· 10 years ago · Apr 11, 2016, 10:12 AM
1\documentclass[a4paper,11pt]{article} % article är en vanlig dokumenttyp
2\usepackage[utf8]{inputenc} % för att kunna läsa UTF-8-tecken (för åäö t.ex.)
3\usepackage[T1]{fontenc} % För att använda en typsnittskodning med åäö t.ex.
4%\usepackage[swedish]{babel} % För att göra avstavning m.m. på svenska
5\usepackage[numbers,sort&compress]{natbib} % Ger snyggare referenser
6\usepackage{xspace} % Till slutet av kommandon som kan följas av mellanrum
7\usepackage{graphicx}
8\usepackage{epstopdf}
9
10\usepackage{pgfplots}
11\pgfplotsset{compat=1.9}
12 \usetikzlibrary{patterns}
13
14%\usepackage{glossaries}
15\usepackage[xindy]{glossaries}
16%\makeglossary
17%\usepackage{glossaries}
18\makenoidxglossaries
19\renewcommand{\glstextformat}[1]{\textit{#1}}
20
21
22%Simons saker
23\usepackage{color}
24\usepackage[showframe=false]{geometry}
25\usepackage{changepage}
26\usepackage{xcolor,colortbl}
27\usepackage{graphicx}
28\usepackage{float}
29
30%fix list lettering
31\usepackage{enumerate}
32
33%appendix
34\usepackage[toc,page]{appendix}
35
36%Keywords
37\providecommand{\keywords}[1]{\textbf{\textit{Keywords---}} #1}
38
39\newglossaryentry{smartHome}
40{
41 name={Smart home},
42 description={A Smart home is a home that takes advantage of automation technologies, to provide an increasing comfort for the residents. The home automation technologies are electrical devices that are able to communicate and send data. You can control the devices or let them perform tasks on their own}
43}
44\newglossaryentry{iot}
45{
46 name={Internet of Things (IoT)},
47 description={The Internet of Things is a term used for a development of a network consisting of objects which are embedded with electronics, software, sensors and network connectivity that enables these objects to collect and exchange data}
48}
49\newglossaryentry{openHab}
50{
51 name={OpenHab},
52 description={OpenHab is a open source automation software designed to control your smart home}
53}
54\newglossaryentry{archLinux}
55{
56 name={Arch Linux},
57 description={Arch Linux is a Linux distribution predominantly of free and open-source software}
58}
59\newglossaryentry{pi}
60{
61 name={Raspberry pi},
62 description={Raspberry Pi is a credit card–sized single-board computer}
63}
64\newglossaryentry{Wireshark}
65{
66 name={Wireshark},
67 description={Wireshark is a network analysis tool that lets the user analyse each package individually}
68}
69\newglossaryentry{gateway}
70{
71 name={Home Gateway/Hub},
72 description={The term gateway often means a device on a network that acts as a central point and or a relay to another network and often used to translate between different communications protocols, data formats, etc}
73}
74\newglossaryentry{malware}
75{
76 name={Malware},
77 description={Malware is any software that is developed for the purpose of doing harm to computers or via computers. The main types of malware include worms, viruses, trojans, backdoors, spyware, rootkits and spam }
78}
79\newglossaryentry{cryptography}
80{
81 name={Cryptography},
82 description={Cryptography refers to constructing unreadable data to prevent third parties or the public to be able to read private data. Information security aspects such as confidentiality, data integrity, authentication, and non-repudiation are central to modern cryptography}
83}
84\newglossaryentry{hash}
85{
86 name={Hash},
87 description={A hash function is used to map data of arbitrary size to data of fixed size, this means that readable data will be unreadable without knowing the stored hash value. This allows the communication of cryptographic messages}
88}
89\newglossaryentry{encryption}
90{
91 name={Encryption},
92 description={In cryptography, encryption is the process of encoding messages or information in such a way that only authorized parties can read it}
93}
94\newglossaryentry{mitma}
95{
96 name={Man-in-the-middle attack (MitMA)},
97 description={Man-in-the-middle attack is an attack where the attacker secretly relays and possibly alters the communication}
98}
99\newglossaryentry{sniffing}
100{
101 name={Sniffing},
102 description={Intercepting network communication to be able to analyse the packages with commonly a computer software}
103}
104\newglossaryentry{nat}
105{
106 name={Network address translation (NAT)
107 },
108 description={Network address translation “NAT†is a method used for remapping one IP address space into another by modifying network address information in Internet Protocol datagram packet headers while they are in transit across a traffic routing device}
109}
110\newglossaryentry{wap}
111{
112 name={Wireless Access point (WAP)},
113 description={A wireless access point “WAP†is in a networking hardware device that allows a Wi-Fi compatible device to connect to a wired network}
114}
115\newglossaryentry{hacker}
116{
117 name={Hacker},
118 description={In computing, hacker is a term which refers to a skilled computer enthusiast. Depending on the field of computing it has slightly different meanings, and in some contexts has controversial moral and ethical connotations}
119}
120\newglossaryentry{backdoor}
121{
122 name={Backdoor},
123 description={ A backdoor is a method used to bypass normal authentication of a product, computer system, etc}
124}
125\newglossaryentry{ ubicomp }
126{
127 name={ Ubiquitous Computing (ubicomp)
128 },
129 description={ The idea to integrating computers anywhere to be able to use a single user interface throughout the whole environment}
130}
131\newglossaryentry{ padding }
132{
133 name={ Padding-oracle attack
134 },
135 description={ An attack conducted by altering the padding inside a cryptographic message. The padding is needed to make the cryptography compatible with the cryptographic algorithm used to build cryptographic protocols}
136}
137\newglossaryentry{cots}
138{
139 name={ Commercial off-the-shelf (COTS)
140 },
141 description={Commercial off-the-shelf “COTS†means that the product is a standard manufactured product rather than a customized version of the product}
142}
143
144
145%
146% Do not change
147\textheight = 220mm
148\textwidth = 150mm
149\topmargin = 10mm
150\oddsidemargin = 5.0mm
151\evensidemargin = 5.0mm
152\unitlength = 1mm
153\setcounter{secnumdepth}{5}
154
155\begin{document}
156%
157% Do not change
158\let\rempage=\thepage
159{
160 \renewcommand{\thepage}{\relax}
161 \begin{picture}(33,0)(15,10)%
162 \special{psfile=mahlogo-name.eps}%
163 \end{picture}%
164
165 \begin{figure}[!htb]
166 \includegraphics{mahlogo-name.eps}
167 \label{fig:digraph}
168 \end{figure}
169
170 \vspace*{-50mm}
171 \hfill\begin{minipage}[t]{16em}\large
172 Fakulteten för teknik och samhälle\\
173 Datavetenskap
174 \end{minipage}
175
176 \vspace*{45mm}
177 \begin{center}
178 {\bf\large
179 Examensarbete
180
181 \small
182 15 högskolepoäng, grundnivå
183 }
184
185 \vspace*{25mm}
186 \LARGE
187 %
188 % Put your title here
189 Evaluating privacy and security risks in smart home entertainment appliances, from a communication perspective
190
191
192 \vspace*{8mm}
193 \large
194 %
195 % Translated title
196
197 Utvärdera integritet och säkerhetsrisker i smarta underhållningsapparater, ur ett kommunikationsperspektiv
198
199 \vspace*{12mm}
200 \Large
201 %
202 % Author names
203 Irengård Gullstrand, Simon
204 \\
205 Morales Larsson, Ivan
206 \\
207
208 \vspace*{30mm}
209 \large
210 %
211 % Picture if you want
212 %Eventuell bild
213 \end{center}
214
215 \vfill
216 \hspace*{-10mm}%
217 \begin{minipage}[t]{20em}
218 %
219 % Fill in correct data for you
220 Examen: Kandidatexamen 180~hp
221 \\
222 Huvudområde: Datavetenskap
223 \\
224 Program: Datavetenskap och \\ applikationsutveckling
225 \\
226 Datum för slutseminarium: 2016-05-30
227 \end{minipage}
228 %
229 \hfill
230 %
231 \begin{minipage}[t]{15em}
232 %
233 % Fill in supervisor and second reader
234 Handledare: Joseph Bugeja
235 \\
236 Bihandledare: Andreas Jacobsson
237 \\
238 \\
239 Andrabedömare:\\
240 Dimitris Paraschakis
241 \end{minipage}
242
243\newpage
244
245\mbox{}
246
247\newpage
248
249
250\section*{Abstract}
251The concept of smart home technology becomes more and more a part of our everyday life. Because of the hasty evolution and considering that wireless communication has become the norm, the security and privacy problems have become more of a concern. The purpose of this work is to examine what kind of information can be extracted from an entertainment-based smart home involving an off-the-shelf game-console, Playstation, connected to the Internet. This scenario has been investigated with experiments focusing on the interception of networking traffic occurring when using such a device under everyday operations. The results of the study shows that sensitive data such as images is infact possible to extract.
