Location based services can be divided into four categories: location based search, location based commerce, navigation services, and tracking applications. Most location based applications lack location verification, leaving them vulnerable to location spoofing attacks where fake locations can be injected. While this allows rewards and deals to be obtained fraudulently, it can also spoof tracking systems. Solutions include client and server side validations of location data to detect spoofing, but GPS signals can also be directly spoofed through simulator tools.
2. +
SOFTWARE DEVELOPMENT DONE RIGHT
Netherlands | USA | India | France | UK
www.xebia.in; Blog :http://.xebee.xebia.in
3. What are Location Based Services ?
→ A service that depends on the network knowing your location
LBS allow consumers to receive services and advertising based on
their geographic location.
4. Location Based Services
Location Based Services Can be basically divided into 4 Broad
Categories1. Location Based Search Information
2. Location Based Commerce
3. Navigation Services
4. Tracking Applications
13. Loca&on
Accuracy
and
Usage
Precise
Loca+on
Acquisi+on
GPS (Global Positioning System)
• 24 satellites in orbit. Typically 5 to 8 are
visible from any one place
• Distance calculated by time it takes for signal
to travel from satellite to receiver. Calculating
the time it takes from 4 satellites provides an
accurate fix.
14. Loca&on
Accuracy
and
Usage
Precise
Loca+on
Acquisi+on
Assisted -GPS
• GPS has a slow time to
fix unless it is
permanently tracking
satellites
• Assisted GPS is based
upon providing GPS
satellite information to
the handset, via the
cellular network
• Assisted GPS gives
improvements in
Time to First Fix
15. NO
Loca+on
Verifica+on
• 99 % of Applications Providing Location Based
Services lack Location Verification Mechanism.
This
Leaves
all
these
Applica+ons
Vulnerable
to
Loca+on
Spoofing
A=acks
18. Results
of
Loca+on
Spoofing
• Commercial
applica+ons
can
be
fooled
by
Checking
in
with
spoofed
Loca+ons.
• Rewards,
Offers,
Deals
on
Specific
Loca+ons
Can
be
Availed
☺
19. Results
of
Loca+on
Spoofing
• Tracking
Applica+ons
can
be
fooled
by
fixing
a
fake
loca+on
or
Randomly
changing
Loca+on.
• Incase
of
Con+nuous
Fleet
tracking,
Pre-‐
Designed
Routes
can
be
Simulated
to
spoof
con+nuous
Loca+on
20. Solu+ons
to
Loca+on
Spoofing
Client
side
valida+ons
• Hourly
loca+on
• Cell
towers
triangula+on
Server
side
Valida+ons
•
•
•
•
•
•
•
Date
of
Registra+on
RapidFire
Check-‐ins
Previous
Check-‐ins,
History
Distance
Algorithims
Traffic
updates.
Speed
and
stops
Loca+ons
in
other
Applica+ons