Analyze Potential Cybersecurity Risks

profileZEKEB
Ataxonomyofcyber-physicalthreatsandimpactinthesmarthome.pdf

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

Available online at www.sciencedirect.com

j o u r n a l h o m e p a g e : w w w . e l s e v i e r . c o m / l o c a t e / c o s e

A taxonomy of cyber-physical threats and impact in the smart home

Ryan Heartfield ∗, George Loukas , Sanja Budimir , Anatolij Bezemskij , Johnny R.J. Fontaine, Avgoustinos Filippoupolitis, Etienne Roesch

Computing and Information Systems, University of Greenwich, UK

a r t i c l e i n f o

Article history:

Received 9 May 2018

Revised 21 July 2018

Accepted 25 July 2018

Available online 1 August 2018

Keywords:

Cyber security

IoT

Smart Home

Cyber-Physical Attacks

Cyber crime

Privacy

a b s t r a c t

In the past, home automation was a small market for technology enthusiasts. Interconnec-

tivity between devices was down to the owner’s technical skills and creativity, while security

was non-existent or primitive, because cyber threats were also largely non-existent or prim-

itive. This is not the case any more. The adoption of Internet of Things technologies, cloud

computing, artificial intelligence and an increasingly wide range of sensing and actuation

capabilities has led to smart homes that are more practical, but also genuinely attractive

targets for cyber attacks. Here, we classify applicable cyber threats according to a novel tax-

onomy, focusing not only on the attack vectors that can be used, but also the potential im-

pact on the systems and ultimately on the occupants and their domestic life. Utilising the

taxonomy, we classify twenty five different smart home attacks, providing further examples

of legitimate, yet vulnerable smart home configurations which can lead to second-order at-

tack vectors. We then review existing smart home defence mechanisms and discuss open

research problems.

© 2018 Elsevier Ltd. All rights reserved.

1

A c a n S b o c p o a h

e e t h t t t h n t l t p

h 0

. Introduction

s homes adopt Internet of Things (IoT) technologies and be- ome increasingly smart by utilising networked sensing and ctuation, cloud computing and artificial intelligence, they aturally become more vulnerable to threats in cyber space. ome of these threats are entirely new. The majority are not, ut applying them in a domestic context generates second- rder threats to the physical and emotional safety of the oc- upants to an extent not previously experienced. Here, we resent a taxonomy of cyber threats to smart homes already bserved in the wild or in controlled experiments, as well s potential future vulnerabilities exposed by specific smart ome configurations and technology adoption.

∗ Corresponding author. E-mail address: [email protected] (R. Heartfield).

t c f

ttps://doi.org/10.1016/j.cose.2018.07.011 167-4048/© 2018 Elsevier Ltd. All rights reserved.

Smart home cyber security is usually addressed as an xtension of the smart grid, looking almost exclusively at nergy-related attacks ( Komninos et al., 2014 ). This has begun o change. Indicatively, Lin and Bergmann (2016) have taken a olistic perspective on smart home privacy and security, iden- ifying the combination and convergence of heterogeneous echnologies, with lack of specialised security knowledge, as wo key challenges exacerbating the cyber threat to smart ome environments. Here, we look more deeply at the tech- ical building blocks of cyber threats to smart homes, iden-

ifying key classification criteria that help to shape the attack andscape. We do not claim that this taxonomy can be exhaus- ive. However, in identifying and characterising existing and otential future cyber threats to the smart home, we are able o highlight motivations, resources, vulnerabilities and cru- ially their impact, so as to help establish the problem space or defence measures that would address them.

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 399

2. Related work

The smart home is not a fundamentally new technological paradigm. So, although there has not been a taxonomy of cy- ber threats for smart homes before, it is meaningful to con- trast against related work that is more general for IoT or pre- viously established areas, such as wireless sensor networks and networked embedded systems. Babar et al. (2010) were the first to propose a taxonomy of IoT cyber threats, but only provided a high-level overview of security requirements and types of threats in terms of communication, identity man- agement, storage management, embedded security, physical threats and dynamic binding. More recent work by Jing et al. (2014) has looked at IoT security from the perspective of se- curity needs at the application layer, the transportation layer and what they refer to as the perception layer, which is where the data collection occurs. The resulting architecture is ef- fectively a taxonomy of the types of threats at each layer, which, interestingly, includes smart home security as one of the requirements at the application layer, but does not elabo- rate further. Another area of interest is privacy in IoT, where Ziegeldorf et al. (2014) have classified the impact of an IoT privacy breach as relating to identification, tracking, profil- ing, privacy-violating interaction, lifecycle transitions, inven- tory attacks and linkage. This is a well thought-out taxonomy, but is naturally limited to privacy and does not consider the technical properties of a smart home or the second-order im- pact on its occupants. Nawir et al. (2016) have presented a tax- onomy of IoT security attacks, classified according to device property, location, access level and protocol type. Their analy- sis includes security issues related to the healthcare, trans- portation and smart home domains, but this classification is not present in their taxonomy. Finally, a taxonomy of IoT based smart environments is presented in the work of Ahmed et al. (2016) , which classifies the IoT environment based on communication enablers, network types, technologies, local area wireless standards, objectives, and characteristics. The security aspects are only briefly touched upon as part of the technologies category.

In Table 1 , we summarise existing taxonomies to high- light the current perceived extensions of the security problem space in the smart home domain. We emphasise in particu- lar on the key security properties, the vulnerabilities and par- ticular factors making smart home IoT security challenging, as well as any recommendations for security and novel chal- lenges for research as identified by each existing taxonomy.

Here, we consider the large variety of technical configura- tions of current smart homes, provide a detailed description of the attack surface and take into account each attack’s impact on domestic life, as supported and shaped by a smart home, extending to the potential impact on the occupants’ physical and emotional wellbeing too.

3. A taxonomy of cyber threats to smart home

A primary motivation for developing this taxonomy is to es- tablish a systematic means for classifying attack vectors and the their impact as a holistic view of cyber threats within the

context of the smart home. Hence, we are not only concerned with identifying extant or emerging attack vectors (e.g., as a result of technology convergence in the household), but also establishing the physical, domestic and emotional impact for human occupants. With these objectives in mind, to direct the construction of taxonomy criteria we start with the following questions:

• By what means can an attacker target the smart home? This involves identifying the different ways and conditions by which an attack might be distributed and automated in the smart home, which are vital to distinguish between ex- plicit vulnerabilities in systems and second-order threats which are manifested by a household’s specific configura- tion.

• How is the cyber security of a smart home compromised by an attack? A consequence of technology convergence in the smart home is the cascading effect of compromise of one system to others. For example, a breach of confidentiality, integrity and availability resulting from a vulnerability in a single device may result in shared exploitation across interde- pendent systems. A secure system may be rendered vul- nerable by the insecurities of a lesser protected platform on which it relies. Stealing the WiFi keys from the firmware of a smart light-bulb inadvertently affects the confidentiality of other devices connected to the same WiFi access point.

• In what ways will cyber-physical systems in the smart home respond to attacks? Establishing the different ways in which physical systems respond to cyber threats is important in understanding the risks to occupants and even for detecting threats by mon- itoring both cyber and physical system behaviour.

• What are the direct consequences of an attack for smart home occupants? Conventional security breaches in cyberspace typically re- sult in financial loss, breaches of data privacy or loss of con- trol of computer devices. In the smart home, by compro- mising or disrupting household appliances and systems, the consequences can extend not only to cyberspace but also to physical space, whereby the physical privacy, safety and well-being of occupants are threatened.

• How do occupants experience the impact of different at- tacks against the smart home? Smart homes are typically set up for convenience, secu- rity and energy efficiency, but these can all be severely dis- rupted by a cyber security breach, leading to adverse expe- rience on the affected users’ daily lives, ranging from mild inconvenience to loss of time and intense frustration due to goal blockage.

• How will occupants respond emotionally as a result of an attack against the smart home? While different people respond differently, stress, anxiety and privacy-seeking behaviour ( Oulasvirta et al., 2012 ) are some of the expected short-term and long-term effects that need to be taken into account.

We use this set of questions as the basis for our root tax- onomy criteria: Attack Vector, Impact on Systems and Impact on Domestic Life . In the following sections, each set of answers is

400 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

Table 1 – Summary of existing taxonomies with applicability in smart home cyber security.