252\\ \\
253\keywords{security, privacy, internet, smart home, playstation, wireshark, wireless communication, entertainment}
254
255\newpage
256
257\mbox{}
258
259\newpage
260
261
262\section*{Sammanfattning}
263Konceptet smarta hem blir mer och mer en del av vår vardag. På grund av den hastiga utvecklingen och med tanke på att trådlös kommunikation har blivit normen, har säkerhet och integritet blivit mer av ett bekymmer. Syftet med detta arbete är att undersöka vilken typ av information som kan utvinnas ur en underhållning-baserat smart hem med inriktning på en off-the-shelf spel-konsol, Playstation, ansluten till Internet. Detta scenario har undersökts med ett experiment som fokuserar på avlyssning av nätverkstrafik som inträffar vid användning av en sådan enhet i det dagliga livet. Resultet av studien visar att känslig data såsom bilder är i själva verket möjligt att utvinna från nätverks kommunikationen.
264
265
266\newpage
267
268\mbox{}
269
270\newpage
271
272\mbox{}
273
274\section*{Acknowledgements}
275
276\thispagestyle{empty}
277
278We wish to thank fellow students Andreas Stridh from Computer Engineering and Mobile Sensing Systems and Dina Eid Musalam from Master in Computer Science program, both from Malmö University, Sweden. They have used and commented upon much of the material in this thesis, and helped us refine it. We also want to thank Joseph Bugeja, Doctoral researcher, part of the Internet of Things and People Research Centre, Malmö University, for suggestions, advice and lively discussions about the nature of research in Information Security and computing. Finally we must thank Andreas Jacobsson, Vice Dean at the Faculty of Technology and Society, Head of Intelligent Support for Privacy Management in Smart Homes – iSMASH project, which is a project at Internet of Things and People Research Centre, at Malmö University, for the help and support as well as the opportunity to be part of the research in the smart home security and privacy field at Malmö University.
279
280
281\clearpage
282
283\newpage
284\printnoidxglossary[nonumberlist]
285\newpage
286\tableofcontents
287\newpage
288\ifodd\value{page}\else\mbox{}\newpage\fi
289\setcounter{page}{1}
290\renewcommand{\thepage}{\rempage}
291%
292
293
294%\printglossaries
295
296
297\section{Introduction}
298
299In recent years, the industrial interest in smart home appliance and enhanced automation features of the home has increased significant~\cite{pastPresentFuture}. We are at a point where we can almost control anything in our houses remotely with great ease. Forecasts estimate a global increase in units sold at an average annual growth rate of 67\%, from around 400 million units in 2014 to 1.8 billion units in 2019~\cite{ForecastsGrowth}. This increased interest in smart appliances has created an increased need for research in this area~\cite{pastPresentFuture}.
300
301
302The vision of \gls{ ubicomp } smart home environments aims to integrate all individual devices to the smart home and control them all though one interface~\cite{DirectionsForHomeAutomationResearch,ChallengesAndOpportunities}. Fulfilling this vision is where the majority of the research within the field is focused~\cite{SakerhetsutvarderingSmartaDorrlas}. While the technology to satisfy the customers is developing, problems with the security and maintainability arises~\cite{DirectionsForHomeAutomationResearch}. This problem is exacerbated when the wireless medium between the home utilities in the smart homes is used. The view of accepting the smart home concept lays in the complication to create a satisfyingly secure smart home for the end user. Studies with focus on social barriers within smart homes~\cite{ChallengesAndOpportunities, SocialBarriers}, presents problems that has to be addressed before the smart home concept is fully accepted. One of the problems is that users generally appreciates the idea of a remote accessible home, where for example cameras and temperature can easily be adjusted. More than half of the respondents experience that this kind of convenience makes the smart home more vulnerable to outside attacks~\cite{ChallengesAndOpportunities}. According to a study about State of the Smart Home~\cite{SmartHomeReport} they found that consumers are most eager to connect their entertainment room to their smart home illustrated in Figure. \ref{fig:graph}, when comparing which of all of the rooms in the house that was most relevant for individuals, regarding the purpose of connecting to a smart home. In this study it was also found that entertainment has emerged as a new and powerful driver to smart home adoption. One of the major reasons to why consumers wanted to purchase a smart home system was that they were able to remotely control and/or monitor the TV and sound systems. This was based on the nearly 45\% of the respondents in the study who found this function to be the most important. Additionally the results showed that the interest in entertainment had increased since the previous year where only 29\% listed this as a top benefit of a smart home~\cite{SmartHomeReport}. Also the Playstation usage has increased, since it is the perfect device to have as a central entertainment device in the entertainment room. Because it can perform almost any task commonly needed in an entertainment room~\cite{playstationRev}. With this kind of upturn in interest of entertainment devices the security and privacy has to keep up with the development. Conceptually a smart home consists of technology that is supposed to raise residents' peace of mind and security~\cite{SocialBarriers}. But by letting the system know more and more about us, we also open up ourselves to being easier exposed. This might bring major security and privacy concerns to the owner of the smart home. These surfaced problems should not exist and be of no concern to the end user. Where in that case the system should be designed in a way so that it is easily managed and as automated as possible~\cite{TrustBasedSecurity}.
303
304 \begin{figure}[ht!]
305 \centering
306 \includegraphics[width=180mm]{barGraphSmartHome.png}
307 \caption{Most desired connected area \label{fig:graph}}
308 \end{figure}
309 \newpage
310 \subsection{Purpose}
311The purpose of this study is to discover potential data leakages in a typical Smart Home setup occurring through the network communication channels. This work will help us to understand and answer questions such as, can we really trust a smart home appliance to store and use confidential data about us in a secure and private way?
312
313 \subsection{Enclosure}
314 To narrow down the study we decided from a security and privacy perspective to focus on the Smart home entertainment category. For the purpose of answering the research questions existing technologies will be investigated. For the practical part of the study to be feasible, experiments will be limited to one of the many smart home devices in the entertainment category available on the market today. The study will also be limited to investigate security flaws in the network communication, specifically between the Smart \gls{gateway} and the Internet. The entertainment appliances of today are communicating all sorts of confidential data about us, like payment information, purchase history as well as information from social media outlets such as Facebook, Twitter and Youtube. By examining different ways of interacting with the device we were able to conclude if there were any common data sets that are being shared to and from the gateway. Hopefully leading to improvements in the security and privacy fields of Smart homes. This study also serves as a preliminary to a larger research project in the field of smart home called the Internet of Things and People conducted at Malmö University.
