Security Evaluation
- f Home-based
IoT Deployments
Omar Alrawi
Security Evaluation of Home-based IoT Deployments Astrolavos - - PowerPoint PPT Presentation
Omar Alrawi Security Evaluation of Home-based IoT Deployments Astrolavos Research Lab at Georgia Tech We specialize in Network Security Measurements Work is presented on behalf of my team Omar Alrawi PhD Student (me) About
Omar Alrawi
Measurements
UNC Chapel Hill
Motivation
Past Research
Methods
Findings
Moving Forward
and Network
Stakeholders
community?
studied?
proposed?
fixes?
security
in Mobile App and Cloud
propose Frameworks
most cases
pins
services leads to Ransomware
(LIFX)
firmware – going nuclear (Hue)
Internet
for nearby communication
vulnerabilities
protocols
mobile apps
Studied Componenets
Devices Cloud integration services Network (by association)
Mitigations
Patching bugs Vendor responsibility
Unexplored Directions
Mobile app Cloud services Network discovery protocols User control and visibility
Our Approach
services
insecure protocols
home assistant, light bulbs, hubs, TVs, game consoles
apps
vulnerabilities
MiCasa Verde VeraLite
locks
port 3401
between components
server
RCE
that are not used
Created a scorecard system Rating for components Independent scoring Modular and customizable Documented
evaluation
evaluation