Reference Key security properties

Vulnerabilities/ challenges

Security recommended

Open problems identified

Komninos et al. (2014) Confidentiality Connected to Internet Auto-immunity to threats Resilience Physical tampering Reliability, availability

Lin and Bergmann (2016) Confidentiality Phys./netw. accessibility Gateway architecture

Auto-configuration

Authentication Constrained resources Updates Access control Heterogeneity

Nawir et al. (2016) Smart meter integrity Remote connectivity Techn. countermeasures

Standardisation

Privacy Physical tampering Regulatory initiatives

Impact evaluation, metrics

Non-repudiation Malicious actuation Intrusion detection Authorisation Logging for audit/forensics

Ziegeldorf et al. (2014) Privacy Identification Detection of sensitive content

Tracking Profiling Linkage

Fig. 1 – Causal relationship between root criteria in smart home cyber-threat taxonomy.

t s

w s s t a t h t

4

I p a s m g v m c

s m i i t

w r v p c c i p m w

l e T a c w

4

T p r c o i b o s p

ranslated into specific categories with relevant examples ob- erved in the wild or carried out as research experiments.

In Fig. 1 , each of the root classification criteria is shown ith basic high-level interactions. These interactions repre-

ent causal relationships which can be used to generate a clas- ification of a smart home cyber threat. In Section 7 , we prac- ically demonstrate how these interactions are represented s linearly separable steps, irrespective of the number of at- ack vectors and variable impact they may have. Moreover, we ighlight how this approach can be used to benefit different

ypes of research related to the cyber security of smart homes.

. Attack vector

oT proliferation, integration of sensors, actuators and low- owered wireless communications in domestic households, longside traditional home-broadband WiFi and Internet ervices, have positioned the smart home as a nexus of infor- ation technology connectivity. In the past, these technolo-

ies were typically designed and reserved for specialist en- ironments, such as industrial control, embedded sensing or edical data collection. In the smart home, they have now

onverged within a general consumer landscape. In a positive

ense, the smart home becomes a catalyst for the transfor- ation of domestic life through ubiquitous access to rich and

nteractive technology. However, almost paradoxically, it also nherits the emerging risks and vulnerabilities that come with he dependency on these technologies.

Within the context of the smart home, it is the occupants ho make the ultimate decision to install a new wireless secu-

ity lock, presence sensor or voice-controlled assistant, as pri- acy and security concerns are carried out according to occu- ants’ risk attitude ( Rahmati et al., 2018 ), personal and social ircumstances. By comparison, for smart offices and smart ities, introducing IoT systems requires rigorous ethical, pol- cy and even legislative evaluation before deployment. This ositions the smart home in many ways as a pilot environ- ent for future deployment of emerging IoT technologies to ider public contexts ( Chung et al., 2014; Dawadi et al., 2013 ).

For the immediate future, the smart home technology andscape is likely to be volatile, consisting of both legacy and merging IoT platforms, each with their own security risks. he threat landscape relates to the communication medium nd control software used, as well as threats in the supply hain, side channel attacks and the sensory channel. Below, e detail each of these categories with examples ( Fig. 2 ).

.1. CM (communication medium)

his is the means by which sensors, actuators, devices and ap- lications communicate in a smart home. It is symptomatic of apid innovation within the field of IoT that several communi- ation protocols deployed within the smart home will become bsolete over time. Consequently, the technologies evaluated

n this taxonomy constitute by no means an exhaustive list, ut at the time of writing, all are implemented within a range f smart home technologies and platforms and have been hown to contain technical vulnerabilities that have been ex- loited.

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 401

Fig. 2 – Smart home attack Vector classification criteria.

4.1.1. CM-HI: home internet Internet-connected households are by no means a new phe- nomenon. However, the advent of the smart home has positioned home internet connectivity as one of the primary gateways for attackers to gain access to devices, sensors and actuators in the household traditionally isolated from the out- side world.

Although home Internet is served externally to the house- hold via physical (e.g., copper or fibre broadband cabling) or wireless means (e.g., cellular), as a communication medium, it can be targeted both directly or indirectly. For example, di- rect targeting attempts to identify the public IP address as- signed to the home internet gateway in order to fingerprint services exposed to the Internet. Indirect targeting relates to solicited connectivity via the home Internet connection origi- nating from internal smart home devices or occupants toward Internet resources, which are under the control of an attacker (e.g., a compromised cloud service or a household occupant opening a phishing email).

As the vast majority of smart home platforms rely on the home Internet gateway to reach respective cloud services in order to function, if an attacker can compromise a smart home Internet gateway they may be able to disrupt or gain control of almost every Internet-connected device in the household. Stamm et al. (2006) have illustrated that by simply accessing a malicious web page an attacker can execute a Java applet with code on the client device that fingerprints home Inter- net routers’ internal IP addressing. On accessing the attacker web page, a basic script is executed that establishes a reverse socket connection back from the household client to the at- tack web server, where the returned client IP address pro- vides an indication of the internal addressing schema. This is subsequently used to enumerate whether web services (i.e., router administration websites) are hosted on any internal ad- dresses, followed by identification of different router models by querying web page content found (e.g., logos, text). Once

a router model is recognised, an attacker then issues a login query with the model’s default vendor credentials (which are often not changed by household users) in order to access the home Internet gateway and change key configuration settings. With this type of threat, no specific vulnerability of the home Internet medium is exploited. The authors have argued that reliance on the default control of blocking all unsolicited in- bound connectivity creates a false sense of security, as this type of access can be achieved by home users mistakenly run- ning malicious code on internal devices which subsequently provide access to the internal network, where all outbound connectivity and home internet router administration is en- abled by default.

As of May 2018, an initial report by Cisco Talos dramat- ically reinforced the growing vulnerability of home inter- net gateways by identifying a large scale advanced persis- tent threat against SOHO routers titled VPNFilter . Analysis of VPNFilter revealed a modular, multi-stage malware capa- ble of conducting intelligence gathering activities, as well as possessing “kill switch” denial of service capabilities against LinkSys, MikroTik, Netgear, Qnap and TP-Link SOHO router platforms typically deployed as home network internet gate- ways. Consisting of a three stage infection and command and control process, stage one installs a persistent boot loader into BusyBox or Linux based firmware, attempting to create an initial connection to an attacker server by downloading from seed URLs originating from Photobucket.com which then extract server IP addresses hidden in image EXIF meta-data; in the event of failure, a backup domain toknownall.com is used with the same process. Stage two proceeds to download a non- persistent module from the attacker server, running in a lo- cal working directory which contacts a C2 server to execute commands. Stage three expands the malware functionality by installing a non-persistent packet sniffing module which in- tercepts traffic and attempts to extract HTTP authentication

402 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

s m

h t d u i w c

4 W v q f u c a f i

s s s m o f

4 O s X a t j a

4 L t t t t s f i l d h c a a t w a t K i a

t i r

4 T w h 2 d a C w d c p o 1 b T c t

p a i p b ( h t t c

4 U p p e f r

4 I p ( d o m c d H b a w

g v p (

trings, as well as a communication plugin for remote com- unication over Tor. The researchers claimed that since 2016 VPNFilter may

ave compromised over 500,000 SOHO routers in over 54 coun- ries (many of which were common household internet router evices). They also noted that whilst no known exploits were ncovered regarding the initial infection vector, many of the

nfected home routers discovered were old or unpatched with idely known vulnerabilities, open source exploits and typi-

ally shipped with default login credentials.

.1.2. CM-WD: wired ired communication is increasingly rare in smart home en-

ironments, although still practical for applications that re- uire very high throughput rates, such as video streaming rom multiple security cameras, or would benefit from the nat- ral physical protection to sniffing and interference that wires an offer over wireless. Of course, this does not protect against ttacks that have penetrated the network and may originate rom the Internet or from inside the network, such as malware nfections and social engineering.

Generally, within the home environment fully-fledged tructured cabling is undesirable and impractical due to in- tallation requirements. However, where a building’s con- truction may introduce undue attenuation to wireless trans- ission signals (e.g., through steelworks or thick brick walls),

ften this has led to utilisation of existing power-line wiring or transmitting data between devices.

.1.3. CM-WD-X: X10 ne of the oldest home automation protocols, X10 was de- igned for power line communications. Improvements on the 10 protocol resulted in the A10 protocol, but without any dded security. In 2011, researchers demonstrated a device hat can be plugged into a power outlet outside a building to am the X10 signals that control lights, doors, air conditioning nd physical security systems ( Kennedy and Simon, 2011 ).