315
316\subsection{Problem discussion}
317Based on the discussion above and the statistics as shown in Figure. \ref{fig:graph} it can be argued that the Playstation 4 is a good candidate to investigate further. Considering that the Smart home entertainment area of the house is such a central point in the home and therefore a very important candidate for security and privacy. Deficiencies in the security, specifically regarding entertainment devices generate risks both in terms of credit card theft and also privacy. It is reasonable to assume that the user will expect the highest level of security in the most relaxed section of the house~\cite{SocialBarriers}. The lack of trust in the security of smart home technology, described in the thesis introduction, manifests itself in the form of the slow transition that has been taken place during the last decade. Also a 2015 research results in that more than half of the respondents experience that convenience like remote access to the smart home devices makes the smart home more vulnerable to outside attacks~\cite{ChallengesAndOpportunities}. The lack of trust indicates a potential for further research in the field to evaluate the safety of smart home entertainment devices and whether the concerns over these are justified.
318
319
320\subsection{Research questions}
321Based on the problem discussion the following research questions were raised:
322
323\begin{enumerate}
324 {\itshape\item Are there data leakages that are of a security or privacy concern in a \gls{cots} smart home entertainment appliance? }
325
326 {\itshape\item Can such data be intercepted and used to identify users and their environment? }
327\end{enumerate}
328
329\subsection{Hypothesis}
330Recent research oriented in the smart home field~\cite{SmartHomeArchitecture,SakerhetsutvarderingSmartaDorrlas,RefrigeratorHacked} involve similar scenarios as this paper. They are demonstrating for example how it is possible to infiltrate and take control over a smart home device as well as intercept and extract data in clear text. Based on the problems raised in the problem discussion we believe this kind of studies are of high interest and therefore want to study this topic further. A directed hypothesis was chosen based on our first prediction, concerning research question 1, which is that we think based on similar studies~\cite{SakerhetsutvarderingSmartaDorrlas,RefrigeratorHacked} that we will find data leakages within the communication between the chosen smart home entertainment device and the Internet. To suggest that data is secure we expect that the transmission of all and especially confidential data such as passwords or credit card numbers are hashed and/or encrypted. What we expect to find within the data is that there are actually some confidential data that we are able to exploit.
331
332This thesis is organized as follows. Chapter two provides background information and key concepts, chapter three will describe our methodology where we describe in detail how our experiment were conducted, chapter four and five will present, discuss and analyze the gathered data from the experiment. Finally, chapter six will be the conclusions of the study.
333
334
335\newpage
336\section{Background}
337This chapter provides background information and key concepts that are used in this thesis such as smart home, Internet of things, recent exploits, privacy and security. It presents and discusses theories and ideas that we have found relevant to understanding the problem domain.
338\subsection{Smart Homes}
339 A Smart home is a home that takes advantage of automation technologies, to provide an increasing comfort for the residents. The home automation technologies are electrical devices that are able to process and exchange data. You can control the devices or let them perform tasks on their own.
340 To understand what home automation is, we have to break down the concept as shown in Figure. \ref{fig:pyramid}. First up is “House Infrastructureâ€, this is a centralized control of a building’s for example heating, lighting, water, ventilation and air conditioning. The goal of this kind of system is to improve comfort, reduce energy consumption and operating costs. Also, by automatically turning off utilities improve their life span.
341
342 \begin{figure}[ht!]
343 \centering
344 \includegraphics[width=80mm]{smarthomeBuildingBlocks.png}
345 \caption{Smart home centralized architecture \label{fig:pyramid}}
346 \end{figure}
347
348Second part is “Appliancesâ€, security locks of doors and gates etc. These kind of systems are what we call \gls{iot} devices, more details in Section 2.2. For example there are specially adapted systems to provide the specific help elderly and disabled people need that otherwise would require a caregiver or institutional care~\cite{TechAwareHome,HealthcareServicesElderlyPeople}. You can automate tasks like yard watering, pet feeding and control of domestic robots. The systems are integrated for easy living, convenience, increased comfort, security and safety, energy efficiency and as well as automation of simple tasks that are performed multiple times~\cite{TechAwareHome}. The home automation devices may be connected to a \gls{gateway} which may be connected to a Local Area Network. This would allow you to control and program the systems from a personal computer, tablet and smartphone, and may allow remote access from the Internet.
349
350
351You can integrate sensors, biomedical monitors and cameras to the system in your home that will collect data about your behaviors and patterns~\cite{TechAwareHome}. This data can be stored locally and/or in a Cloud storage. Systems can use the data to ensure the greatest comfort and advantages possible for you. Example of benefit, if the system recognizes that you are not home it can turn off the water, all the lights and also perform checks on different other utilities in your home like a stove or an oven and turn them off automatically as well. While you’re at home, it is able to perform different kind of tasks; one example is if you leave or enter a room the light goes off/on automatically. If you choose to install speakers in every room, the music you are currently listening to is also able to follow you throughout the house. If you start cooking the potentially dimmed light goes to 100\% ~\cite{HomeAutomationWild,TechAwareHome}.
352
353\subsubsection{Types of smart homes}
354The list of differents types of smart homes is open-ended and is only being limited by the human imagination. But as it stands today there are four major categories of which a smart home can be identified as~\cite{AnOverviewSmartHomeEnvironments}, they are as follows:
355
356\begin{itemize}
357 \item Home care/Elderly care
358 \item Energy Efficiency
359 \item Entertainment
360 \item Security and Safety
361\end{itemize}
362
363
364The listed categories are not always necessarily disjoint, an example of this is that Security and Safety can be related with Home care/Elderly care. Additionally, functions belonging to one or more different application types can be found within the same category. Finally, these applications can share approaches. For example, applications related to eldercare and safety very often use the same methods for video surveillance~\cite{VisionSurveillanceTechniques}.
365
366\paragraph{Home care/Elderly care}
367The main purpose of the technology created for this category is to help people in need, people that are disabled and can not help them self. Also elderly people who are in a constant need for help and attention. This type of smart home is part of a more general interest for developing new smart home technologies for addressing the problems of the elders related to health, loneliness, disability, cognitive limitation, etc. Two main subcategories were identified within the category of Home care and Elderly~\cite{Angelah}:
368
369\begin{enumerate}
370 \item Assistance at any given time that focuses on assisting elders during their daily activities, as well as addressing their disabilities and cognitive limitations.
371 \item Ubiquitous care that addresses elders’ social limitations by providing them with services and facilities for social inclusion with purpose of reducing their sense of loneliness.
372\end{enumerate}
373
374\paragraph{Energy Efficiency}
375Reduction of energy consumption is a very important development within technology for the modern society with a major impact on future development of the mankind~\cite{AnOverviewSmartHomeEnvironments}. On the one hand the technology progress requires the use of more energy, while on the other hand energy is on the verge of becoming a limited resource. Therefore there are smart devices and appliances, that can control energy savings. For example switching off or to set low-power mode on the appliances currently not in use or according to the user preference settings, that can be implemented to a home in order to reduce the inevitable energy consumption, and through that save both energy and money.
376
377\paragraph{Entertainment}
378A category that address users comfort and entertainment. Typical examples are ambience control (for example lighting and background music), advanced user interfaces used to control devices (for example based on voice or gestures), automation of routine activities, etc. And it is within this category our work will focus on.
