首页> 外文会议>IEEE Consumer Communications and Networking Conference >Watch and be watched: Compromising all Smart TV generations
【24h】

Watch and be watched: Compromising all Smart TV generations

机译:观看并观看:妥协所有智能电视代

获取原文

摘要

Smart TVs are slowly becoming ubiquitous in households and offices, offering an ever-growing number of features such as Internet access, media players, and built-in cameras and microphones. They are physically placed in sensitive locations and connected to trusted home and business networks. These TVs use the same operating systems and software stacks as regular PCs, leaving them vulnerable to similar software-based attacks. Even worse, security updates are provided much less frequently and stop completely after the TV has reached end-of-life. Furthermore, as these systems are closed, it is nearly impossible for end users to examine if the TV is vulnerable or if it has been compromised. This paper demonstrates that Smart TVs in their current state must not be considered trustworthy and therefore pose a severe security and privacy threat. We show that the integrated media player — a feature offered on nearly every Smart TV on the market, ranging from entry level to high end models and regardless of the vendor — is highly vulnerable. We developed a practical proof-of-concept attack using a malicious video file that gives an attacker permanent, full control over the device, yet is completely undetectable by the user. Furthermore, we provide fully functional payloads for stealthily tapping into a TV's camera and microphone.
机译:智能电视正在逐渐成为家庭和办公室无处不在,提供了一个日益增多的功能,如上网,媒体播放器,并内置摄像头和麦克风。它们物理上放置在敏感的地点并连接到可信的家庭和商业网络。这些电视使用与常规PC相同的操作系统和软件堆栈,使它们容易受到类似的基于软件的攻击。更糟糕的是,安全更新在电视达到寿命结束后,频繁频繁地提供频繁且完全停止。此外,随着这些系统关闭,最终用户几乎不可能检查电视是否易受攻击,或者如果它已被泄露。本文表明,他们当前状态的智能电视不得被认为是值得信赖的,因此构成了严重的安全和隐私威胁。我们展示了集成的媒体播放器 - 在市场上几乎每场智能电视提供的功能,从入门级到高端模型,无论供应商都有高度脆弱。我们使用一种恶意视频文件开发了一个实际的概念验证,该文件给出了攻击者永久性,完全控制设备,但用户完全无法侦测。此外,我们提供全功能有效载荷,用于悄悄地挖掘到电视的相机和麦克风。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号