.1.4. CM-WD-K: KNX ike X10, KNX is a relatively old home and building automa- ion system that was designed to provide connectivity be- ween heating, ventilation, air and cooling systems which in he past had no means of communicating to report their sta- us or to provide remote configuration. Over time, IP exten- ions have been built into KNX gateways to facilitate greater unctionality and integration between system components n home and building automation deployments. However, by everaging IP-to-KNX connectivity Antonini et al. (2014) have emonstrated a practical attack against a real-world KNX ome automation platform, by successfully sending arbitrary ommands to actuators. The attack is achieved by distributing malware from a compromised IP host to KNX enabled actu- tors over the IP-to-KNX network gateway, no-password pro- ected actuators execute arbitrary commands within the mal- are command-set causing an operating system reset which

mounts to a DoS impact. In the case of password protec- ion, the malware simulates a device malfunction over the NX network (as device actions are not authenticated or ver-

fied), which results in controller reprogramming of the actu- tor with its password; as KNX does not use packet encryp-

ion, the resultant plaintext passphrase sent over the network s then sniffed over the network by the malware and used to eprogram KNX actuators.

.1.5. CM-WD-H: HAPCAN he Home Automation Project based on Controller Area Net- ork (HAPCAN) is an open source hardware framework which as been developed using the CAN 2.0B standard ( HAPCAN, 017 ). Analysis of the HAPCAN specification show a potential esign flaw in the communication protocol which may allow n attacker to exploit the arbitration mechanism within the AN bus. A rogue node can exploit the arbitration mechanism ithin CAN by constantly transmitting message IDs with a ominant bit set on the bus. The arbitration mechanism pro- esses message IDs with the dominant bit (0) with a higher riority over the recessive bit (1), i.e. a packet with message ID f 0000 will have higher priority over a packet with message ID 111, thus by constantly submitting a message ID of 0 to the us an attacker will take over the control of the arbitration. his attack leads other modules on the bus being starved of ommunication between each other, which effectively makes hem unavailable.

In HAPCAN, denial of service can also be achieved by ex- loiting the fact that all nodes are interconnected in series, nd therefore a failure of one module affects overall availabil- ty. Furthermore, as HAPCAN utilises the CAN protocol, the rotocol itself is at risk to several additional CAN vulnera- ilities, such as request overload and false request to send Mukherjee et al., 2016 ), or rogue node packet amplification ex- austing ( Bezemskij et al., 2016 ). Here, it is important to note

hat an attacker requires physical access to the communica- ion bus, e.g., by implanting a rogue node through the supply hain.

.1.6. CM-WD-U: universal power bus niversal Powerline Bus (UPB) is intended to be an X10 re- lacement with superior reliability (lower susceptibility to owerline noise and increased range). However, UPB has no ncryption and therefore any attack that is able to sniff data rom the powerline (such as using a rogue UPB node) is able to ead and inject data in the network.

.1.7. CM-WD-H: HomePlug AV n 2010, Puppe and Vanderauwera conducted a research roject into the security of the HomePlug AV protocol Vanderauwera and Puppe, 2010 ). They were able to execute ictionary attacks against the Devolo dLAN HomePlug’s use f 56-bit DES network encryption within 20 minutes. Further- ore, it was shown that a simple DoS attack could be exe-

uted by doctoring the rate at which an attacker HomePlug evice sends management packets (which are broadcast to all omePlugs’ in the network), whereby packet loss on a mem- er HomePlug was shown to be as high as 30% on receiving high rate of management packets sent with the wrong net- ork encryption key.

Tasker (2014) demonstrated how to infiltrate a HomePlu- AV network, using the ON Network’s PL500 HomePlugAV de- ice. Tasker identified that the MAC address of a HomePlug owerline station (STA) is used to derive a Device Access Key

DAK), which in turn can be used to tell target STAs to join a

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 403

rogue HomePlugAV network. HomePlugAV traffic can be pas- sively sniffed to identify MAC addresses to calculate the DAKs of available STAs and enrol them on the attacker network. Whilst this causes a temporary outage of the STAs if con- nected to an existing network, it is momentary and if the at- tacker leaves the network, normal communication with the legitimate HomePlug network will resume (thus the intrusion can go unnoticed by a occupant). Here, a successful attack al- lows for complete access to target data and it was identified that at that time at least eleven brands of HomePlug AV de- vice were vulnerable to the attack due to the DAK derivation method used to join the network – which if left unchanged makes the attack practically indefensible. A similar, but more complicated attack against DAKs was undertaken in Dudek (2015) , whereby a DAK passphrase generation technique was implemented to gain access to a neighboring HomePlug AV network.

For attacks against HomePlug devices to be practical, ac- cess to the same power line is required, for example within an apartment complex with a shared power feed, as practi- cally demonstrated by Dudek (2015) between two apartments in the same tower block in France.

4.1.8. CM-WD-L: LonTalk LonTalk is a building and home automation protocol opti- mised to control actuation and sensing devices as part of a LonWorks platform, originally developed in proprietary for- mat by Echelon Corporation, but now adopted as a ISO/IEC standard. Like other wired powerline building automation protocols ported to the smart home environment (e.g., X10, UPB, KNX). Despite recent resurgence of LonTalk as a viable means of smart home automation, the protocol has been as- sessed to be insecure by default by a cryptanalysis report in 2015 ( Corporation, 2010 ). Specifically, the EN 14908 algorithm used by LonTalk as part of its the Open Smart Grid protocol implementation uses a 48-bit key encryption key which can be trivially bruteforced ( Jovanovic et al., 2015 ). An online arti- cle by BusinessWire reported that LonTalk was estimated to be implemented in over 90 million devices world-wide as of 2010.

4.1.9. CM-WD-DS: digitalSTROM Recently, Brauchli and Li (2015) identified viable attacks on dig- italSTROM (DS), a smart home system with growing popularity throughout Europe based on home power-line networking. DS uses a proprietary unencrypted protocol (DS485) ( digitalStrom, 2015 ), typically consisting of an optional DS server and at least one DS meter and filter per circuit, with a number of termi- nal blocks connected to a DS chip for each device (e.g., fridge, fire alarm, heater, coffee maker etc.). Brauchli and Li have dis- cussed theoretical attacks, such as uploading power readings to a remote server for occupancy detection to manipulating lights and household appliances, by exploiting the DS Android app’s public interface through an Android intent cross-app message on a compromised smart phone. Whilst a compro- mised smartphone is required as an entry vector into the pow- erline, once this is established, the DS protocol provides un- restricted access to launch arbitrary commands against any connected appliances.

4.1.10. CM-wireless The majority of modern smart homes utilise wireless commu- nications and as a result are vulnerable to the security threats that are inherent in a wireless medium. For example, the sig- nals containing sensor data or actuation commands can be captured by an adversary in the vicinity, which makes strong encryption and countermeasures against replay attacks par- ticularly important. At the same time, wireless control can be rather trivially disrupted via communication jamming.

4.1.11. CM-WI-W: WiFi As most homes already have a Wi-Fi router, Wi-Fi is a common technology for connecting to smart home devices, such as a smart lights and smart plugs. However, security wise this also makes the Wi-Fi router the central point of failure of the smart home setup. This is significant because there are multiple free applications available on the Internet for acquiring the pass- word for Wi-Fi connections. Interestingly, by having access to the home Wi-Fi password, it may also be a smart home device that exposes it. This is the case where devices, such as smart light bulbs, need to communicate network configuration data between them. Masquerading as a new light bulb joining the network, researchers have demonstrated how to access secu- rity credentials, such as the home Wi-Fi password if no secu- rity measures are taken specifically for the light bulb to light bulb communication ( Wakefield, 2014 ). A practical example of such an attack was demonstrated by Chapman in 2014 against the LIFX lightbulbs ( Chapman, 2014 ), where in the presence of more than one bulb, a master is elected and network config- uration and information is passed between master and slave bulbs using an insecure IPv6 over low-power wireless personal area networks implementation.