379
380\paragraph{Security and safety}
381Safety refers to the detection of unusual situations inside the smart home~\cite{AnOverviewSmartHomeEnvironments}, like for example fires, floods, accidents even possible falls of disabled or the elderly. Security refers to the detection of malicious behaviors that might harm the home or the residents, like for example burglars, unauthorized access, and others. For the detection, signalling and response to such safety or security violation situations, the smart home are equipped with sub-systems for video surveillance, remote monitoring, alarming, and emergency response.
382
383\subsubsection{Architecture}
384
385A traditional smart home is often implemented using a centralized architecture by reason of that it is the most popular architecture, also easier to manage and has better security~\cite{NetworkTopology}. A general build for centralized architecture is shown in Figure. \ref{fig:house}. The home appliances are connected to the homes local network and controlled by the home gateway, which is the platform for service providers to provide services to residents~\cite{SmartHomeArchitecture}. The way it works is that the different smart devices, such as smart thermostats and smart refrigerators or in our case entertainment devices like a smart tv or gaming consoles to be communicating with the home gateway. In turn the gateway directs all traffic to and from the Internet as shown in Figure. \ref{fig:house}. The person shown in Figure. \ref{fig:house}, represents a smart home user and is able to through the Internet and then through the home gateway, control and communicate with the devices in the smart home. This can all be done with the designated android or IOS application.
386
387\begin{figure}[ht!]
388 \centering
389 \includegraphics[width=90mm]{Centralazied.png}
390 \caption{Centralized architecture \label{fig:house}}
391\end{figure}
392
393Another solution for a smart home architecture is the Distributed Architecture. It is a topology where all peers communicate symmetrically, have equal roles and collaborates together on a certain task. Each device in the network has the ability to communicate with or through any other device as seen in Figure. \ref{fig:nodes}.
394
395\begin{figure}[ht!]
396 \centering
397 \includegraphics[width=50mm]{Decentralized.png}
398 \caption{Decentralized architecture \label{fig:nodes}}
399\end{figure}
400
401\subsection{Internet of Things}
402The Internet of things or “IoT†for short is a term for a development of a network with physical objects that consist of but is not limited to, devices, vehicles, buildings, appliances, clothes and even creatures (including humans). Which are embedded with electronics, software, sensors and network connectivity that enables these objects to collect and exchange data. These can observe their environment, communicate with it, and thus create a specific behaviour and help create smart, helpful environments, products and services. There are many big fields where The Internet of Things can be applied to such as the field of media. The media industry appears to be moving away from the traditional approach such as newspapers, magazines, or television shows and instead distribute their content through personalized technology. That way the person who is using the device will decide what content (articles) and advertisements that appeals to him. Another field is environmental monitoring where Internet of Things applications can use sensors to monitor air or water quality, atmospheric or soil conditions, and can even include areas like monitoring the movements of wildlife and their habitats. Medical and healthcare is also a field that can greatly benefit from Internet of Things applications, such applications could be remote health monitoring and emergency notification systems~\cite{TechAwareHome,HealthcareServicesElderlyPeople}.
403
404\subsection{Security and Privacy}
405Cyber criminals are identified as a raising hostile threat category. With increasing number of smart devices and homes connected to the Internet, there is a high potential abuse of smart homes. Therefore the priority of security should be considered more important. Furthermore, several economic factors generate security vulnerabilities, based on that design choices are competing against cost and convenience. Not all smart homes are created equally due to multiple design strategies which result in their own security and privacy solutions. Just as in many other areas of Internet connected things, applying basic information security can significantly increase overall security in the smart home~\cite{SmartHomesSecuritySmart}.
406
407
408Computer security in a communication network depends not only on the security investment made by individual users, but also on the correlation between them. If a user puts in little effort in protecting its computer system, then it is easy for viruses to infect this computer and through it continue to infect others’. On the contrary, if another user invests more effort to protect itself and its computer system, then other users will also gain a benefit because the chance of \gls{malware} spreading is reduced~\cite{SelfishInvestments}. Besides user preferences, the network topology, which describes the relationship among different users, is also important. For example, assume that in a local network, user A is directly connected to the Internet. All other users are connected to A and exchange a large amount of traffic with A. The security level of A is important for the local network since A has the largest influence on other users. That means if A has low security then whole network might suffer.
409
410
411There have been many definitions of privacy over the years. One of the early definitions of privacy was forwarded by Louis Brandeis and Samuel Warren in a Harvard Law Review article~\cite{RightOfPrivacy}. They tried to explain how the right to privacy was different from legal rights. They believed in the “…right to be let aloneâ€~\cite{RightOfPrivacy}. In a more recent journal~\cite{privacyLimitsLaw}, the author defines privacy as â€the limitation of other people’s access to individualsâ€. Her definition has three points: secrecy, anonymity, and solitude. Spinello states that “Anonymity is protection from undesired attention; solitude is the lack of physical proximity to others; and secrecy (or confidentiality) involves limiting the dissemination of knowledge about oneselfâ€~\cite{spinello2010cyberethics,PrivacyEthicalConcerns}. When security becomes an increasing concern privacy and ethical aspects is not to forget. We live in a society with access to all types of information. Leading to privacy growing more important, how much personal information should we really teach the system at hand about us, to be able to grant the promised benefits? It is a hard question and still we’re forced to answer this question everyday.
412
413
414But what information is regarded confidential? Any information that someone can use to identify an individual constitutes personal data. For example, a list of usernames and email addresses will count as personal data~\cite{PersonalData}. Geographical location is one of the most sensitive data types currently able to be collected. A recent MIT study~\cite{de2013unique,presentAnonymityRisk} by de Montjoye et al. showed that four spatio-temporal points, approximate locations and times, are enough to identify 95\% of 1.5M people uniquely in a mobility database. Further the study presents that these constraints hold even when the resolution of the dataset is low. This results in that, even coarse or blurred datasets provide poor anonymity~\cite{Countermeasures}.
415
416
417Time and date are another data type that is of a sensitive nature from a privacy and security perspective. When a file is timestamped, a unique identifier, for the file is created by the computer. This identifier is a unique number calculated from the file's contents~\cite{digitalTimestamp}. By altering this information interesting things can happen. One example of this is a recently found bug in the iOS 5 operating system where by changing the date to some point in the past, the \gls{hacker} were able to view previously taken images without unlocking the Iphone~\cite{TimeStampBug}. Additionally images are also a privacy concern out of initially a user identification perspective. Pictures about us is not very pleasant to be shared around the Internet without our acknowledgement or even worse, being used for blackmailing. Still there are countless hacks where this type of behavior has happened~\cite{PixStealTrojan}. Also an image contains privacy and security related data, for example date it was created, geographical location of the device when the image was taken or created, and sometimes even information about the device it is stored on. One way of ensuring that the data is more secure is to use an \gls{encryption} protocol when communicating sensitive data. A problem is that it is still hackable if an older version of the protocol is used~\cite{Migrating}. Since the release of SSL (secure socket layer) v3.0, several vulnerabilities have been discovered. One example is the “POODLE†issue where cleartext data were extracted by conducting a padding-oracle attack on the communication~\cite{CyberAwareness}. The solution for this issue is to restrict the usage of secure protocols to only the latest version, which at the time of publication is TLS v1.2~\cite{Migrating}.
