ZLeaks: Passive Inference Attacks on Zigbee based Smart Homes

07/22/2021
by   Narmeen Shafqat, et al.
0

In this work, we analyze the privacy guarantees of Zigbee protocol, an energy-efficient wireless IoT protocol that is increasingly being deployed in smart home settings. Specifically, we devise two passive inference techniques to demonstrate how a passive eavesdropper, located outside the smart home, can reliably identify in-home devices or events from the encrypted wireless Zigbee traffic by 1) inferring a single application layer (APL) command in the event's traffic burst, and 2) exploiting the device's periodic reporting pattern and interval. This enables an attacker to infer user's habits or determine if the smart home is vulnerable to unauthorized entry. We evaluated our techniques on 19 unique Zigbee devices across several categories and 5 popular smart hubs in three different scenarios: i) controlled shield, ii) living smart-home IoT lab, and iii) third-party Zigbee captures. Our results indicate over 85 determining events and devices using the command inference approach, without the need of a-priori device signatures, and 99.8 devices using the periodic reporting approach. In addition, we identified APL commands in a third party capture file with 90.6 we highlight the trade-off between designing a low-power, low-cost wireless network and achieving privacy guarantees.

READ FULL TEXT
research
07/26/2019

PingPong: Packet-Level Signatures for Smart Home Device Events

Smart home devices are vulnerable to passive inference attacks based on ...
research
09/21/2019

IoT Inspector: Crowdsourcing Labeled Network Traffic from Smart Home Devices at Scale

The proliferation of smart home devices has created new opportunities fo...
research
03/24/2023

"Get ready for a party": Exploring smarter smart spaces with help from large language models

The right response to someone who says "get ready for a party" is deeply...
research
05/06/2020

I Always Feel Like Somebody's Sensing Me! A Framework to Detect, Identify, and Localize Clandestine Wireless Sensors

The increasing ubiquity of low-cost wireless sensors in smart homes and ...
research
01/21/2020

PDS: Deduce Elder Privacy from Smart Homes

With the development of IoT technologies in the past few years, a wide r...
research
02/25/2021

Deep Adversarial Learning on Google Home devices

Smart speakers and voice-based virtual assistants are core components fo...
research
03/20/2023

Smartphones with UWB: Evaluating the Accuracy and Reliability of UWB Ranging

More and more consumer devices implement the IEEE Ultra-Wide Band (UWB) ...

Please sign up or login with your details

Forgot password? Click here to reset