312-50V11 · Question #958
Kate dropped her phone and subsequently encountered an issue with the phone's internal speaker. Thus, she is using the phone's loudspeaker for phone calls and other activities. Bob, an attacker…
The correct answer is D. ASpearphone attack. Bob performed an ASpearphone attack, a side-channel attack that exploits loudspeaker hardware vibrations to covertly capture audio output from a mobile device.
Question
Kate dropped her phone and subsequently encountered an issue with the phone's internal speaker. Thus, she is using the phone's loudspeaker for phone calls and other activities. Bob, an attacker, takes advantage of this vulnerability and secretly exploits the hardware of Kate's phone so that he can monitor the loudspeaker's output from data sources such as voice assistants, multimedia messages, and audio files by using a malicious app to breach speech privacy. What is the type of attack Bob performed on Kate in the above scenario?
Options
- AMan-in-the-disk attack
- BaLTEr attack
- CSIM card attack
- DASpearphone attack
How the community answered
(22 responses)- A5% (1)
- B9% (2)
- C5% (1)
- D82% (18)
Why each option
Bob performed an ASpearphone attack, a side-channel attack that exploits loudspeaker hardware vibrations to covertly capture audio output from a mobile device.
A Man-in-the-disk attack exploits Android's external storage to tamper with application data between storage and the app, not to monitor loudspeaker audio.
An aLTEr attack is a network-layer attack that targets LTE communications by impersonating a base station, and is unrelated to device loudspeaker hardware.
A SIM card attack targets the subscriber identity module to intercept calls or clone the device identity, not to exploit loudspeaker hardware for eavesdropping.
ASpearphone is a side-channel attack that leverages the device's accelerometer to eavesdrop on loudspeaker output by sensing the physical vibrations produced by the speaker hardware. In this scenario, Bob exploited Kate's already-active loudspeaker via a malicious app to monitor voice calls, multimedia messages, and audio files, which precisely matches the definition of an ASpearphone attack targeting speech privacy through hardware exploitation.
Concept tested: ASpearphone side-channel loudspeaker eavesdropping on mobile
Topics
Community Discussion
No community discussion yet for this question.