EvilScreen Attack: Smart TV Hijacking via Multi-channel Remote Control Mimicry

10/06/2022
by   Yiwei Zhang, et al.
0

Modern smart TVs often communicate with their remote controls (including those smart phone simulated ones) using multiple wireless channels (e.g., Infrared, Bluetooth, and Wi-Fi). However, this multi-channel remote control communication introduces a new attack surface. An inherent security flaw is that remote controls of most smart TVs are designed to work in a benign environment rather than an adversarial one, and thus wireless communications between a smart TV and its remote controls are not strongly protected. Attackers could leverage such flaw to abuse the remote control communication and compromise smart TV systems. In this paper, we propose EvilScreen, a novel attack that exploits ill-protected remote control communications to access protected resources of a smart TV or even control the screen. EvilScreen exploits a multi-channel remote control mimicry vulnerability present in today smart TVs. Unlike other attacks, which compromise the TV system by exploiting code vulnerabilities or malicious third-party apps, EvilScreen directly reuses commands of different remote controls, combines them together to circumvent deployed authentication and isolation policies, and finally accesses or controls TV resources remotely. We evaluated eight mainstream smart TVs and found that they are all vulnerable to EvilScreen attacks, including a Samsung product adopting the ISO/IEC security specification.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/10/2018

IREXF: Data Exfiltration from Air-gapped Networks by Infrared Remote Control Signals

he technology on infrared remote control is widely applied in human dail...
research
04/05/2019

EvoCreeper: Automated Black-Box Model Generation for Smart TV Applications

Smart TVs are coming to dominate the television market. This accompanied...
research
11/03/2022

A Comparative Study of Smartphone and Smart TV Apps

Context: Smart TVs have become one of the most popular television types....
research
02/14/2022

Analog Physical-Layer Relay Attacks with Application to Bluetooth and Phase-Based Ranging

Today, we use smartphones as multi-purpose devices that communicate with...
research
04/03/2020

Testing the Usability and Accessibility of Smart TV Applications Using an Automated Model-based Approach

As the popularity of Smart Televisions (TVs) and interactive Smart TV ap...
research
04/18/2022

Collusion-resistant fingerprinting of parallel content channels

The fingerprinting game is analysed when the coalition size k is known t...
research
01/21/2021

BB: Booting Booster for Consumer Electronics with Modern OS

Unconventional computing platforms have spread widely and rapidly follow...

Please sign up or login with your details

Forgot password? Click here to reset