Fraunhofer-Gesellschaft

Publica

Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

Analyzing the security and privacy of cloud-based video surveillance systems

 
: Obermaier, J.; Hutle, M.

:

Association for Computing Machinery -ACM-; Association for Computing Machinery -ACM-, Special Interest Group on Security, Audit and Control -SIGSAC-:
IoTPTS 2016, 2nd ACM International Workshop on IoT Privacy, Trust, and Security. Proceedings : Xi'an, China, May 30, 2016
New York: ACM, 2016
ISBN: 978-1-4503-4283-4
S.22-28
International Workshop on IoT Privacy, Trust, and Security (IoTPTS) <2, 2016, Xi'an>
Englisch
Konferenzbeitrag
Fraunhofer AISEC ()

Abstract
In the area of the Internet of Things, cloud-based camera surveillance systems are ubiquitously available for industrial and private environments. However, the sensitive nature of the surveillance use case imposes high requirements on privacy/confidentiality, authenticity, and availability of such systems. In this work, we investigate how currently available mass-market camera systems comply with these requirements. Considering two attacker models, we test the cameras for weaknesses and analyze for their implications. We reverse-engineered the security implementation and discovered several vulnerabilities in every tested system. These weaknesses impair the users' privacy and, as a consequence, may also damage the camera system manufacturer's reputation. We demonstrate how an attacker can exploit these vulnerabilities to blackmail users and companies by denial-of-service attacks, injecting forged video streams, and by eavesdropping private video data - even without physical access to the device.

: http://publica.fraunhofer.de/dokumente/N-422321.html