Consumer Internet of Things (IoT) devices are increasingly common, from smart speakers to security cameras, in homes. Along with their benefits come potential privacy and security threats. To limit these threats a number of commercial services have become available (IoT safeguards). The safeguards claim to provide protection against IoT privacy risks and security threats. However, the effectiveness and the associated privacy risks of these safeguards remains a key open question. In this paper, we investigate the threat detection capabilities of IoT safeguards for the first time. We develop and release an approach for automated safeguards experimentation to reveal their response to common security threats and privacy risks. We perform thousands of automated experiments using popular commercial IoT safeguards when deployed in a large IoT testbed. Our results indicate not only that these devices may be ineffective in preventing risks, but also their cloud interactions and data collection operations may introduce privacy risks for the households that adopt them.
翻译:消费者物联网(IoT)设备越来越普遍,从智能音箱到安全摄像头都已经进入家庭。随着物联网的普及,潜在的隐私和安全威胁也随之增加。为了限制这些威胁,商业服务提供了大量的IoT安全保障系统。这些安全保障系统声称能够保护IoT隐私和安全威胁。然而,这些安全保障系统的有效性以及相关的隐私风险仍然是一个重要的未解决问题。在本文中,我们首次研究了IoT安全保障系统的威胁检测能力。我们开发并发布了一种自动化安全实验方法,以揭示它们对常见安全威胁和隐私风险的反应。我们在一个大型IoT测试平台上部署了几千个流行的商业IoT安全保障系统进行自动化实验。我们的结果表明,这些设备不仅可能无法有效地防止风险,而且它们的云交互和数据收集操作还可能为使用它们的家庭引入隐私风险。