WiFi de-authentication attacks present a well-known vul- nerability in the 802.11 protocol and can be utilised to lead to denial of service with de-authentication packets, or as a mechanism to perform Wi-Fi Protected Access (WPA) password cracking via sniffing a household WiFi-enabled device’s WPA 4-way handshake after they have been de- authenticated from the WiFi access point. In the same con- text, de-authentication can also be used to mount phishing attacks. For example, WiFiphisher can be used to execute a de-authentication attack for firstly disconnecting user devices (e.g., mobiles, tablets etc.) from the household WiFi access point, followed by a “Evil Twin” man-in-the-middle attack (e.g., SSID spoofing) to collect WiFi passwords from the unsuspect- ing occupants ( Chatzisofroniou, 2016 ). Here, the fact that WiFi is such a common protocol benefits the attacker, as there are several tools (indicatively, Aircrack-ng, MDK3, Void11, Scapy, Zulu and open-source project wifijammer software) and off-the-shelf hardware devices (indicatively, nodeMCU with ESP8266 DeAuther, spacehuhn, 2017 and the WiFi Pineap- ple device, Kitchen and Kinne, 2017 ) that are readily available. WiFi de-authentication is by no means new, but in the con- text of the smart home, the loss of WiFi means loss of Internet connectivity in the household, on which IoT platforms are in- creasingly dependent in order to function. Whilst the vulner- ability in question was addressed in 2009 by introduction of the 802.11w RFC, which strengthened the authenticity and in- tegrity of WiFi management packets, consumer-based router manufacturers do not often implement this extension into

404 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

t i 8 p

t 2 e s s w o c m t s e t s e L v

c p d n v i t t m t i 2 a a v c t f w t i h a c o c

4 Z h t t n m n h f

r q l t r (

s s d ( t fi b t t a

4 D m t s m c a c d h b s o d i t a i u s i o fl m w b e t a c (

4 B e fi e t t v a

heir WiFi protocol stack. So, even though 802.11w is available n most recent Linux kernels and Windows OS (since Windows ), often this feature must be disabled in order for it to be com- atible with household WiFi routers.

A newer type of WiFi attack that can affect a smart home is he key re-installation attack (KRACK) ( Vanhoef and Piessens, 017 ), which targets the four-way handshake of the WiFi WPA2 ncryption protocol. To connect to an access point with WPA2 ecurity, a Linux or Android-based device negotiates a unique ession-specific encryption key using a four-way handshake, here the key is installed after receiving message three out f four. However, to cope with lost or dropped packets, an ac- ess point will retransmit message three if an acknowledge- ent is not received from the connecting device, and each

ime this message is received, the target device reinstalls the ame encryption key; thereby resetting the nonce value (in ach packet) and receive replay counter. In this case, an at- acker can force nonce resets by collecting and replaying mes- age three. This can be used to decrypt, replay packets and ven inject new packets depending on the target protocol. inux and Android operating systems (OSs) are particularly ulnerable.

In January 2018, the WiFi Alliance released new WiFi se- urity enhancements entitled “WPA3”. WPA3 includes new rotections and enhancements on the existing WPA2 stan- ard, such as default unauthenticated encryption to public etworks, individual device data encryption (aiming to pre- ent complete compromise of the network if the WiFi key s compromised), protection against key re-installation at- acks (e.g., KRACK), as well as prevention of brute-force at- acks (through rate-limiting of device connectivity). WPA3 also

andates Protected Management Frames as part of the cer- ification (which has also been extended to WPA2), prevent- ng forced de-authentication attacks from occurring ( Alliance, 019 ). However, as with WPA2, there remains no specific mech- nisms to address the threat of Evil Twin access points where n attacker may strategically force unsuspecting smart de- ices to fall-back to a more insecure version of the WPA2 se- urity standard (or no WPA protection at all). Furthermore, he expected lengthy transition period from WPA2 to WPA3 or all WiFi enabled households and SOHO devices world- ide means that existing WiFi vulnerabilities are likely to per-

ain for an unknown length of time. More generally, grow- ng reliance on WiFi connectivity as an enabler of the smart ome continues positioning this communication medium as key target for attacks that aim to disrupt and gain ac- ess to the household, whether by disrupting WiFi services r compromising vulnerable devices which rely on WiFi for onnectivity.

.1.12. CM-WI-ZG: ZigBee igBee is one of the most popular protocols used in smart omes. An example attack that has been demonstrated in

he smart home cyber security literature is a sinkhole at- ack ( Coppolino et al., 2015 ), where a rogue node infiltrates a etwork of ZigBee wireless sensors and increases its trans- ission power, so as to be able to reach the ZigBee coordi-

ator with fewer hops and as such be preferred by the Ad oc On-Demand Distance Vector (AODV) routing protocol used

or routing packets by the other sensors. In this position, the

ogue node can choose not to forward the packets (and conse- uently the sensor data or the actuation commands) to their

egitimate destination or to modify them before doing so. No- ably, performing attacks in ZigBee networks is facilitated by eadily available exploitation frameworks, such as KillerBee Wright, 2009 ).

ZigBee and emerging IPv6 over Low power Wireless Per- onal Area Network technologies, such as Google’s open ource protocol Thread , rely on the IEEE 802.15.4 radio stan- ard for physical layer and media access control. Jenkins et al.

2014) have demonstrated how different implementations be- ween 802.15.4 radio receivers can be used to achieve device ngerprinting and facilitate targeted attacks, distinguishing etween a device that uses ZigBee or Thread (or another fu- ure protocol), then identifying the product vendor allows at- ackers to analyse the smart home and target known vulner- bilities in its devices.

.1.13. CM-WI-Z: ZWave evices using the Z-Wave communication protocol can imple- ent the Z-Wave security layer, which uses symmetric cryp-

ography to provide encryption and authentication services, o as to limit sniffing, replaying and injecting wireless com- ands. However, different Z-Wave devices share the same se-

ret key. So, physical access to an external sensor, such as passive infrared sensor outside the property can help ac- ess the key, which could work also for the front door, as emonstrated in Badenhop and Ramsey (2016) . A compre- ensive hacking toolkit named EZ-Wave has been developed y Hall and Ramsey for exploiting Z-Wave networks using oftware-defined radios. The EZ-Wave toolkit is built on top f the Python Scapy-radio library and consists of a network iscovery and active network enumeration functions, device

nterrogation to elicit device name, firm versions, configura- ion settings and execution of supported command classes, s well as determination of Z-Wave’s module generation us- ng physical network layer (packet preamble length) manip- lation ( Hall and Ramsey, 2018 ). The authors also demon- trated that Z-Wave toolkit can facilitate attacks which result n cyber-physical impact on smart devices, with an example f causing vulnerable Z-Wave enabled industrial and compact uorescent light bulbs to fail (the latter of which are com- only used in modern homes). With two HackRFs, EZ-Wave as utilised to request supported capability classes exposed

y the Z-Wave devices’ application program interface (API), ex- cuting these unauthenticated due to lack of encryption on he device. This allowed the researchers to repeatedly turn on nd off the Z-Wave enabled industrial and compact fluores- ent bulbs in 1 s “on” and 3 s “off” cycles, causing them to break Smith, 2018 ).

.1.14. CM-WI-B: bluetooth luetooth is becoming increasingly common in smart home nvironments. That is because it is at the same time an ef- cient communication protocol and a good mechanism for valuating proximity through signal strength (especially Blue- ooth Low Energy). Ho et al. (2016) have described how two at- ackers can unlock a smart lock using a Bluetooth relay de- ice. If attacker A is in close proximity to the legitimate user nd attacker B near the lock, then when B touches the smart

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 405

lock to begin the touch-to-unlock procedure, the message con- taining the authentication challenge is captured by the Blue- tooth relay device and is forwarded to attacker A (via Wi-Fi or some other communication channel). Upon receiving the relayed challenge, attacker A broadcasts it masquerading as the lock, and this is received by the legitimate owner’s de- vice, which returns a legitimate response. Attacker A captures this and relays it to attacker B, and in turn to the smart lock, which accepts it and unlocks. Similar attacks have often been demonstrated for unlocking cars that feature keyless entry ( Francillon et al., 2011 ).

4.1.15. CM-WI-N: NFC Over the last decade, Near Field Communications (NFC) has considerably evolved from its original inception in Radio Fre- quency Identification (RFID) technology. In standard RFID plat- forms, systems utilise short range wireless communication medium at low frequency ranges (30–300 KHz); commonly consisting of an identification tag (e.g., transponder), which responds passively by reflecting a signal or actively by broad- casting a signal. NFC (and by extension RFID), are commonly used in physical security systems, such as door entry or phys- ical authentication systems across a variety of industries which require physical security controls (e.g., corporate build- ing access, hotel room keys, Du, 2013 ). Within the context of the smart home, NFC technologies have been employed to provide the same benefits for physical security, as users are able to utilise their mobile devices as front-door keys.