418
419\subsection{Examples of recent exploits}
420This section describes a few recent smart home exploits. A hacker, if successful, can study smart device wireless communication to identify residents locations in a home, unlock doors, disable sensors and alarms for further infiltration~\cite{SmartHomeInvasion}. In brief, the security of Smart appliances is very important to withhold the privacy of the residents.
421\\
422\\
423Two practical attacks has been conducting in a laboratory environment against ZigBee Smart home security~\cite{VidgrenSecurity}. The first attack is based on sabotaging the ZigBee EndDevice by sending a special signal that makes it wake-up constantly until the battery runs out. The second attack is based on exploiting the key exchange process in ZigBee when using the Standard Security level defined by the ZigBee specification~\cite{StandardsDevelopment,VidgrenSecurity}. Which would possibly mean that the hacker could take control of the smart home devices.
424\\
425\\
426The Nest Thermostat is a smart home automation device that aims to learn a user’s heating and cooling habits to help optimize scheduling and power usage. This system was exploited through a connected USB device, which bypassed where the firmware verification is done by the Nest software stack, providing the means to completely alter the behavior of the unit. The compromised Nest Thermostat then acted as a \gls{backdoor} to attack other nodes within the local network. Also, any information stored within the unit is now available to the attacker wirelessly~\cite{hernandez2014smart}.
427\\
428\\
429Security firm Proofpoint report 2014, that hackers are attacking "smart" appliances in your household. The firm looked into attacks that occurred between Dec. 23 and Jan. 6, and found that more than 25 percent of spam email was sent by home-networking routers, connected multimedia centers, televisions and at least one refrigerator~\cite{hackRefig}.
430\\
431\\
432Vulnerabilities were found in a mobile app developed by Samsung to wirelessly control the refrigerator. Where hackers figured out that they were able to conduct man-in-the-middle attack to gain access to the Gmail login credentials, if they had an access to the same Wifi network as the Samsung refrigerator where connected to. This leads to access to for example shopping habits and other stored confidential data in the google account as as the data stored in the refrigerator~\cite{RefrigeratorHacked}.
433
434
435\subsection{Related work}
436The authors of~\cite{OvercomingInvasion} performed a study about traffic analysis of SmartThings devices to demonstrate that a hacker might perhaps identify obvious traffic pattern of smart home products~\cite{OvercomingInvasion} [22]. In their study, the authors had built a SmartThings system consisting of a SmartSense Open/Closed sensor - a door sensor, a SmartSense Motion sensor, and a GE Link - a SmartThings-compatible LED bulb, all of which are connected to the SmartThings cloud server through a SmartThings Hub and a router. In order to capture all of the packets between the SmartThings Hub and the cloud server, the authors connected a computer running Ubuntu as a bridge between the router and the home gateway. This allowed the gateway to obtain an IP address and connect to the Internet while we could monitor the network traffic before it was forwarded to the router. This is also called to conduct a \gls{mitma}. The tool \gls{Wireshark} was used to capture all of the Ethernet network traffic to observe communications taking place on the network between the gateway and the SmartThings server. In their study the authors discovered privacy vulnerabilities in the smart home environment~\cite{OvercomingInvasion} and that the use of a Virtual Private Network (VPN) is desired to prevent packet captures. This can prevent a hacker from directly monitoring the traffic between the home gateway and associated smart home server.
437
438
439Another study was about network behavior within the smart home on selected smart devices were performed in a study by Notra~\cite{EmergingHousehold} to examine if the implementation of encryption, authentication and privacy solutions are acceptable and secure or may contain vulnerabilities. The smart devices for the experiment consists of a lightbulb, a light-switch and a smoke detector detector that are directly connected to the Internet and a mobile application that can control these devices, according to the authors these devices are the most frequently bought and distributed devices that are considered to be IoT devices. The investigation of the devices individual communication was performed in a controlled lab environment where the network activity was intercepted by using Wireshark software tool. The results varied between devices and for example the testing of the smoke detectors smart features include motion, light and heat sensors did not show any direct weaknesses, but all communication was encrypted. The authors~\cite{EmergingHousehold} found that some packets are of a larger size and the risk of sensitive data to be logged and collected do exists. The lightbulb, lacks encryption and communicates in cleartext over the network. Only the username is hidden, but in the form of a \gls{cryptography} \gls{hash}. This means that a person who observes the network communication can extract data containing for example the location of the residents. According to the authors~\cite{EmergingHousehold} vulnerabilities of this specific type of light-bulb was already demonstrated by the manufacturers in the past, and they have taken measures on how to communicate the username safer. The text however, at the time of the study (2014) was still shown in cleartext. Testing of the light-switch demonstrates several security flaws when it comes to communication, for example content is communicated in cleartext and lack of authentication between devices. This means that an interceptor can access sensitive data related to the status of the home and also could take control of connected devices.
440
441
442One study performed by a couple of students from Malmö högskola evaluated security of a smart door lock from a communication perspective~\cite{SakerhetsutvarderingSmartaDorrlas}. Their study were consisted of practical experiments on a smart home lock that existed on the market at the time their study were conducted. The lock was examinated by intercepting and collecting quantitative data of the radio based communication that transpire between the smart home lock and the centralized home gateway. After the interception the collected data was analysed with the help of a pattern recognition algorithm and finally analyzed manually with Wireshark in order to find common features in the data that formed some sort of system information~\cite{SakerhetsutvarderingSmartaDorrlas}. Their study showed that it is possible for outsiders to extract information from the smart locks’ communication. Approximately 70\% of the door communication is encrypted with what seems to be the AES-128 and these messages are real payload and they may not be recover within a reasonable time. The information that can be extracted is metadata containing the communication in the form of message length (number of packets per message), package types and the length of the data in packets. This information can be used to categorize the interaction with the door in six different categories: interaction from a distance, closing the door, unlocking with a cipher code or key card, opening the door, locking via physical button and input of incorrect cipher code.
443
444
445\section{Methodology}
446This chapter is aimed to describe the research approach undertaken for this thesis. According to Carolyn B~\cite{QualitativeMethods}, “Qualitative data are data represented as words and pictures, not numbersâ€. Qualitative study was chosen to investigate the security in a smart home and to answer the research questions which is about finding out if there are any data leakages and if it is possible to intercept and identify users and their environment. The choice to perform experiments on an entertainment device through intercepting the communication is based on methodologies in similar studies~\cite{SakerhetsutvarderingSmartaDorrlas,EmergingHousehold}. These methodologies is about intercepting communication in a controlled environment, followed by analysing packets with filters (only displaying relevant packets for our study) and/or scripts to recognize important data. We conducted our experiments based on the way these similar experiments were conducted.
447
448\subsection{Metod of choice}
449The chosen method for this study is a practical experiment due to the need for setting up a research environment as close to a real life scenario as possible and because the study is focused on how the Playstation 4 behave in reality and not in simulation. To be able to answer the research questions and to evaluate the security and privacy concerns the study have to be conducted as a practical experiment with real devices. We also believe this approach could deliver unpredictable and interesting outcomes on top of the expected results described in the hypothesis section.
450
451\subsection{Experimental setup environment}
452In order for the experiment to be conducted a setup environment was constructed. The construction as seen in Figure. \ref{oursetup} is a replica and a miniature version of the setup shown in Figure. \ref{fig:house}. Also both hardware and software components are needed. The hardware includes a laptop, a Playstation and a WiFi USB Adapter. The laptop functions as a home gateway (or hub), the Playstation is the entertainment device being analyzed, and the WiFi USB Adapter -is responsible for channeling the communication between the laptop and the Playstation. The software include Wireshark and the script. Wireshark is used to intercept communication and a script, Create\_AP see Appendix \ref{bilaga:createAp} - to create a \gls{nat} software access point.
