VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing Attacks
Authors
Document Title
VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing Attacks
Document Information
- Subject Areas: Information Security, User Interaction, and Medical Communication
- Keywords: Information Verification, Phishing, Impersonation Attacks, Medical Communication, User Research, Usability Design, Elderly Users, Security Analysis, Verification System, SMS Phishing Attacks
Research Background and Problem
-
Identified Issues or Challenges:
- Communication channels between medical institutions and patients (e.g., SMS) are vulnerable to phishing and number spoofing attacks.
- Such attacks result in financial losses, sensitive information leaks, and even undermine patients' trust in medical systems.
- Existing SMS security solutions lack inclusivity and are particularly unfriendly to users without smartphones.
-
Significance:
- SMS is a crucial channel for elderly users (especially non-smartphone users) to receive medical notifications.
- According to the U.S. Federal Trade Commission (FTC), there were 68,496 cases of healthcare-related fraud in 2022, with total losses amounting to $17 million.
-
Research Motivation and Related Work:
- While defense research on email and web phishing is relatively mature, security research targeting SMS remains limited.
- Existing defense technologies (e.g., STIR/SHAKEN protocol) are not widely adopted due to high costs and deployment complexity.
- A low-cost, user-friendly security solution tailored for elderly users is urgently needed.
Solution
Proposed Solution by Authors
- VeriSMS:
- Allows patients to verify SMS content sent by medical institutions by calling a voice proxy number.
- Implements a verification mechanism using "Message ID" and "Secret Word Pair," where the "Secret Word Pair" is a unique static English word pair assigned to each user.
Innovations of the Solution
- Inclusivity:
- Requires no additional hardware or advanced settings; only SMS and phone functionality are needed.
- Trade-off Between Security and Usability:
- The design does not aim for absolute security but optimizes the balance between user habits and practical operations.
- Uses static "Secret Word Pair" to avoid the cumbersome process of authentication for every received SMS.
- Trust Root Based on Existing Mechanisms:
- Utilizes the physical number printed on medical cards as the system's trust root.
Implementation Steps and Key Technologies
- Users receive a medical card from the institution, which includes the official hospital phone number.
- Upon receiving a medical SMS:
- Users check the "Message ID" and "Secret Word Pair" in the SMS.
- They can call the voice proxy number printed on the card and input the "Message ID" to verify the SMS's authenticity.
- If the SMS contains an incorrect "Message ID" or "Secret Word Pair," the voice proxy will detect and alert the user that the message may be fraudulent.
- Two rounds of user research were conducted to validate the system design and improve user experience.
Research Outcomes
Specific Results
-
User Verification Effectiveness:
- Verified that users could correctly understand how VeriSMS works and identify phishing SMS.
- In the first (Phase-1) study, 83% of users correctly identified all legitimate messages; 77% of users were still able to correctly classify messages after 7+ days.
-
Security:
- Increased attacker costs: The probability of an attacker successfully guessing a user's "Message ID" and "Secret Word Pair" is 1.6×10⁻¹².
- Randomized response mechanisms prevent attackers from brute-forcing the voice proxy system.
-
Usability and User Experience:
- The system's SUS score averaged 79.1 (ranging between "Good" and "Excellent"), indicating high user acceptance.
- User research included participants from various age groups, with 43% aged 55 and above.
Comparative Advantages Over Existing Solutions
- Does not require modifications to underlying communication networks, avoiding the high costs of solutions like STIR/SHAKEN.
- Tailored for non-smartphone users, addressing a security gap in this market segment.
- Defends against common attacks (SMS fraud, number spoofing, etc.), significantly increasing phishing attack difficulty.
Experimental Results and Evaluation
- All participants successfully identified phishing messages (Fraud-A and Fraud-B scenarios).
- A small number of false positives were primarily due to user misunderstanding of the secret words or SMS content.
Limitations and Future Directions
-
Limitations:
- Small-scale user research, primarily involving participants with technical backgrounds.
- Pre-experiment tutorials may have introduced a "priming" effect on user results.
- Did not simulate more complex targeted phishing attacks (e.g., personalized messages with user names).
-
Future Directions:
- Collaborate with medical institutions to test the system on a broader patient population.
- Explore defenses against more sophisticated adaptive attacks, such as trust root forgery or user behavior manipulation scenarios.
- Enhance voice proxy interaction features to improve user experience in cases of input errors.
Conclusion
VeriSMS demonstrates an innovative approach that balances inclusivity, security, and user experience, offering a practical solution to combat phishing and fraud in medical communication.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can an SMS verification system be designed for non-smartphone users to block phishing attacks in medical communication?Category: Aging, Frailty, Dementia, and Elder CareSimilar questionsarrow_forward
- How effective are secret word pairs (unique static English phrases) at improving usability and security of SMS verification systems?Category: Aging, Frailty, Dementia, and Elder CareSimilar questionsarrow_forward
- Can verifying SMS content through voice agent numbers effectively block number spoofing attacks?Category: Aging, Frailty, Dementia, and Elder CareSimilar questionsarrow_forward
Practical Problems
1- Older patients lack secure verification methods and are easily harmed by medical SMS scams.Category: Aging, Frailty, Dementia, and Elder CareSimilar questionsarrow_forward
- 75%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 75%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 75%
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
CHI '22· Privacy by Design & User Control +1
- 75%
Obfuscation Remedies Harms Arising from Content Flagging of Photos
CHI '22· Privacy by Design & User Control +1
- 75%
Understanding Privacy Switching Behaviour on Twitter
CHI '22· Privacy by Design & User Control +1
- 75%
How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
CHI '23· Privacy by Design & User Control +1
- 75%
The Impact of Risk Appeal Approaches on Users’ Sharing Confidential Information
CHI '24· Privacy by Design & User Control +1
- 67%
Apps Against the Spread: Privacy Implications and User Acceptance of COVID-19-Related Smartphone Apps on Three Continents
CHI '21· Privacy by Design & User Control +2
- 60%
Contextualizing Privacy Decisions for Better Prediction (and Protection)
CHI '18· Privacy by Design & User Control +1
- 60%
“This App Would Like to Use Your Current Location to Better Serve You”: Importance of User Assent and System Transparency in Personalized Mobile Services
CHI '18· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)