However, due to a lack of definable NFC wireless commu- nication standards and a proliferation of NFC-enabled sys- tems, a number of vulnerabilities have been found across a range of NFC implementations. For example, NFC is vulner- able to remote eavesdropping attacks assuming that an at- tacker has a powerful enough receiver to capture a NFC signal ( Kennedy and Hunt, 2008 ) (by design, NFC requires extremely close proximity between the transponder and receiver, e.g., up to 10 cm). However, based on the device’s role (i.e. active or passive communication) which is limited by the type of de- vice (e.g., mobile, payment card etc.), the viable distance for an attacker can vary from 1 m to about 10 m. NFC implementa- tion is often application-specific and even vendor-specific, in many cases omitting security measures. Haselsteiner and Bre- itfuß (2006) have demonstrated data corruption, data modifi- cation, data insertion and man-in-the-middle attacks against NFC systems. Other attack vectors have been suggested by Francis et al. (2009) , who have demonstrated that it is possible for an RFID tag to be replayed or emulated on a NFC-enabled device. In one example ( Mayes et al., 2010 ), a cloning proce- dure was successfully implemented through the emulation of the behaviour of a legitimate NFC token.

4.1.16. CM-BC: BidCos The Bidirectional Communication Standard (BidCos) is a wire- less communication protocol operating at the 868MHz fre- quency and developed for the HomeMatic smart home sys- tem, used primarily in Germany. Whilst the BidCos protocol claims to support AES-128 encryption, it has been shown by Laufer and Mallas (2013) that the encryption is used for au- thentication purposes only and that any data exchange tak- ing place is actually unencrypted and does not provide data

confidentially. Kodra (2016) has demonstrated that this allows an attacker to easily sniff data on the BidCos network. More- over, the protocol data unit ( Frimmel et al., 2016 ) also allows an attacker to replay packets on the wireless network, which Kodra has demonstrated experimentally against a Homematic testbed in Kodra (2016) . Laufer and Mallas (2013) also demon- strated that it was possible to register a malicious node on the smart home network or reconfigure the system in such a way that nodes would change their control unit, if the user had not changed their default password (which was highly likely, because at the time an implementation bug was causing authentication problems if the password had been changed).

4.1.17. CM-WI-I: Insteon Insteon is a home area network protocol that utilises both wireless and wired connectivity to create a dual-mesh topol- ogy for communication between devices. The protocol aims to enforce network security via link control so that users can- not create links which would allow control over a neighbour’s smart home, but researchers have shown that the RF process is vulnerable to man-in-the-middle attacks, as Insteon device IDs can be easily sniffed. At DEFCON 23, Peter Shipley demon- strated that by reverse engineering the Insteon RF transmis- sion protocol and its Cyclic Redundancy Check (CRC) algo- rithm, in reality, it did not use or enforce any encryption in the link-layer at all ( Shipley, 2015 ); allowing attackers to sniff traf- fic, conduct replay attacks and issue arbitrary actuation com- mands.

4.2. CS: control software

Control software refers to the methods by which devices in the smart home are monitored, configured and operated (e.g., to trigger actuation, request sensor data or install updates). Control software is a prime target for attackers, where diverse software features can expose attack vectors through use of third party apps and vulnerabilities in the operating system or firmware.

4.2.1. CS-3PA: third party apps One of the key drivers of innovation and adoption of smart home technologies is the emergence of programming frame- works that facilitate the development of third party apps, for the same manufacturer or for integration of devices across multiple manufacturers. Popular examples are the Samsung SmartThings SmartApps , Apple HomeKit apps and Vera apps. Fernandes et al. (2016) carried out static analysis, runtime test- ing and manual analysis of 499 SmartApps and found that more than half of them were over-privileged due to too coarse- grained capabilities. Notably, one of the key threats demon- strated was remote lock-picking via a backdoor pin code in- jection attack. The exploitation functioned by allowing the re- searchers to generate a HTTPS link that led to the authentic SmartThings login page, which then exploited a flaw in the app allowing redirection of the user credentials (once submit- ted) from the SmartThings webpage to an attacker-controlled domain. Crucially, it was noted by the researchers that coarse permission binding between smart apps and smart devices was often forced upon the developers by the integration

406 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

f t l t c m t w d s a t a n v t P p J h t m w c s t s t I

4 T t u a h u t a a a c f a t D T s a ( t s i d t n O c i p

r a

4

F d s s i f t d l p d a t fi

s e a fi g c i t c r c i w i W t t a W t w a a t o t t o a t p d

c d h a r c t

ramework used. For example, analysis of the API exposure be- ween Samsung SmartThings platform integration and a Zwave ock highlighted that the device is exposes all of its capabili- ies to the SmartThings platform such as “capability.actuator, apability.lock, capability.battery ... etc.” The researchers re- arked that a smart app requesting one of these API func-

ions will be prompted by SmartThings for user authentication, hich then provides the requested access to the Zwave lock evice. However, following successful authorisation, the user’s mart app not only gains access to the requested resource, but lso to all of the other aforementioned capabilities exposed by he Zwave lock device at the same time. As a result, the smart pp is granted the the ability to perform functions that it may ot have been intended for and therefore if compromised pro- ides a key attack vector to compromise third-party integra- ion between smart apps and smart devices in the household. oor authentication and authorisation frameworks and im- lementation is also demonstrated in research carried out by

acoby (2014) , who demonstrated successful compromise of is network-attached storage by exploiting the insecure au-

hentication measures of its web server application (where the ain configuration file containing account password hashes as made available to anyone on the internal network). Ja-

oby also carried out a man-in-the-middle attack against his mart TV by exploiting the cloud application services used o populate multimedia information, which was made pos- ible due to a lack of authentication or encryption used by he TV when downloading content from the network and nternet.

.2.2. CS-OS: host OS o effectively manage and scale heterogeneous devices within he smart home and ensure practical usability for the home ser, control software tends to be designed to operate through single host operating system, such as a smartphone or home ub. In the case of the former, Android has become a pop- lar OS platform in which to develop smart home applica- ions, but is also known for having security flaws regarding pplication over-privilege or cross-talk. For example, an attack gainst the DigitalSTROM home automation system ( Brauchli nd Li, 2015 ) was practically facilitated by exploiting the intent ross-app message functionality provided by the Android OS or inter-communication between applications. In an attack gainst the Wink relay controller in Singh and Singh (2015) , he privacy of the system was breached through the Android ebug Bridge (ADB) service. In 2017, Neiderman reported that izen OS , Samsung’s IoT operating system, which used exten- ively on washing machines, refrigerators and other appli- nces, was vulnerable to at least forty zero-day attack vectors Bright, 2017; Drozhzhin, 2017 ). Of note was the observation hat the particularly insecure strcpy() function (superseded by trcpy_s()) in the C language had been used, even though it s widely known to easily lead to buffer overflow conditions ue a lack of bounds checking on input size for the destina- ions fixed-length buffer. In this case, the buffer overflow vul- erability enables an attacker to execute arbitrary code on the S, by injecting malicious input which will trigger the appli- ations memory stack to overflow and execute the remain- ng bytes (which correspond to the attacker’s code) with the ermission rights of the host program; which if running with

oot permissions may grant control of the platform to the ttacker.

.3. CS-F: firmware

irmware configuration and type is often dependent on the evice circuitry, chipset and hardware board. Therefore, many ecurity vulnerabilities in smart homes are often device- pecific, caused by flaws or lack of security protocols employed n their design or implementation. Here, we have chosen a ew indicative examples in a variety of systems, starting with he lack of state validation in the key exchange protocol han- ler programmed in the ZWave door lock firmware of a smart

ock analysed in Fouladi and Ghanoun (2013) . Another exam- le is the common vulnerability exposure code issued to a ishwasher’s firmware web server ( MITRE, 2017 ), which allows n attacker to traverse and map out the underlying web direc- ory and gain access to sensitive data, such as configuration les and database credentials.

Firmware vulnerabilities identified in the WeMo control oftware were found to be related to the use of a propri- tary protocol that is router-dependent and piggybacks across household’s WiFi network. In 2013, researchers discovered ve vulnerabilities in WeMO related to hard-coding of crypto- raphic keys, downloading firmware codes without integrity hecks based on the absence of a local certificate to verify the ntegrity of SSL connections, clear-text transmission of sensi- ive information, unintended proxy or intermediary protocol onfiguration and improper restriction of XML external entity eferencing (which related to the peerAddresses API which ould be attacked through XML injection potentially reveal- ng contents of local device system files). These vulnerabilities ere later issued in a CERT advisory ( CERT, 2014 ). Indicatively,

n the case of the unintended proxy, the flaw existed within eMo’s use of the universal plug and play over the session

raversal for network address translation (NAT) ( STUN ) pro- ocol, which bypasses network address translation firewalls nd consequently enables attackers to connect directly to the eMo devices over the Internet. Of course, these vulnerabili-

ies were later patched in a firmware upgrade, but until then ould give attackers the ability to utilise WeMo devices within Botnet or conduct cyber-physical attacks, such as flipping switch at a very fast rate to cause electrical damage. Un- il patched in newer versions, a vulnerability on the firmware f Amazon Echo would allow raw audio captured by the sys- em microphone to be forwarded to an attacker server. The at- ack required physical access to the debug pads on the bottom f the device (after removing the rubber base), and attaching secure digital (SD) card to the diagnostic interfaces. From here, a persistent implant was installed into the firmware to rovide root access, gaining remote shells and exfiltrating au- io recording ( Goodwin, 2017 ).