453% LINK TO GLOSSARY LIST: NATed , wireshark? ,
454\begin{figure}[H]
455 \begin{center}
456 \makebox[\linewidth]{ % to center the image
457 \includegraphics[width=110mm, height=50mm]{Our_SetUp.png}
458 }
459 \caption{ Illustration of our setup. }
460 \label{oursetup}
461 \end{center}
462\end{figure}
463
464\subsubsection{Hardware}
465
466\paragraph{Laptop}
467The laptop that was used during the experiment was Lenovo Yoga 2 Pro running Arch Linux 4.4.1-2 as the operating system. The purpose of the laptop during the experiment was for it to work as the home gateway and to also monitor and log the network communication with Wireshark.
468
469\paragraph{WiFi USB adapter}
470The WiFi USB Adapter that was used in the experiment is called TP-LINK TL-WN722N. It was chosen since it is highly recommended and used within the linux and network administration community. This means there is a lot of documentation.
471
472\paragraph{The Smart home entertainment device}
473As for the smart device an existing smart entertainment device which currently exist on the market during execution of this study was chosen, in our case that would be a Playstation 4. The main purpose for the Playstaion 4 is for it to work as the smart device for the experiment. The Playstation in question is a regular stock product that has not gone through any modifications but it has been in use for approximately thirteen months. The reason for why a used Playstation 4 were used in the experiment was on account of that we wanted the experiment to be as close to a real scenario as possible to simulate what is communicated in a real smart home.
474
475\subsubsection{Software}
476\paragraph{Create\_Ap}
477To make the laptop act like a home gateway we used the script Create\_Ap~\cite{gitHub}. The script was recommended on the Arch networking section of the forum. It consists of the commands used to create a access point on linux. More about Create\_Ap consult Appendix \ref{bilaga:createAp}.
478
479\paragraph{Wireshark}
480Wireshark version 2.0.1 with libpcap version 1.7.4. Built using gcc 5.3.0 was used in the experiment to intercept, log and analyse the network communication.
481
482A similar tool considered for the experiment was TCPdump which is a Linux based terminal software. Wireshark was chosen based on what previous researchers used in previous similar studies~\cite{SakerhetsutvarderingSmartaDorrlas,EmergingHousehold}. Wireshark is a free and open-source packet analyzer, it is widely used and recommended for network troubleshooting, analysis, software and communications protocol development, and education.
483% REFERENCE 26, 45
484
485\subsection{Experimental task}
486Before the experiment was conducted we started with identifying the most common activities to be performed while interacting with the Playstation 4. This information was gathered by conducting a survey on twenty random “gamers†on the Playstation 4 forum and the Playstation 4 chat network. Most common tasks on the device involved logging on to the Playstation network, downloading applications from the Playstation store, Chatting with people on the Playstation chat and Playing online games. We added two extra tasks that we believe might relieve interesting packages, which are: Letting the device stand in standby mode for one minute and using the Playstation's built in web browser to visit a widely used website. The chosen website is Facebook.com by reason of that it is the third most visited website on the web~\cite{mostWeb}. With this information in consideration we also want to do further research based on previous experiments conducted in the same field. With Trapps~\cite{MonitoringAndroid} paper in mind, where he suggests investigating: “Attach a console like a Wii or PS3 and see what kind of information it sends at startup and logon.†%REFERENCES 49, 24
487
488\begin{enumerate}
489 \item Log on the device.
490 \subitem Description: This task contains booting up the console and a normal login process, conducted by starting the Playstation and letting everything that is loading finish.
491
492 \item Let the device stay on standby for one minute.
493 \subitem Description: Located on the Dashboard without any interaction with the device during one minute.
494
495
496 \item Log in and out of Facebook, using the web browser on the device.
497 \subitem Description: Opening the preinstalled web browser, searched “facebook.com†and logged in. Next we scrolled for about 5 seconds and then logged out.
498
499 \item Download a free application on the Playstation store.
500 \subitem Description: Opened the preinstalled Playstation store application and searched “media player†and downloaded the first in the list named “MediaPlayerâ€.
501
502
503 \item Exchange a few messages with another user using the Playstation chat function.
504 \subitem Description: Started a chat with a current friend in the friend list on the Playstation chat. Exchanged a few messages with each other then exit chat.
505
506 \item Play an online game for five minutes.
507 \subitem Description: Started the game “Tom Clancy’s The Division†and entered an online match. Played for five minutes and then quit the game.
508\end{enumerate}
509%DONE
510
511
512
513\subsection{Procedure}
514
515The study consisted of practical experiments by intercepting the network communication between the Playstation 4 and the Internet. This was done by initially setting up the environment so that the interception could be performed.
516
517Firstly we connected the laptop running \gls{archLinux} to the Internet, then the Internet connection was NATed to the Playstation 4. This was done by inserting the WiFi USB Adapter into the laptop. To be sure that the WiFi USB Adapter could perform the task at hand we decided to configure it to be set in Monitor mode. This was done by firstly acquiring the “interface name†Arch gave the WiFi USB Adapter. In the terminal we ran the command: \textit{Ifconfig} . This command lists all active interfaces. Next we had to put the interface in idle mode to be able to change the mode. In the terminal we ran the command: \textit{sudo ifconfig wlp0s20u1 down}. Then we change the mode by running the command: \textit{sudo ifconfig wlp0s20u1 monitor}. At last we put the interface in active state by running the command: \textit{sudo ifconfig wlp0s20u1 up}.
518%Link arch to glossary?
519
520Subsequently a shell script named Create\_ap~\cite{gitHub} was used, which created a NATed Software Access Point by after installing it running the command shown in Figure. \ref{createap}.
521% REFERENCE 27
522
523The Create\_Ap command works by this syntax: create\_ap [options] wifi-interface [interface-with-Internet] [access-point-name [passphrase]], where [options] defines what method to be used to transfer Internet over to the other interface.
524
525\begin{figure}[H]
526 \begin{center}
527 \makebox[\linewidth]{ % to center the image
528 \includegraphics[width=160mm]{createap.png}
529 }
530 \caption{ Terminal window while the Create\_Ap script is running. }
531 \label{createap}
532 \end{center}
533\end{figure}
534
535When the access point was up and running we connected the Playstation 4, and simultaneously started Wireshark on the laptop to intercept all the network communication done by the tasks described in the Experimental task section.
536
537
538\subsubsection{Data analysis}
539Every package received and sent by the device was saved and categorized in a separate log file for each task performed. These log files were then processed by Wireshark filters and string search queries to extract data of interest.
540
541To be able to simplify and perform the analysis as effective as possible multiple filters were developed for each of the tasks with the device. These filters allowed us to quickly separate non relevant data from data that is actually interesting for our study. Non relevant data is for example keep alive packages communicated from the laptop to the device. Each filter used is listed below with description, followed by the filter code marked in bold text.
542
543\begin{description}
544 \item [Filter 1]
545 A filter was developed to hide packages to and from the host laptop as well as arp, icmp, dns, which are protocols that may produce background noise. Allowing us to focus on the traffic of interest from the Playstation 4 and the Internet.
546 \textbf{!(ip.src==192.168.1.1)\&\&!(ip.dst==192.168.1.1)\&\&!(arp or icmp or dns)}.
547
548 \item [Filter 2]
549 To filter out only HTTP GET requests the following filter was written: \textbf{http.request}. This filter allowed us to filter out so that all remaining was the images.
550
551 \item [Filter 3]
552 The following filter was used to bring forth as much clear text communication as possible since the majority is sent over these protocols: \textbf{http or dns}.
