A Smart Home is No Castle: Privacy Vulnerabilities of Encrypted IoT Traffic
arXiv:1705.06805
Abstract
The increasing popularity of specialized Internet-connected devices and appliances, dubbed the Internet-of-Things (IoT), promises both new conveniences and new privacy concerns. Unlike traditional web browsers, many IoT devices have always-on sensors that constantly monitor fine-grained details of users' physical environments and influence the devices' network communications. Passive network observers, such as Internet service providers, could potentially analyze IoT network traffic to infer sensitive details about users. Here, we examine four IoT smart home devices (a Sense sleep monitor, a Nest Cam Indoor security camera, a WeMo switch, and an Amazon Echo) and find that their network traffic rates can reveal potentially sensitive user interactions even when the traffic is encrypted. These results indicate that a technological solution is needed to protect IoT device owner privacy, and that IoT-specific concerns must be considered in the ongoing policy debate around ISP data collection and usage.
6 pages, 2 figures, appears in Workshop on Data and Algorithmic Transparency (DAT '16)
Cited by in corpus (13)
- Detection of Unauthorized IoT Devices Using Machine Learning Techniques
- The Case for Retraining of ML Models for IoT Device Identification at the Edge
- IoT Behavioral Monitoring via Network Traffic Analysis
- A Survey on Anonymous Communication Systems with a Focus on Dining Cryptographers Networks
- D-Score: An Expert-Based Method for Assessing the Detectability of IoT-Related Cyber-Attacks
- A Haystack Full of Needles: Scalable Detection of IoT Devices in the Wild
- Augmented Reality's Potential for Identifying and Mitigating Home Privacy Leaks
- Privacy-Preserving Detection of IoT Devices Connected Behind a NAT in a Smart Home Setup
- Video or Image Transmission Security for ESP-EYE IoT device used in Business Processes
- Smart Home, security concerns of IoT
- Privacy Leakage in Smart Homes and Its Mitigation: IFTTT as a Case Study
- Deep Adversarial Learning on Google Home devices
- Securing Smart Home Edge Devices against Compromised Cloud Servers