VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing Attacks

Privacy by Design & User ControlPrivacy Perception & Decision-MakingPhysicians, Nurses & CliniciansPrivacy Policy Makers

Document Title

VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing Attacks

Document Information

  • Subject Areas: Information Security, User Interaction, and Medical Communication
  • Keywords: Information Verification, Phishing, Impersonation Attacks, Medical Communication, User Research, Usability Design, Elderly Users, Security Analysis, Verification System, SMS Phishing Attacks

Research Background and Problem

  • Identified Issues or Challenges:

    • Communication channels between medical institutions and patients (e.g., SMS) are vulnerable to phishing and number spoofing attacks.
    • Such attacks result in financial losses, sensitive information leaks, and even undermine patients' trust in medical systems.
    • Existing SMS security solutions lack inclusivity and are particularly unfriendly to users without smartphones.
  • Significance:

    • SMS is a crucial channel for elderly users (especially non-smartphone users) to receive medical notifications.
    • According to the U.S. Federal Trade Commission (FTC), there were 68,496 cases of healthcare-related fraud in 2022, with total losses amounting to $17 million.
  • Research Motivation and Related Work:

    • While defense research on email and web phishing is relatively mature, security research targeting SMS remains limited.
    • Existing defense technologies (e.g., STIR/SHAKEN protocol) are not widely adopted due to high costs and deployment complexity.
    • A low-cost, user-friendly security solution tailored for elderly users is urgently needed.

Solution

Proposed Solution by Authors

  • VeriSMS:
    • Allows patients to verify SMS content sent by medical institutions by calling a voice proxy number.
    • Implements a verification mechanism using "Message ID" and "Secret Word Pair," where the "Secret Word Pair" is a unique static English word pair assigned to each user.

Innovations of the Solution

  1. Inclusivity:
    • Requires no additional hardware or advanced settings; only SMS and phone functionality are needed.
  2. Trade-off Between Security and Usability:
    • The design does not aim for absolute security but optimizes the balance between user habits and practical operations.
    • Uses static "Secret Word Pair" to avoid the cumbersome process of authentication for every received SMS.
  3. Trust Root Based on Existing Mechanisms:
    • Utilizes the physical number printed on medical cards as the system's trust root.

Implementation Steps and Key Technologies

  1. Users receive a medical card from the institution, which includes the official hospital phone number.
  2. Upon receiving a medical SMS:
    • Users check the "Message ID" and "Secret Word Pair" in the SMS.
    • They can call the voice proxy number printed on the card and input the "Message ID" to verify the SMS's authenticity.
  3. If the SMS contains an incorrect "Message ID" or "Secret Word Pair," the voice proxy will detect and alert the user that the message may be fraudulent.
  4. Two rounds of user research were conducted to validate the system design and improve user experience.

Research Outcomes

Specific Results

  1. User Verification Effectiveness:

    • Verified that users could correctly understand how VeriSMS works and identify phishing SMS.
    • In the first (Phase-1) study, 83% of users correctly identified all legitimate messages; 77% of users were still able to correctly classify messages after 7+ days.
  2. Security:

    • Increased attacker costs: The probability of an attacker successfully guessing a user's "Message ID" and "Secret Word Pair" is 1.6×10⁻¹².
    • Randomized response mechanisms prevent attackers from brute-forcing the voice proxy system.
  3. Usability and User Experience:

    • The system's SUS score averaged 79.1 (ranging between "Good" and "Excellent"), indicating high user acceptance.
    • User research included participants from various age groups, with 43% aged 55 and above.

Comparative Advantages Over Existing Solutions

  • Does not require modifications to underlying communication networks, avoiding the high costs of solutions like STIR/SHAKEN.
  • Tailored for non-smartphone users, addressing a security gap in this market segment.
  • Defends against common attacks (SMS fraud, number spoofing, etc.), significantly increasing phishing attack difficulty.

Experimental Results and Evaluation

  • All participants successfully identified phishing messages (Fraud-A and Fraud-B scenarios).
  • A small number of false positives were primarily due to user misunderstanding of the secret words or SMS content.

Limitations and Future Directions

  • Limitations:

    • Small-scale user research, primarily involving participants with technical backgrounds.
    • Pre-experiment tutorials may have introduced a "priming" effect on user results.
    • Did not simulate more complex targeted phishing attacks (e.g., personalized messages with user names).
  • Future Directions:

    • Collaborate with medical institutions to test the system on a broader patient population.
    • Explore defenses against more sophisticated adaptive attacks, such as trust root forgery or user behavior manipulation scenarios.
    • Enhance voice proxy interaction features to improve user experience in cases of input errors.

Conclusion

VeriSMS demonstrates an innovative approach that balances inclusivity, security, and user experience, offering a practical solution to combat phishing and fraud in medical communication.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/148268/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642027
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
No award tagged
group
Authors
8 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Physicians, Nurses & Clinicians, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers