论文标题

IP摄像机上的脆弱性评估和渗透测试

Vulnerability Assessment and Penetration Testing on IP cameras

论文作者

Biondi, Pietro, Bognanni, Stefano, Bella, Giampaolo

论文摘要

IP摄像机一直是物联网(IoT)的一部分,并且是家庭和专业环境中使用最广泛的设备之一。不幸的是,IP摄像机的脆弱性吸引了恶意活动。例如,在2016年,大规模攻击导致数千台摄像机和物联网设备被破坏并用于创建僵尸网络。鉴于这些设备可以访问数据的历史以及数据的极其敏感的性质,因此自然要质疑今天采取哪些安全措施。 在本文中,在特定的IP摄像头TP-Link Tapo C200上进行了漏洞评估和渗透测试。更详细地说,我们的发现表明,有关的IP摄像机遭受了三个漏洞,例如:拒绝服务,视频窃听,最后是一种称为“ Motion Oracle”的新型攻击。实验不仅限于进攻部分,而且还为相关摄像机以及所有可能遭受相同脆弱性的相机提供对策。对策是基于使用另一个物联网设备Raspberry Pi的使用。

IP cameras have always been part of the Internet of Things (IoT) and are among the most widely used devices in both home and professional environments. Unfortunately, the vulnerabilities of IP cameras have attracted malicious activities. For example, in 2016, a massive attack resulted in thousands of cameras and IoT devices being breached and used to create a botnet. Given this history and the extremely sensitive nature of the data these devices have access to, it is natural to question what security measures are in place today. In this paper, a vulnerability assessment and penetration testing is performed on a specific model of IP camera, the TP-Link Tapo C200. More in detail, our findings show that the IP camera in question suffers from three vulnerabilities such as: denial of service, video eavesdropping and, finally, a new type of attack called "Motion Oracle". Experiments are not limited to the offensive part but also propose countermeasures for the camera in question and for all those that may suffer from the same vulnerabilities. The countermeasure is based on the use of another IoT device, a Raspberry Pi.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源