exploiting social navigation - black hat · pdf fileintro •navigation (like most content)...

35
Exploiting Social Navigation MEITAL BEN SINAI NIMROD PARTUSH SHIR YADID ERAN YAHAV Technion, Israel

Upload: phamdat

Post on 22-Mar-2018

219 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social NavigationMEITAL BEN SINAINIMROD PARTUSHSHIR YADIDERAN YAHAV

Technion, Israel

Page 2: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Outline

• Intro

• Goals & Motivation

• Attacks (+Demos \(^o^)/)

• Defense

• Summary & Conclusions

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 2

Page 3: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Intro

• Navigation (like most content) is becoming social

• Waze has over 50 Million Users

• The data is being crowdsourced

• But the crowd is oblivious to consequences

• What kind of attacks can be applied in this context?

• Can the crowdsourcing process be exploited?

• How to mitigate?

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 3

Page 4: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

How did this happen?

- while driving out of congested Jerusalem

with Waze on, on a Thursday afternoon.

As a joke, called and told my adviser

He took it too seriously..

Enter undergrads*!

+ =

4Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav

Page 5: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

5Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav

Page 6: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Research Goal

• Successfully apply a Sybil Attack to a social navigation system

• And explore what can be gained

“In a Sybil attack the attacker subverts the reputation system of a peer-to-peer network by creating a large number of pseudonymousidentities, using them to gain a disproportionately large influence”

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 6

Page 7: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Motivation

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 8

Page 8: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Attacks

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 10

Page 9: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Attack #1: Creating False Congestion & Affecting Routing

• (Insert Demo Here)

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 11

Page 10: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Navigation

Page 11: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Successful Attack

Page 12: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Navigation has Changed!

Page 13: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Spoof Attack: Responses

• "These students may be in an "excellence program" but obviously they, and more so the academic adviser, have lost their moral compass which is far more important for providing direction than Waze. Even if the project was done as a prank or as an academic exercise, the results are no different than physically going out and blocking a major roadway, something that presumably would not be tolerated by the legal system. And to then go and brag about it? Why are they not swiftly being investigated by the police.."

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 19

Page 14: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Spoof Attack: Disclosure

• We notified Waze of the attack 2 months before publishing

• We saw a change in the registration process roughly 6 months after publishing (+8 months)

• 6 months later, the attack seemed to have been patched

• At least in the small setting of our experiment

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 20

Page 15: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Spoof Attack: Implications

• National• Render the system useless• Waste time & fuel (& pollution) of users

• Private Financial• Congest (free) roads near toll roads• Make people drive by my restaurant\sign• Create congestion near the competition

• Criminal• Lead a target down an attacker controlled path

• Personal• Clear roads to save time• Get people out (or in?) of your neighborhood

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 21

Page 16: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Attack #2: Tracking Users

• (Insert Demo Here)

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 22

Page 17: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav23

Page 18: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav24

Page 19: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav25

Page 20: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav26

Page 21: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav27

(:You're Never Fully

Dressed Without A

Smile

Page 22: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav28

Page 23: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav29

Page 24: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav30

Page 25: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav31

Page 26: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav32

Page 27: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav33

Page 28: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav34

Hectororrantia

52724 385646

one year ago

Page 29: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Exploiting Social Navigation - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav35

Page 31: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Privacy Attack: Implications

• 2-way street

• Track location from identity

• Spy on people

• Know if a target is near you

• Infer identity from location

• Infer persons of interest from location

• Attack can be focused

• R\W

• Tracking is read, Spoofing is write

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 37

Page 32: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Mitigating Attacks

• Tracking attack: Waze allows you to opt out of the ‘Live map’

• But this is not the default option

• Spoofing attack: Can be mitigated by using carrier information

• Waze started doing this after the attack became pubic

• Read more in the white paper!

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 39

Page 33: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Summary

• A Sybil attack on Social navigation is possible

• We demonstrated a spoofing & tracking attack• Attacks requires no RE-ing, uses the Waze mechanism

against itself

• Tracked thousands of users

• Successfully created false congestion reports• Reproducible• Routing affected• Vast implications

• Suggested mitigation• Adapted by Waze (??)

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 48

Page 34: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Conclusions

• Users should beware of blindly trusting social applications

• Even in reliable applications such as Waze

• Applications with millions of users can and should put more effort into security

• Undergrads* can be useful

Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav 49

Page 35: Exploiting Social Navigation - Black Hat · PDF fileIntro •Navigation (like most content) is becoming social •Waze has over 50 Million Users •The data is being crowdsourced •But

Questions?

50Exploiting Social Navigation - Black Hat Asia 2015 - Meital Ben Sinai, Nimrod Partush, Shir Yadid, Eran Yahav