553
554 \item [Filter 4]
555 This filter was built to be able to show only SSL encrypted packages to conclude if there were any communication conducted over old versions of this protocol: \textbf{ssl}.
556\end{description}
557
558\subsubsection{Manual analysis}
559Finally manual analysis on the gathered data was conducted. The purpose of finding out what kind of information we were able to extract. For example clear text (unencrypted) messages or images from the collected packages and if there was any data to put together about the system or the systems users. To be able to search for a specific String in the gathered data packages the Wireshark Find Packet Tool was used. Accessed by clicking Edit -> Find Packet. This tool is similar to the filter: \textbf{tcp contains traffic} which displays all TCP packets that contain in this example the word ‘traffic’.
560
561Table \ref{stringTable} contains all the strings used for searching inside the collected packages. The strings consists of file types (written in capital letters), common privacy and security related keywords (written in lowercase letters) and finally (written in blue color) username and password for the currently logged in user as well as the username of the other user, where messages were exchanged in task 5. Each string are also followed by a short description [58].
562The decision on which strings to use for the string searches is based out of the privacy section in the background.
563%REFERENCE 58
564
565
566
567
568\begin{table}[!ht]
569 \begin{center}
570 \begin{tabular}{ | l | l | }
571 \hline
572 \textbf{Strings} & \textbf{Descriptions} \\\hline
573 date, time & Looking for data containing package timestamps \\ \hline
574 location & Looking for data containing geographical location \\ \hline
575 username, user & Looking for username related data \\ \hline
576 password, pass & Looking for password related data \\ \hline
577 {\color{blue} other username} & Username of the user who messages were exchanged in task 5 \\ \hline
578 {\color{blue} username} & Real users username, currently logged in on the device \\ \hline
579 {\color{blue} password} & Real users password, currently logged in on the device \\ \hline
580 SWF & Shockwave Flash \\ \hline
581 PNG, JNG, MNG & Portable/JPEG/Multiple-image Network Graphics \\ \hline
582 MP3 & Audio file format \\ \hline
583 AAC & Advanced Audio Coding \\ \hline
584 ZIP & ZIP archive \\ \hline
585 GPX & \parbox[t]{10cm}{ Geotag for images from a GPS, the GPX file format contains a track log } \\ \hline
586 NMEA & Global Positioning file (GPS) \\ \hline
587 KLM & \parbox[t]{10cm}{ Keyhole Markup Language, an XML notation for expressing geographic annotation. } \\ \hline
588 CSR, CER & Stores certificates \\ \hline
589 SSH, PUB & \parbox[t]{10cm}{ OpenSSH private key, Secure Shell private key; format generated by ssh-keygen. } \\ \hline
590 PPK & \parbox[t]{10cm}{ PuTTY private key ,Secure Shell private key, in the file format \\ generated by PuTTYgen instead of the format used by OpenSSH. } \\ \hline
591 KDB, KDBX & Encrypted password file created by KeePass password manager \\ \hline
592 BPW & Encrypted password file created by Bitser password manager \\ \hline
593 INI & Configuration text file \\ \hline
594 HTML & HyperText Markup Language \\ \hline
595 JSON & Data file format used by many programming languages \\ \hline
596 XML & An open data file format \\
597 \hline
598 \end{tabular}
599 \caption{contains all the strings with description used for the string searches.}
600 \label{stringTable}
601 \end{center}
602\end{table}
603
604
605\newpage
606\section{Results}
607 This chapter is conducted to present the results gathered during the experiment to answer if there are any data leakages in the communication between the Playstation 4 and the Internet. In that case what kind of information we are able to extract and how that is done. The results are broken down into sections based on the tasks in same order as mentioned in methodology chapter. Each section presents initially if any encrypted communication was conducted with outdated protocols, followed by the result of those string queries previously described in Table. \ref{stringTable} where something was found.
608
609
610\subsection{Results from each tasks}
611
612\subsubsection{Task 1: Log on the device}
613After the filter for ssl was applied we could conclude that one tenth of the packages displayed was sent over an old version of TLS more specifically version 1.0.
614
615
616
617\begin{table}[!ht]
618 \begin{center}
619 \begin{tabular}{ | l | l | }
620 \hline
621 \textbf{Strings} & \textbf{Returned result} \\ \hline
622
623 png & Cleartext url to images and Json containing URLs to images of different games \\ \hline
624
625 user & A couple of certificates containing hashed values \\ \hline
626
627 pass & Json containing URLs to images of different games \\ \hline
628
629 csr & Certificates found with encryption \\ \hline
630
631 cer & Certificates found with encryption \\ \hline
632
633
634 json & Containing URLs to images \\ \hline
635
636 \end{tabular}
637 \caption{This table presents the strings that returned a result in task 1. }
638 \label{task1table}
639 \end{center}
640\end{table}
641
642
643The results gathered from task 1 are as shown in table \ref{task1table}. First of which is the string “pngâ€, which resulted in that we got some cleartext urls to images and a couple of json tables containing URLs to images of different games and applications. One of the images found and its url is shown in figure \ref{getImageWireshark}. While searching for “user†we were able to find certificates with hashed values. The same jsons containing the URLs to images that was found while searching for “png†were also found when the search for “pass†and “json†was conducted. Searching for “csr†and “cer†resulted in certificates with a ssl encryption.
644
645\begin{figure}[ht!]
646 \begin{center}
647 \makebox[\linewidth]{% to center the image
648 \includegraphics[width=190mm]{getImageWireshark.png}
649 }
650 \caption{ Get request for a png files url in cleartext acquired during task 1. }
651 \label{getImageWireshark}
652 \end{center}
653\end{figure}
654
655
656\subsubsection{Task 2: Let the device stay on standby for one minute}
657After the filter for ssl was applied we could conclude that a couple of the packages displayed was sent over an old version of TLS more specifically version 1.0.
658
659\begin{table}[!ht]
660 \begin{center}
661 \begin{tabular}{ | l | l | }
662 \hline
663 \textbf{Strings} & \textbf{Returned result} \\ \hline
664
665 user & Some certificates found containing encrypted values \\ \hline
666
667 cer & certificates found \\ \hline
668
669 pub & a couple encrypted pubkeys with key length in cleartext \\
670
671 \hline
672 \end{tabular}
673 \caption{This table presents the strings that returned a result in task 2. }
674 \label{task2table}
675 \end{center}
676\end{table}
677
678The results gathered from task 2 are as shown in table \ref{task2table}. While searching for “user†and “cer†a couple of certificates with encrypted content were found, one of which can be seen in figure \ref{certificat_whireshark}. Searching for the string “pub†resulted in that a few pubkeys were found, but they were all encrypted. The length of the pubkeys was also found.
679
680
681\begin{figure}[ht!]
682 \begin{center}
683 \makebox[\linewidth]{% to center the image
684 \includegraphics[width=170mm]{certificat_whireshark.png}
685 }
686 \caption{ A certificate acquired during task 2. }
687 \label{certificat_whireshark}
688 \end{center}
689\end{figure}
690
691
692\subsubsection{Task 3: Log in and out of Facebook, using the web browser on the device}
693After the filter for ssl was applied we found out that all the communication was exchanged with the latest version of TLS.
