An avalanche of unwanted post could be released upon an unsuspecting victim using nothing more than an internet connection and some simple code, a team of US researchers says.
The attack, devised by Aviel Rubin at Johns Hopkins University and Simon Byers and David Kormann at AT&T Labs, involves automatically subscribing a victim to hundreds of thousands of catalogue request forms that are available online.
Using search engines to instantly locate such forms and then simple code to automatically feed a victim’s name and address into them, the researchers say such an attack would be dangerously simple to carry out.
Advertisement
“We have been living in a state of bliss, spoiled by the lack of any concerted attacks that utilise these new services, search engines in particular,†the researchers write in a paper entitled Defending Against an Internet-based Attack on the Physical World.
The researchers say guarding against an attack would be difficult. One method might be to include a visual puzzle in web forms that humans can easily solve but which foils automated programs. However, in weighing up possible defences, the researchers conclude: “Defending against these new attacks often requires taking large steps backwards in the convenience offered by technology.â€
Spammer spammed
But the inconvenience caused by such an attack was recently demonstrated when self-confessed junk email sender Alan Ralsky was targeted with junk post. After his home address was published online, a concerted effort by frustrated recipients of spam email began entering Ralsky’s address into as many online catalogue forms as they could find. A week later he was receiving thousands of letters per day.
Aside from the impact on individuals, Rubin and his co-authors warn that such an attack could even disable a local postal office.
“There’s no easy defense,†writes computer security consultant Bruce Schneier, in his monthly newsletter Cryptogram. “If the attacker used an anonymous connection to launch his attack – one of the zillions of open wireless networks would be a good choice – I don’t see how he would ever get caught.â€
Schneier says the attack is made possible when an existing physical process is moved online, and then automated in an unanticipated way. He warns: “They’re emergent properties of the systems. And they’re going to become more prevalent in the years ahead.â€