In Resno (2017) , the white hat hacker group Exploiteers dis- losed firmware vulnerabilities in over 43 Internet of Things evices from home automation devices such as the Wink ub to an LG smart refrigerator. In most cases, insecure ccess to the operating system via universal asynchronous eceiver/transmitter (UART) interfaces allowed direct root ac- ess to system firmware for reverse engineering and injec- ion of malicious code. Here, UART interfaces were found to be

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 407

1 Although not in the context of smart homes, the principle of exploiting the fact that a speaker-microphone pair is a security- wise unmonitored communication link has been used by Diao et al. (2014) to bypass the permission settings of a smartphone. Their experimental application needed only access to the speaker to whisper a command such as “call x number”, which is picked up by the phone’s microphone, and recognised by Google Voice Ser-

vulnerable due to the lack of secure UART bootloader which utilise encryption and authentication. This is considered a standard method for offensive exploitation of IoT systems, but one can argue that this, and generally the vast majority of firmware attack approaches, require physical access and are therefore often impractical. Of course, there is also the possi- bility of a supply chain attack, where the firmware has been compromised before it reaches the buyer (see Section 4.5 for more details).

4.3.1. CS-WA: workflow automation Beyond third party apps, the development of which requires programming skills, users can create their own automated workflows and event-driven links with their smart home sys- tems, using If This Then that (IFTTT) applets , Zapier worfklows , Stringify flows and other workflow automation services. An example IFTTT applet may set “location of the user’s smart- phone is at home” or “user’s smartphone connected to home Wi-Fi” as the trigger and “unlock the front door” as the action. In this case, an adversary that might have found it impossible to target the smart lock itself, may instead target one of the triggers in the user-defined applet .

As workflow automation platforms can gain significant ac- cess in defining, controlling and triggering system behaviour and interaction in the smart home, this makes them a prime target for semantic social engineering attacks ( Heartfield and Loukas, 2016 ). Whilst an attacker may not necessarily tar- get a specific vulnerability in workflow automation platforms themselves, a successfully crafted phishing email that de- ceives a user into divulging their account’s username and password potentially provides an attacker with the ability to edit, delete and create new workflow automation rules in the target household. By example, soon after Heartbleed OpenSSL vulnerability was made public in 2014, attacks began to craft phishing attacks targeting the IFTTT service aiming to gain ac- cess to victims accounts by spoofing emails requesting users to reset their passwords in light of the vulnerability affecting account security ( Cluley, 2014 ). Depending on the degree of in- tegration and different systems within the smart home, an at- tacker may have the ability to exfiltrate data, delete rules as a form of denial of service, as well as introduce new rules that would result in physical impact (detailed in Section 5 ).

4.4. S1: sensory channel

While research in relation to the security of sensing tends to focus on the data sharing, storage and processing, attackers may also maliciously manipulate the process at the level of data collection by exploiting physical weaknesses of the sen- sors themselves. Below, we have included an indicative list of such sensory channel exploitations.

4.4.1. S1-U: ultrasonic Ultrasonic sensing is commonly used for physical security ap- plications in smart homes, for example for presence detection ( Labs and Elliptic, 2017 ), but is also applicable to indoor posi- tioning ( Li et al., 2016 ). Ultrasonic sensing can be deceived by jamming the signal and replaying it slightly later, so as to gen- erate the impression of longer physical distance ( Sedighpour et al., 2005 ) or by producing a new but similar ultrasonic pulse

( Akdemir et al., 2010 ). In some cases, ultrasonic sensors can be bypassed by moving very slowly in front of them or by wear- ing a costume made of anechoic material that absorbs sound waves ( Loukas, 2015 ).

In 2017, ultrasonic attacks against a range of popular voice-controlled smart home assistants were demonstrated experimentally by generating human inaudible voice com- mands in the 20 kHz frequency range that were detected and processed. Zhang et al. have shown how to perform what they call a “Dolphin” attack ( Zhang et al., 2017 ) by modulating low-frequency voice as baseband signals on an ultrasonic carrier, which are then effectively demodulated by voice capture speech recognition systems on the receiv- ing hardware. Their results have shown that 15 out of 16 voice control systems (consisting of both mobile devices and home assistants, such as Amazon Echo Alexa) recognised the ultrasonic voice commands and (where applicable) 13 out of 13 platforms activated in response to the ultrasonic commands. However, it was also shown that the modulation parameters and maximum effective distance for recognition and activation varies significantly between different plat- forms. Nevertheless, the researchers demonstrated how the attack can be performed in a mobile nature using a relatively simple attack implementation, consisting of a Samsung Galaxy S6 Edge smartphone, ultrasonic transducer and a low-cost amplifier (where the transducer and amplifier cost no more than 3 dollars). Given this inexpensive and portable attack platform, the practicality of executing remote- controlled rogue ultrasonic voice injection attacks becomes an attractive prospect for attackers targeting voice-controlled systems.

Using the same premise, theoretically, an infrasonic at- tack (which by current convention would be named a “whale” attack) would pose the same threat to voice-controlled sys- tem microphones that are able to detect acoustic noise below 20Hz. To date, there have been no publicised infrasonic attacks against smart home or IoT systems. However, infrasound has been studied extensively as to its adverse effects on human subjects and therefore any future attack that aims to generate or inject infrasound in the smart home could potentially lead to harmful effects on occupants’ physical and mental well- being.

4.4.2. S1-V: voice Google assistant, Amazon’s Alexa and Apple’s Siri are exam- ples of personal assistant services that allow voice-activated control of a rapidly expanding range of smart home systems. From the perspective of security, voice becomes a sensory channel for the transmission of smart home actuation com- mands and exfiltration of information. Yet, this is a channel that is not normally monitored by technical cyber security measures.1

408 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

p A s p t K z m s a 2 ( r a f t ( i i t w c s H t c

s p c a i i t M s t G a p w o h g p t ( m

4 T n s ( n w

v e

d t d ( i c b c o k s o g c t v h s e C l

4

T s m p p w h b i s l a i

4 I i f d s e ( w m h s fi p q r

t p

In addition, personal assistant services tend to offer third arty apps (CS-3PA), such as Google Assistant’s Actions and mazon Alexa’s Skills , which expand massively the range of ystems and functionality that can be controlled. Equally im- ortant is that modern voice-activated systems do not need o learn their users’ voice, as exemplified in 2017 by a Burger ing television advert which activated voice-controlled Ama- on Echo devices by intentionally embedding a voice com- and ( Engadget, 2017 ) and by the rogue dollhouse orders is-

ued when “Alexa, can you play dollhouse with me and get me dollhouse?” was heard on a television programme ( Morsley, 017 ). Consider a situation where a compromised smart toy Medim, 2015; Partners, 2016a; Technology, 2016 ) plays a pre- ecorded voice command, such as “Alexa, unlock front door”, s demonstrated in Fig. 5 . In April 2018, security researchers rom Checkmarx developed a proof-of-concept malware that akes advantage of the platform’s third-party app integration see Section 4.2.1 , called Alexa Skills , which puts the device n an continual audio recording state to eavesdrop on audio n the household and then export recorded transcripts to a hird-party system ( Checkmarx, 2018 ). By disguising the mal- are as a simple calculator app, activated via “Alexa, open cal-

ulator”, the Echo API ( Amazon Lambda ) associated with the kill launches a second request to covertly record audio input. owever, the activity can be visually detected by occupants if

hey recognise that the blue light on the device (which indi- ates it is listening for voice input).

In 2016, research carried out in Carlini et al. (2016) demon- trated how hidden voice commands can be carried out on ersonal assistants and a range of smart device with voice- ontrolled applications. The researchers were able to gener- te voice commands, unintelligible to human listeners, but nterpretable by voice-controlled speech recognition systems n smart devices. Using a black box model, they were able o obfuscate commands with an audio mangler and using el-Frequency Cepstrum transformation, without any under-

tanding of the target system’s configuration (in this case, he Google Nows speech recognition system). For phrases “Ok oogle” and “Turn airplane mode on”, the Google system was ble to interpret with 95% and 45% accuracy respectively, com- ared to human transcribers’ 22% and 24%. In the case of a hite box approach, where an attacker has full knowledge f the internals of the speech recognition system, utilising a idden Markov model (HMM), the researchers generated a tar- et audio phrase derived as a sequence of HMM states com- ressed by minimising the number of speech frames. Their esting showed that a speech recognition system targeted CMU Sphinx) accurately interpreted 82% of obfuscated com-

ands, compared to 0% for human transcribers.

