Skip to main navigation Skip to search Skip to main content

Design and analysis of enumeration attacks on finding friends with phone numbers: A case study with KakaoTalk

Research output: Contribution to journalArticlepeer-review

Abstract

Users' phone numbers are popularly used for finding friends in instant messaging (IM) services. In this paper, we present a new security concern about this search feature through a case study with KakaoTalk which is the most widely used IM in Korea. We demonstrate that there are multiple ways of collecting victims' personal information such as their (display) names, phone numbers and photos, which can be potentially misused for a variety of cyber–criminal activities. Our experimental results show that a user's personal data can be obtained automatically (0.26 s on average). The results also indicate that a large portion of KakaoTalk users (72.8%) have used real or real-like names in their profiles, which means that our discovered enumeration attacks seem to be practically dangerous. To mitigate these attacks, we present three countermeasures including a misuse detection system that can discover abnormal application activities within a certain time-window.

Original languageEnglish
Pages (from-to)267-275
Number of pages9
JournalComputers and Security
Volume52
DOIs
StatePublished - 1 Jul 2015

Keywords

  • Enumeration attack
  • Finding friends with phone numbers
  • Information leakage
  • Instant messaging
  • KakaoTalk
  • Privacy

Fingerprint

Dive into the research topics of 'Design and analysis of enumeration attacks on finding friends with phone numbers: A case study with KakaoTalk'. Together they form a unique fingerprint.

Cite this