694
695\begin{table}[!ht]
696 \begin{center}
697 \begin{tabular}{ | l | l | }
698 \hline
699 \textbf{Strings} & \textbf{Returned result} \\ \hline
700
701 cer & certificates found \\ \hline
702
703 pub & a few pubkeys, encrypted and with key length \\ \hline
704
705 ini & Facebook’s ip address, both ipv4 and ipv6 \\
706
707 \hline
708 \end{tabular}
709 \caption{This table presents the strings that returned a result in task 3. }
710 \label{task3table}
711 \end{center}
712\end{table}
713
714
715The results gathered from task 3 are as shown in table \ref{task3table}. While searching for “cer†a couple of certificate containing encrypted data were found. Searching for “pub†returned a few pubkeys, but they were also encrypted. The length of the pubkey was also found. When “ini†was used as the search string, we were able to locate IP addresses both IPv4 and IPv6 for Facebook's european server.
716
717\subsubsection{Task 4: Download a free application on the Playstation store}
718After the filter for ssl was applied we could conclude that almost one third of the packages displayed was sent over an old version of TLS more specifically version 1.0.
719
720\begin{table}[!ht]
721 \begin{center}
722 \begin{tabular}{ | l | l | }
723 \hline
724 \textbf{Strings} & \textbf{Returned result} \\ \hline
725
726 user & \parbox[t]{10cm}{ Found a json file with the downloaded applications name in different language the applications icon } \\ \hline
727
728 cer & multiple certificates found \\ \hline
729
730 ppk & json containing pkg files \\ \hline
731
732 pub & a couple pubkeys, encrypted and with key length \\ \hline
733
734 json & \parbox[t]{10cm}{ json file with the downloaded applications name in different language and the applications icon. Also another json with pkg files inside. }\\
735
736 \hline
737 \end{tabular}
738 \caption{This table presents the strings that returned a result in task 4. }
739 \label{task4table}
740 \end{center}
741\end{table}
742
743The results gathered from task 4 are as shown in table \ref{task4table}. Searching for “user†resulted in a json file containing the downloaded applications name in different languages and the applications icon. Searching for the string “cer†returned a couple of certificates with encrypted content. While searching for “pub†a few pubkeys were found, but they were also encrypted. The length of the pubkey was also found. “ppk†resulted in a json containing pkg files. Pkg file type contains instructions on how to create SIS files on a Symbian OS device, including the vendor name, software dependencies, and application files to copy; stored in a plain text format [62].
744%REFERENCE
745And by searching for “json†we got two jsons, the first one was the same as the one we got while searching for “user†and the second one was the same as the one we got while searching for “ppkâ€.
746\subsubsection{Task 5: Exchange messages with another user using the Playstation chat}
747After the filter for ssl was applied we could conclude that nearly half of the packages displayed was sent over an old version of TLS more specifically version 1.0.
748
749\begin{table}[!ht]
750 \begin{center}
751 \begin{tabular}{ | l | l | }
752 \hline
753 \textbf{Strings} & \textbf{Returned result} \\ \hline
754
755 png & picture of users avatar \\ \hline
756
757 aac & certificate \\ \hline
758
759 user & some certificate, image of users avatar \\ \hline
760
761 cer & multiple certificates found \\ \hline
762
763 ppk & found a json, containing pkg files \\ \hline
764
765 pub & a certificate \\
766
767 \hline
768 \end{tabular}
769 \caption{This table presents the strings that returned a result in task 5. }
770 \label{task5table}
771 \end{center}
772\end{table}
773
774The results gathered from task 5 are as shown in table \ref{task5table}. Searching for “png†resulted in that we were able to obtain the user's profile picture shown in figure \ref{profilepic}. And while searching for “aacâ€, “cer†and “pub†a couple of certificate containing encrypted data were found. “ppk†resulted in a json containing pkg files. And we searched for “user†we once again got the user's profile picture and also a few certificate containing encrypted data.
775
776
777
778\begin{figure}[ht!]
779 \begin{center}
780 \makebox[\linewidth]{% to center the image
781 \includegraphics[width=70mm]{viewImageFromGame.png}
782 }
783 \caption{ This image is the profile picture of one of the users in the chat session acquired during task 5. }
784 \label{profilepic}
785 \end{center}
786\end{figure}
787
788
789\subsubsection{Task 6: Play an online game for five minutes}
790After the filter for ssl was applied we found out that all the communication was exchanged with the latest version of TLS.
791
792\begin{table}[!ht]
793 \begin{center}
794 \begin{tabular}{ | l | l | }
795 \hline
796 \textbf{Strings} & \textbf{Returned result} \\ \hline
797
798 png & found about 20 images \\ \hline
799
800 user & some certificate \\ \hline
801
802 pass & found a few images \\ \hline
803
804 cer & multiple certificates found \\ \hline
805
806 pub & a couple pubkeys, encrypted and with key length \\ \hline
807
808 json & found a json file containing the game name also an icon and a background picture \\
809
810 \hline
811 \end{tabular}
812 \caption{This table presents the strings that returned a result in task 6. }
813 \label{task6table}
814 \end{center}
815\end{table}
816
817The results gathered from task 6 are as shown in table \ref{task6table}. While searching for “user†and “cer†a couple of certificate containing encrypted data were found. And searching for “pub†resulted in a few pubkeys, but they were also encrypted. The length of the pubkey was also found. Searching for “png†and “pass†resulted in a couple of pictures from the game itself. And finally while searching for json we got a json file with the game name and an icon and a background picture.
818
819
820\definecolor{lightblue}{rgb}{0.0,0.99,0.9}
821
822
823\subsection{Summarization of the results}
824This section aims to summarize the results.
825
826
827\begin{table}[!ht]
828 \begin{center}
829 \begin{tabular}{ | l | c | c | }
830 \hline
831 \textbf{Tasks} & \textbf{Data leakages} & \textbf{No data leakages} \\ \hline
832
833
834 Task 1 & x & \\ \hline
835
836 \cellcolor{lightblue}Task 2 & \cellcolor{lightblue} & \cellcolor{lightblue}x \\ \hline
837
838 Task 3 & x & \\ \hline
839
840 \cellcolor{lightblue}Task 4 &\cellcolor{lightblue}x & \cellcolor{lightblue} \\ \hline
841
842 Task 5 & x & \\ \hline
843
844 \cellcolor{lightblue}Task 6 & \cellcolor{lightblue} &\cellcolor{lightblue}x \\
845
846 \hline
847 \end{tabular}
848 \caption{This table shows what tasks contained data leakages and which ones did not.}
849 \label{taskSumTable}
850 \end{center}
851\end{table}
852
853
854Table \ref{taskSumTable} illustrates a summarization of the results gathered during the experiments. It shows that 66\% of the tasks analysed had at least one data leakage. All the tasks where there were data leakages, leaked images. As discussed in the security and privacy section in the background chapter, images could contain sensitive data about the user or the user’s system.
855For the Wireshark dump files containing the complete data, see Appendix \ref{bilaga:dumpfiles}.
856%DONE
857
858%\section{Discussion}
859
860%\section{Conclusion and future work}
861
862
863\newpage
864\addcontentsline{toc}{section}{}
865 \bibliographystyle{elsarticle-harv}
866 \bibliography{biblotek}
867
868 \newpage
869 \begin{appendices}
870
871 \begin{enumerate} [(A)]
872 \item Create\_Ap script - A shell script to create a NATed/Bridged Software Access Point\label{bilaga:createAp}
873 \subitem https://github.com/oblique/create\_ap
874
875 \item Experimental tasks Wireshark dump files for each task performed.\label{bilaga:dumpfiles}
876 \subitem https://drive.google.com/open?id=0BxJ1ec4LM8hfODRqVFp4NDVfRjQ
877
878
879 \end{enumerate}
880 \end{appendices}
881
882\end{document}