.4.3. S1-IR: infrared he broad range of infrared applications varies from commu- ication between home appliances (IR remote), distance mea- uring or medical equipment such as medical fusion pumps Park et al., 2016 ), where researchers have used an exter- al infrared transmitter to alter medication dosage. Recent ork carried out by researchers at Ben-Gurion University has

ices, which in turn initiates the call (also using text-to-speech to xfiltrate sensitive information)

t S

emonstrated how CCTV security cameras with infrared func- ionality can be used as a data exfiltration medium to export ata from a compromised device in an air-gapped network Guri et al., 2017 ). Here, the researchers blink infrared LEDs n a morse-code-like pattern to transmit binary data to a re- eiver over a distance of tens of meters. The attack functions y utilising the infrared light as a sensory that can be en- oded and decoded to exchange data. By employing basic “on- ff keying”, binary frequency-shift keying and amplitude-shift eying modulation techniques, the researchers have demon- trated that the absence/presence of a signal, the frequency f change and the illumination of the light can be used to enerate a bit datastream for infiltration (e.g., command and ontrol) or exfiltration of data, respectively.The attack posi- ions smart IR-enabled CCTV smart platforms as viable attack ectors for steal sensitive data from a compromised smart ome network. The researchers have also highlighted that the ame vulnerabilities are likely to exist with doorbell cameras quipped with IR LEDs, which are typically installed (unlike CTV cameras) at locations and heights which provide easier

ine of sight for an attacker to exchange data via IR signals.

.5. S2: supply chain

he extreme diversity between devices, actuators and sen- ors, as well as control software and third-party applications eans that the smart home is particularly vulnerable to a sup-

ly chain attack. Here, were refer to the supply chain as ex- loitation of the method of distribution and delivery of hard- are and/or software components for devices in the smart ome, whereby the supply chain positions an attacker to em- ed malware, gain control of, or sabotage these devices and

nterdependent systems in the household. As an example, the econd-hand sale of smart home technology in popular on- ine marketplaces such as Amazon and Ebay allows provides n ideal supply chain for threat actors to distribute malware- nfected products.

.5.1. S2-S: software n 2014, a cyber espionage grouped named DragonFly target- ng supply chains in industrial control software suppliers were ound to be replacing legitimate files in suppliers’ software istribution websites with their own malware-infected ver- ions of the software ( CERT-UK, 2015 ). Specifically, the attack- rs “trojanised” existing, legitimate industrial control system ICS) software by first compromising the website of the soft- are suppliers and replacing the existing ICS software with alware-infected versions allowing remote access. In smart

ome platforms, this attack targets a legitimate and trusted oftware supply chain for household devices (e.g., providing rmware, operating system or third-party software). A com- romise of the software supply chain may result in subse- uent attacks on smart home devices control software as a esult of installing compromised software (see Section 4.2 ).

Software supply chain threats can also be observed hrough the side-loading of malicious applications on smart- hones and tablets, where such devices are often applica- ion control hubs for smart home automation and control. ide-loading involves the installation of an application on a

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 409

smart device outside of the security of a monitored applica- tion marketplace (e.g., Google Play, Apple App Store), where the integrity of the software supplier cannot be verified. This may involve downloading an application via a URL or adver- tisement hosted on a website or presented through another app that is being used. In 2016, a remote access Trojan called DroidJack posing as the popular android application Pokemon Go was identified by security company Proofpoint. At the time of discovery, Pokemon Go was not available in specific coun- tries, whereby the Trojan APK seemingly offered the appli- cation unofficially via a side-loading installation ( Proofpoint, 2016 ). On installation, in addition to standard Pokemon Go per- missions, DroidJack would additionally request access to read web history, change network connectivity, directly call phone numbers, edit text messages, record audio, modify contacts, as well as retrieve apps running at startup. This would effec- tively grant the malware complete control over the Android device, and as a result of any smart home devices controlled by it. Inspection by analysts showed that three classes had been added in the Trojanised app, with one of them creating a chan- nel to a hardcoded command and control domain and port.

For smart homes, the software supply chain is particu- larly vulnerable to audio/video streaming in social media plat- forms, such as YouTube, where the provenance of data is of- ten unknown and can be uploaded by any user. Here, voice- controlled systems are specifically targeted with the aim to make speaker-equipped household devices play malicious au- dio supplied through these services, as exemplified by re- cent YouTube adverts and Television shows triggering home automation systems ( Engadget, 2017; Morley, 2017 ). The me- dia hosting entity in the software supply chain host can be trusted, such as YouTube, or untrusted, such as illegal stream- ing websites.

4.5.2. S2-H: hardware Supply chain attacks on hardware include physical damage or tampering of system components used in the construction of IoT devices (such as memory, wireless antennas, interface buses, firmware etc.) or devices that have been intercepted by attackers and compromised. The latter can involve sabotaging the integrity of an internal component or inserting malicious implants, so as to provide the attacker some form of control of the system when activated ( Miller, 2013 ).

4.6. S3: side-channel

Side-channel attacks are a well-studied area of research in computer security, especially in the field of cryptography for attempting to gain knowledge about a system based on elec- tromagnetic emanations from its hardware. Such knowledge, such as frequency spectrum, power fluctuations and elec- tromagnetic interference provide insight into the state of a system or the function it is performing. Side-channel at- tacks can also use modules present on modern processors to create covert communication channels. Evtyushkin and Ponomarev (2016) have used a hardware random number gen- eration module that operates across CPU cores and virtual ma- chines, to construct a covert channel with a capacity of up to 200 kbit/s. Although the capacity depends on the system’s load, the approach results in a reliable and low-error channel.

An approach that can exfiltrate data from air-gapped comput- ers without audio hardware and speakers has been presented in Guri et al. (2016) . The proposed approach uses noises emit- ted by the CPU and chassis fans, and controls the acoustic signals they produce using a specialised software. The binary data produced are then transmitted to a nearby mobile phone. The method achieved a transmission rate of 900 bits/hour and the authors demonstrated that it can also be used for IoT de- vices that contain fans of various sizes. In the following sec- tions, we further elaborate on the side-channel attacks related to electromagnetic emanations and interference, as these are more closely related to the context of a smart home.

4.6.1. S3-EMA (electromagnetic emanations) Here, an example would be the electromagnetic emanations leaking from unfiltered powerlines. Enev et al. (2011) have demonstrated the viability of measuring a home’s powerline activity with such accuracy that they could identify what the occupants were watching on television. Their method was re- producible and accurate enough across a wide range of mod- ern television sets.

4.6.2. S3-EMI (electromagnetic interference) Instead of passive eavesdropping emanations to elicit infor- mation from a system, electromagnetic interference is either an intentional or unintentional threat which disturbs the cor- rect operation of a system. In the smart home, it has the poten- tial to damage consumer electronics attached to the power- line or used within a directional electromagnetic antenna and has been used as an attack vector in multiple real-world cases associated to robbery and causing criminal damage ( Sabath, 2011; 2012 ). Kune et al. (2013) have demonstrated experimen- tally that at certain distances electronic devices containing microphones are vulnerable to injection of rogue radio signals.

5. Impact on systems

A primary consideration in proposing this taxonomy is the na- ture of impact that different cyber and cyber-physical attacks can have on the occupants of a smart home. Here, we follow the terminology introduced in Loukas (2015) , where a cyber- physical attack is defined as a “security breach in cyber space, which adversely affects physical space, leading to breach of physical privacy, unauthorised actuation, incorrect actuation, delayed actuation or prevented actuation, as summarised in Table 2 and illustrated as to their taxonomic categorisation in Figure 3 .

In terms of cyber impact, we adopt the standard CIA triad of confidentiality, integrity, availability and include a further property of non-repudiation. This is not exhaustive, as au- thenticity and other extensions of the CIA triad can be consid- ered, but we argue that the four chosen are of relatively higher priority in a smart home context.

5.1. Physical impact

5.1.1. P-BPP: breach of physical privacy While in the traditional grid, energy consumption informa- tion is collected once a month, the use of smart meters al- lows frequent energy consumption reporting, typically in 15

410 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

Table 2 – Definitions of physical impact on systems.

