skip to main content
10.1145/2899007.2899008acmconferencesArticle/Chapter ViewAbstractPublication Pagesasia-ccsConference Proceedingsconference-collections
research-article

Analyzing the Security and Privacy of Cloud-based Video Surveillance Systems

Published:30 May 2016Publication History

ABSTRACT

In the area of the Internet of Things, cloud-based camera surveillance systems are ubiquitously available for industrial and private environments. However, the sensitive nature of the surveillance use case imposes high requirements on privacy/confidentiality, authenticity, and availability of such systems. In this work, we investigate how currently available mass-market camera systems comply with these requirements. Considering two attacker models, we test the cameras for weaknesses and analyze for their implications. We reverse-engineered the security implementation and discovered several vulnerabilities in every tested system. These weaknesses impair the users' privacy and, as a consequence, may also damage the camera system manufacturer's reputation. We demonstrate how an attacker can exploit these vulnerabilities to blackmail users and companies by denial-of-service attacks, injecting forged video streams, and by eavesdropping private video data - even without physical access to the device. Our analysis shows that current systems lack in practice the necessary care when implementing security for IoT devices.

References

  1. A. Costin, J. Zaddach, A. Francillon, D. Balzarotti, and S. Antipolis. A large-scale analysis of the security of embedded firmwares. In USENIX Security Symposium, 2014. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Deloitte & Technische Universität München. Ready for Takeoff? Smart Home aus Konsumentensicht. http://www.connected-living.org/content/4-information/5-downloads/4-studien/5-ready-for-takeoff/deloitte-smart-home-consumer-survey-20150701.pdf, July 2015.Google ScholarGoogle Scholar
  3. GfK. Smart home beats wearables for impact on lives, say consumers. http://www.gfk.com/fileadmin/user_upload/dyna_content_import/2015-11-24_press_releases/data/Documents/Press-Releases/2015/2015-11-11_smart-home_press-release_global.pdf, November 2015.Google ScholarGoogle Scholar
  4. M. Green. Attack of the week: FREAK (or 'factoring the NSA for fun and profit'). http://blog.cryptographyengineering.com/2015/03/attack-of-week-freak-or-factoring-nsa.html, Mar. 2015.Google ScholarGoogle Scholar
  5. P. Kocher, R. Lee, G. McGraw, and A. Raghunathan. Security as a new dimension in embedded system design. In Proceedings of the 41st Annual Design Automation Conference, DAC '04, pages 753--760, New York, NY, USA, 2004. ACM. Moderator-Ravi, Srivaths. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. N. Serpanos and A. Papalambrou. Security and privacy in distributed smart cameras. Proceedings of the IEEE, 96(10):1678--1687, 2008.Google ScholarGoogle Scholar
  7. H. Vagts and J. Beyerer. Security and privacy challenges in modern surveillance systems. In Proceedings of the Future Security Research Conference, pages 94--116, 2009.Google ScholarGoogle Scholar
  8. T. Winkler and B. Rinner. Security and privacy protection in visual sensor networks: A survey. ACM Computing Surveys (CSUR), 47(1):2, 2014. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. T. Winkler and B. Rinner. Secure embedded visual sensing in end-user applications with trusteye. m4. In Intelligent Sensors, Sensor Networks and Information Processing (ISSNIP), 2015 IEEE Tenth International Conference on, pages 1--6. IEEE, 2015.Google ScholarGoogle Scholar

Index Terms

  1. Analyzing the Security and Privacy of Cloud-based Video Surveillance Systems

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Conferences
            IoTPTS '16: Proceedings of the 2nd ACM International Workshop on IoT Privacy, Trust, and Security
            May 2016
            54 pages
            ISBN:9781450342834
            DOI:10.1145/2899007

            Copyright © 2016 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 30 May 2016

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • research-article

            Acceptance Rates

            IoTPTS '16 Paper Acceptance Rate6of12submissions,50%Overall Acceptance Rate16of39submissions,41%

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader