中文

物联网的暗面与明面:识别智能家居设备与服务的攻击与对策

密码学与安全 2021-07-27 v4 机器学习

摘要

我们提出了一种基于机器学习的新攻击,利用网络模式在 WiFi 无线频谱中检测智能物联网设备及其运行服务的存在。我们开展了广泛的数据收集测量活动,并构建了描述三种流行物联网智能家居设备(即 Google Nest Mini、Amazon Echo 和 Amazon Echo Dot)流量模式的模型。我们证明,在拥挤的 WiFi 场景中,可以以压倒性概率检测并识别上述设备的存在及其运行的服务。本工作证明,仅标准的加密技术不足以保护终端用户的隐私,因为网络流量本身会暴露设备及其关联服务的存在。尽管需要更多工作来防止不可信第三方检测并识别用户的设备,我们引入了 Eclipse 这一缓解此类攻击的技术,它通过重塑流量使设备及其关联服务的识别类似于随机分类基线。

关键词

引用

@article{arxiv.2009.07672,
  title  = {The Dark (and Bright) Side of IoT: Attacks and Countermeasures for Identifying Smart Home Devices and Services},
  author = {Ahmed Mohamed Hussain and Gabriele Oligeri and Thiemo Voigt},
  journal= {arXiv preprint arXiv:2009.07672},
  year   = {2021}
}

备注

15 pages, 7 figures. Accepted for the 9th International Symposium On Security And Privacy On Internet of Things (SPIoT), 2020