856-6101Instituto Politécnico de Viana do Castelo, Rua Escola Industrial e Comercial Nun’Álvares, Viana do Castelo, PortugalADiT-LAB, Instituto Politécnico de Viana do Castelo, Rua Escola Industrial e Comercial Nun’Álvares, Viana do Castelo, PortugalADiT-LAB, Instituto Politécnico de Viana do Castelo, Rua Escola Industrial e Comercial Nun’Álvares, Viana do Castelo, PortugalThe digital contact tracing applications are one of the many initiatives to fight the COVID-19 virus. Some of these Apps use the Exposure Notification (EN) system available on Google and Apple’s operating systems. However, EN-based contact tracing Apps depend on the availability of Bluetooth interfaces to exchange proximity identifiers, which, if compromised, directly impact their effectiveness. This paper discloses and details the Advertising Overflow attack, a novel internal Denial of Service (DoS) attack targeting the EN system on Android devices. The attack is performed by a malicious App that occupies all the Bluetooth advertising slots in an Android device, effectively blocking any advertising attempt of EN or other Apps. The impact of the disclosed attack and other previously disclosed DoS-based attacks, namely Battery Exhaustion and Storage Drain, were tested using two target smartphones and other six smartphones as attackers. The results show that the Battery Exhaustion attack imposes a battery discharge rate 1.95 times higher than in the normal operation scenario. Regarding the Storage Drain, the storage usage increased more than 30 times when compared to the normal operation scenario results. The results of the novel attack reveal that a malicious App can prevent any other App to place their Bluetooth advertisements, for any chosen time period, thus canceling the operation of the EN system and compromising the efficiency of any COVID contact tracing App using this system.https://ieeexplore.ieee.org/document/9492122/Attackapplicationsandroiddenial of serviceCOVID-19contact tracing |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Henrique Faria Sara Paiva Pedro Pinto |
spellingShingle |
Henrique Faria Sara Paiva Pedro Pinto An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications IEEE Access Attack applications android denial of service COVID-19 contact tracing |
author_facet |
Henrique Faria Sara Paiva Pedro Pinto |
author_sort |
Henrique Faria |
title |
An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications |
title_short |
An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications |
title_full |
An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications |
title_fullStr |
An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications |
title_full_unstemmed |
An Advertising Overflow Attack Against Android Exposure Notification System Impacting COVID-19 Contact Tracing Applications |
title_sort |
advertising overflow attack against android exposure notification system impacting covid-19 contact tracing applications |
publisher |
IEEE |
series |
IEEE Access |
issn |
2169-3536 |
publishDate |
2021-01-01 |
description |
The digital contact tracing applications are one of the many initiatives to fight the COVID-19 virus. Some of these Apps use the Exposure Notification (EN) system available on Google and Apple’s operating systems. However, EN-based contact tracing Apps depend on the availability of Bluetooth interfaces to exchange proximity identifiers, which, if compromised, directly impact their effectiveness. This paper discloses and details the Advertising Overflow attack, a novel internal Denial of Service (DoS) attack targeting the EN system on Android devices. The attack is performed by a malicious App that occupies all the Bluetooth advertising slots in an Android device, effectively blocking any advertising attempt of EN or other Apps. The impact of the disclosed attack and other previously disclosed DoS-based attacks, namely Battery Exhaustion and Storage Drain, were tested using two target smartphones and other six smartphones as attackers. The results show that the Battery Exhaustion attack imposes a battery discharge rate 1.95 times higher than in the normal operation scenario. Regarding the Storage Drain, the storage usage increased more than 30 times when compared to the normal operation scenario results. The results of the novel attack reveal that a malicious App can prevent any other App to place their Bluetooth advertisements, for any chosen time period, thus canceling the operation of the EN system and compromising the efficiency of any COVID contact tracing App using this system. |
topic |
Attack applications android denial of service COVID-19 contact tracing |
url |
https://ieeexplore.ieee.org/document/9492122/ |
work_keys_str_mv |
AT henriquefaria anadvertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications AT sarapaiva anadvertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications AT pedropinto anadvertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications AT henriquefaria advertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications AT sarapaiva advertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications AT pedropinto advertisingoverflowattackagainstandroidexposurenotificationsystemimpactingcovid19contacttracingapplications |
_version_ |
1721279255822729216 |