• Survey on Security Risks in NFC Application

  • Part 1: User Information

  • What is your gender?
  • What is your age?
  • What is your highest/ current level of education?

  • What is your occupation?
  • Have you heard of Near Field Communication (NFC)?*
  • How do you rate your level of expertise on NFC technology?
  • How long is your knowledge/experience with NFC?
  • Part 2: CVSS Quick Reference

  • This section presented 10 case studies regarding to NFC application. You need to evaluate the case studies based on the metrics given. The case studies are evaluated using Common Vulnerability Scoring System (CVSS) as available at https://goo.gl/DfAwvo. 

    PLEASE USE THE CALCULATOR PROVIDED and INSERT THE SCORING VALUES INTO THE GIVEN BOXES.

     

    QUICK REFERENCE TO EVALUATE

    (Reference:https://www.first.org/cvss/user-guide)

    Attack Vector

    Attack Vector

    Attack Complexity

    Attack Complexity

    Privileges Required

    Privileges Required

    User Interaction

    User Interaction

    Scope

    Scope

    Note, if Scope change has not occurred, Confidentiality, Integrity and Availability impacts reflect consequence to the vulnerable component, otherwise they reflect consequence to the component that suffers the greater impact.

    Confidentiality Impact

    Confidentiality Impact

    Integrity Impact

    Integrity Impact

    Availability Impact

    Availability Impact

  • Part 3: Evaluation of case study

  • 1. Eavesdropping

    Vulnerability: NFC communication takes place in wireless mode which has high chance for eavesdropping. The content of NFC card can be read by malicious attacker even the NFC device is not in use. Hence, the information can be intercepted and obtained by a malicious party.
     
    Attack Scenario: A user touches his NFC smartphone to access and enter into a building. He does not realize that there is a transmitter that can be used to eavesdrop the device’s activity. In this situation, attacker can use bigger and powerful antennas or transmitter to eavesdrop NFC communication over greater distance.
     eavesdrop
  • 2. Corruption of data

    Vulnerability: Attacker can try to disturb the communication between NFC devices by modifying the data that transmitted through NFC devices into unrecognized format. When sender and receiver of NFC devices try to communicate with each other, the receiver is not able to understand the data by the sender. Data error may occur when user touch the NFC device to NFC reader.
     
    Attack Scenario: A user touches his NFC smartphone which contain a valid digital ticket to access the railway entry. The NFC reader does not recognize the ticket. Hence, the ticket is useless and the NFC reader could not retrieve any data.
  • 3. Modified data

    Vulnerability: Data that received from devices is valid but it has been modified by attacker to disturb communication between NFC devices. NFC reader read a manipulated data that has been modified by attacker to access ticketing system. The actual data that has been changed is still valid but the data may incorrect.
     
     
    Attack Scenario: A user touches his NFC smartphone on NFC reader to enter a cinema. The NFC smartphone acts as digital ticket to enter the cinema. A seat was reserved to the user as he bought the ticket. But the seat that was reserved for him was booked by another person. Hence, there are redundant information in the ticketing data.
  • 4. Spoofing

    Vulnerability: Tag spoofing happens when authorized NFC tag is replaced with the other tag that is under attacker or fraudster’s control. The attacker supplies false information such as fake domain name or false email in the tag contents.
     
    Attack Scenario: User touch NFC smartphone to NFC tag to gain access about ticketing information in particular website by touch his smartphone to an NFC smart poster. Different website is opened as the original website has been replaced with fake/false website.
  • 5. Ticket Cloning

    Vulnerability: The e-tickets has been copied and shared to others with the same features and functions.
     
    Attack Scenario: The e-tickets are distributed to everyone and can be used for entrance ticketing. The purchased tickets could be reused and shared unlimitedly since it is not validated. If the tickets have been validated, they can be used until expiration.
  • 6. Denial of service (DOS)

    Vulnerability: NFC technology activates with a card and NFC reader can work even with wrong card, sending error message or empty card.
     
    Attack Scenario: Attacker tricks user to install malicious application in the mobile phone. The application sends a massive asking message that causes the application installation aborted. When there is flooding access request to NFC device, the NFC service may suspended.
  • 7. Relay attack

    Vulnerability: Rogue devices are placing between the communications of two NFC devices so that the communication goes unnoticed through that third device.
     
    Attack Scenario: In relay attack, attacker uses a relay device and proxy device as decoy to perform the access/ticketing system using NFC smartphone. A relay device is placed close to the victim's smartphone. A proxy device is placed close to NFC reader to perform the system. When a user touch his smartphone to NFC reader, the communication between NFC reader and smartphone is relayed over proxy and relay device through wireless communication. The proxy device send credentials to NFC reader as the real owner and relay attack is successful when the NFC reader cannot detect the fake device.
     
    relay atack
  • 8. Phishing

    Vulnerability: Attacker tries to mislead user by modifying or replacing contents data of NFC tags.
     
    Attack Scenario: The NFC tag content has been altered by attacker and user will access into the malicious website that have similar features and functions with original website. Attacker tricks user to enter details of personal information for attacker’s benefit.
  • 9. Only use single ID

    Vulnerability: Every smart card has a single unique ID and it is useful for identification and do not occur any authentication. Unique ID of NFC chip can always be read and also the non-secured personal data on device or tag.
     
    Attack Scenario: Attacker can copy the unique ID and act as the owner of the ID. He can access application that specified for the ID as the victim is not aware of the situation.
  • 10. Insertion of unwanted data

    Vulnerability: Unwanted data is inserted by attacker while data exchanging between two devices. Attacker manipulated data depends on duration of communication and the response time of receiving device. The answering device may need a long time to response to answer. The insertion is successful only when attacker inserts and sends the data before the original device starts to answer. If the original device and spoofed transmit overlap at the same time, the data will be corrupted.
     
    Attack Scenario: A user touches his NFC smartphone as digital ticket to board a train. The NFC reader from the train station takes a long time to read the data that saved in the ticket. Then, the data become corrupted.
  • Part 4: Solution and recommendation

  • Each of the attacks given have their own solutions. In your opinion, choose 2 solutions to prevents those attacks and to have a secure NFC application in overall especially for access control or ticketing application. (Choose TWO)
  • Thank you for answering.

  • Should be Empty: