MagneticSpy: Exploiting Magnetometer in Mobile Devices for Website and Application Fingerprinting

by   Nikolay Matyunin, et al.

Recent studies have shown that aggregate CPU usage and power consumption traces on smartphones can leak information about applications running on the system or websites visited. In response, access to such data has been blocked for mobile applications starting from Android 7. In this work, we explore a new source of side-channel leakage for this class of attacks. Our method is based on the fact that electromagnetic activity caused by mobile processors leads to noticeable disturbances in magnetic sensor measurements on mobile devices, with the amplitude being proportional to the CPU workload. Therefore, recorded sensor data can be analyzed to reveal information about ongoing activities. The attack works on a number of devices: We evaluated 59 models of modern smartphones and tablets and observed the reaction of the magnetometer to CPU activity on 39 of them. On selected devices, we were able to successfully identify which application has been opened (with up to 90 web page has been loaded (up to 91 side channel poses a significant risk to end users' privacy, as the sensor data can be recorded from native apps and even from web pages without user permissions. Finally, we discuss possible countermeasures to prevent the presented information leakage.


A Tool for Conducting User Studies on Mobile Devices

With the ever-growing interest in the area of mobile information retriev...

Chameleon: A Color-Adaptive Web Browser for Mobile OLED Displays

Displays based on organic light-emitting diode (OLED) technology are app...

Web Performance with Android's Battery-Saver Mode

A Web browser utilizes a device's CPU to parse HTML, build a Document Ob...

Undermining User Privacy on Mobile Devices Using AI

Over the past years, literature has shown that attacks exploiting the mi...

Addressing Knowledge Leakage Risk caused by the use of mobile devices in Australian Organizations

Information and knowledge leakage has become a significant security risk...

Understanding Quality of Experiences on Different Mobile Browsers: Measurements, Analysis, and Implications

The web browser is one of the major channels to access the Internet on m...

A Context Model for Personal Data Streams

We propose a model of the situational context of a person and show how i...

Please sign up or login with your details

Forgot password? Click here to reset