Is Anybody Home? Inferring Activity From Smart Home Network Traffic - eScholarship
Bogdan Copos, Karl Levitt, Matt Bishop, Jeff Rowe · 2016
Is Anybody Home? Inferring Activity From Smart Home Network Traffic Bogdan Copos ∗ , Karl Levitt † , Matt Bishop ‡ , Jeff Rowe § Department of Computer Science University of California, Davis Email: ∗ [email protected], † [email protected], ‡ [email protected], § [email protected], Abstract—As smart home devices are introduced into our homes, security and privacy concerns are being raised. Smart home devices collect, exchange, and transmit various data about the environment of our homes. This data can not only be used to characterize a physical property but also to infer personal information about the inhabitants. One potential attack vector for smart home devices is the use of traffic classification as a source for covert channel attacks. Specifically, we are concerned with the use of traffic classification techniques for inferring events taking place within a building. In this work, we study two of the most popular smart home devices, the Nest Thermostat and the wired Nest Protect (i.e. smoke and carbon dioxide detector) and show that traffic analysis can be used to learn potentially sensitive information about the state of a smart home. Among other observations, we show that we can determine, with 88% and 67% accuracy respectively, when the thermostat transitions between the Home and Auto Away mode and vice versa, based only on network traffic originating from the device. This information may be used, for example, by an attacker to infer whether the home is occupied. I. I NTRODUCTION Smart home devices are becoming increasingly popular in households around the world. Nest Labs, one of the most popular manufacturers of smart thermostats and smoke detectors, is believed to have sold 440,000 smoke detector units over the span of four months in 2014 alone. Smart home devices are designed to help homeowners automate and simplify mundane tasks around their property. However, bringing internet connectivity to household devices has also introduced many security and privacy concerns. At the end of 2015, security researchers discovered a vulnerability in Barbie dolls which would allow attackers to not only steal personal information but also convert a doll into a spying device capable of listening into conversations [6]. In early 2016, security research from Rapid7 found vulnerabilities in Comcast’s Xfinity Home Security system that would cause the system to not report when a property’s windows and/or doors were compromised [19]. In this paper, we investigate how device-to-device and device-to-cloud smart home network traffic can be used to infer personal information. Specifically, we use traffic analysis techniques on network traffic generated by devices from Nest Labs to learn information about the presence of residents and other events occurring within the property. Traffic analysis is the process of intercepting and analyzing network packets in order to deduce information from patterns in communication. The experiments involve two smart home devices, a smart thermostat and a smart smoke and carbon dioxide detector. The rest of the paper is organized as follows: • Section II describes relevant previous work. • Section III gives a detailed rundown of the devices used in this study and their features and capabilities. • In Section IV the data collection process is described. • In Section V, the methodology behind the traffic classi- fication is explained. • Section VI reports the findings of our analysis. • Section VII describes how the findings were tested for validity and presents information about the accuracy of our findings. • Section VIII discusses limitations of our approach. • In section IX we provide some initial ideas for solutions and list possible future work. II. P REVIOUS W ORK Traffic analysis attacks were highlighted in “Attacks of the SSL 3.0 protocol” [16], by Wagner and Schneier who showed the URL of an HTTP GET request is leaked in SSL because cipher-texts fail to disguise the plaintext length. Later, Cheng and Avnur [3] show that websites can be fingerprinted by performing traffic analysis of SSL encrypted web browsing traffic. Ever since, there have been a number of works [2], [7], [8], [10], [13], [15] exploring traffic analysis attacks using various features including source and destination attributes (e.g. address, port), protocol, packet and connection sizes, and even timing information (e.g. duration of connec- tions, burstiness of transmissions). Efforts have also been put into developing countermeasures for such attacks [5], [11], [18]. Countermeasure techniques include traffic padding and traffic masking. Another variation is in the implementation, whether server side, client side, or both. Recently, in “Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures Fail” [4], Dyer, Coull et. al. provide the first comprehensive analysis of some of the proposed traffic analysis countermeasures and show why they fail to protect against attacks. The authors argue that there is no efficient solution.