Physical impact Definition

Breach of physical privacy Be watched, listened to, or recorded against one’s wishes ( Moreham, 2014 ) Unauthorised actuation Actuation initiated without the approval of an authorised user ( Loukas, 2015 ) Incorrect actuation Actuation not as required by authorised user ( Loukas, 2015 ) Delayed actuation Actuation initiated or completed later than desired by authorised user ( Loukas, 2015 ) Prevented actuation Authorised user unable to initiate desired actuation ( Loukas, 2015 )

Fig. 3 – Impact on system’s taxonomy criteria.

o e v a l

a i c b A l

t p n a o i s t “ c s n c d t

t m p

a M

5 A t e G s i s m t e

5 A c s A c o a t s e B

t t a p t o n t a o c i

5 A n m Z h a a

r 30-min intervals. The transmission of highly granular en- rgy data leads to the risk of eavesdropping attacks targeting aluable physical privacy information about the presence of household’s occupants at a particular point in time or their ifestyles in the longer term ( Ghansah, 2009 ).

An attack demonstrated by Veracode demonstrated the bility to breach physical privacy in a household by hijack- ng the Wink Relay touch-enabled controller to turn on its mi- rophone and record audio in a household. Here, privacy is reached through audio means, by taking advantage of the ndroid Debug Bridge (ADB) ( Singh and Singh, 2015 ). ADB was

ater disabled by the vendor in a subsequent software update. Increasingly, smart home devices come equipped with In-

ernet access which are left poorly secured and as a result ex- ose vulnerabilities over physical privacy. For example, Inter- et device scanning search engines (such as Shodan), allow ttackers to identify open ports of nodes, indexing the header r banner information of responsive nodes; which can include

nformation such device type, model, vendor, firmware ver- ion other open protocols. As Lin and Bergmann have iden- ified in Lin and Bergmann (2016) , simple queries such as has_screenshot:true port:554” on Shodan returns a list of ameras, their IP addresses, geographic location and captured creen-shots. More often than not, results include both inter- al and external home surveillance systems; granting mali- ious actors remote visibility over everything (including other evices which could be used for further, lateral intrusion) in he smart home.

Real-world threats to smart home privacy have been ma- erially observed in recent vulnerabilities in home video baby-

onitor devices. Over the past three years, a number of re- orts have identified vulnerable baby monitor cameras, which

llowed perpetrators to visually spy on children ( Albrecht and cintyre, 2015; Independent, 2016; Mirror, 2014 ).

.1.2. P-UA: unauthorised actuation ny attack leading to the hijacking of a smart home’s actua-

ion commands could lead to unauthorised actuation. Here, an xample would be the unlocking of a smart lock ( Fouladi and hanoun, 2013; Technology, 2016 ), as well as the unauthorised witching on or off of lights, heating, ventilation, air condition- ng, etc. A network traversal vulnerability discovered in WeMo mart home devices provided attackers with the ability to re- ote connect and execute commands that would allow them

o be utilise in a botnet or to cause physical damage such as lectrical faults.

.1.3. P-IA: incorrect actuation t small scale, a simple related attack would be one that would ontinuously increase the temperature readings of a thermo- tat, forcing it to keep lowering the temperature in the rooms. t much larger scale, cyber attacks against smart homes at ommunity level could cause large-area power system black- uts through cascading effects. Liu et al. (2016) have studied nalytically and via simulation adversarial cases, where an at- acker manipulates the electricity price to overload transmis- ion lines by forming peak energy loads, or increases the en- rgy load’s fluctuation to disturb the power system dynamics. oth lead to cascading outages in the power grid.

Incorrect actuation can also occur as a result of “uninten- ional actuation”, that is, actuation executed as a result of au- omatic functionality configured through a users smart home ppliance. For example, in Ho et al. (2016) the researchers ex- lain how the August and Danalock smart lock appliances au- omatically unlock the doors they are connected to when the ccupier (with the smartphone app and a Bluetooth BLE con- ectivity) is within a 50m radius. However, these locks assume

hat occupants always enters and leaves via the same door nd therefore automatically unlocks the same door when the ccupant is within the BLE connectivity radius. In shared ac- ommodation or areas with high crime rates such behaviour s highly undesirable.

.1.4. P-DA: delayed actuation ttacks affecting the availability of a smart home’s commu- ication network can lead to delayed transmission of com- ands and consequently delayed actuation. The smart home

igBee sinkhole attack in Coppolino et al. (2015) demonstrated ow a rogue node can advertise itself as a favourable route to ZigBee controller, whereby ZigBee sensors (containing actu- tion commands) which utilise the rogue node for data trans-

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 411

port may result in a delayed actuation if the rogue node drop or manipulates the data.

5.1.5. P-PA: prevented actuation One popular feature provided by smart home technology providers is vacation mode, typically involving turning on and off of lights and other devices, so as to create the impres- sion that the occupants are in while they are away. Fernandes et al. (2016) have proposed a “disabling vacation mode” at- tack, where their own SmartApp interferes with the occu- pancy simulation by raising a false mode change event. This prevents the actuation expected by the occupants while they are away.

5.2. Cyber impact

5.2.1. C-C: confidentiality Here, an example is the door lock pin code snooping attack demonstrated in Fernandes et al. (2016) . In their proof of con- cept implementation, the authors have developed a battery monitor SmartApp , which exploits an over-privilege issue in Samsung’s SmartThings environment, to view plain text pin codes and leak them via a short message service (SMS) mes- sage. Unauthorised access to this information would likely lead to unauthorised physical actuation as a second-order physical effect (P-UA).

5.2.2. C-I: integrity Breaching the integrity of data or a service is a common route for a cyber-physical attack targeting actuation. In that sense, most cyber security breaches in a smart home will involve some form of unauthorised manipulation of data. An interest- ing early example would be the malware infections caused by digital photo frames reported in 2009 ( Tarala, 2009 ). The infec- tion would occur when some of these devices were connected to a computer via USB to load new photos. In 2014, a large scale phishing attack discovered was discovered by Proofpoint (2014b) , where it was found that source-addresses of phishing messages included smart home appliances such as internet- connected fridges, where it was surmised that these devices were likely used as message relays/proxies for forwarding the malicious emails which is a common practice in obfuscating the source of a phishing campaign.

5.2.3. C-A: availability Common examples of availability attacks are denial of service and jamming. In a Wi-Fi based smart home, denial of service would involve first gain access to the home network and then flooding with meaningless network traffic its smart devices, such as security cameras, rendering them unable to receive commands or transmit data. Communication jamming has also been studied extensively for some of the main communi- cation protocols used in smart homes. For example, Jokar et al. (2011) have demonstrated wide-band denial, pulse denial and jamming designed specifically for IEEE 802.15.4, which is the basis for ZigBee.

An major threat to the cloud-supported availability of the smart home was exemplified by a major Amazon Web Services outage on February 27th 2017, for which many IoT smart home vendors rely on for cloud services. The outage of the AWS S3

storage platform resulted in multiple vendors system going down and a many reports from smart home occupants claim- ing that they were unable to turn off appliances such as WiFi connected ovens, alarms and loss of functionality for physical security appliances and multimedia systems ( Hindi, 2017 ).

5.2.4. C-NP: non-repudiation Within the smart home, non-repudiation is associated to an occupant’s ability to provide evidence that distinguishes le- gitimate computer activity generated by themselves or fellow occupants and activity which has been executed by a ma- licious actor. Here, examples include a compromised smart meter which increases the energy consumption ( Partners, 2016b ) and rogue payments through home assistants using audio-based attack vectors ( Morley, 2017 ). Future risks may well include compromised devices (such as smart fridges, Exploiteers, 2017 ), which are under the command and control of a botnet ( Proofpoint, 2014a ) or used as message relays for attack communications.

6. Impact on domestic life

We have proposed a number of potential attack vectors and associated physical and cyber impacts, which almost certainly have wider applicability beyond the scope and context of the smart home (e.g., smart city, hospital, school, warehouse etc.). However, another primary motivation for this taxonomy is to identify specifically how such threats, within the unique smart home setting, directly affect domestic life.

Smart home environments aiming to enhance home secu- rity ( Robles et al., 2010 ), well-being, especially for the elderly and disabled ( Demiris and Hensel, 2008; Domingo, 2012; Lei- jdekkers et al., 2007 ), energy efficiency and financial savings ( Jahn et al., 2010 ), and enable greater workspace and voca- tional flexibility, are expected to provide a significant positive impact to domestic life. Paradoxically, by merging cyber and physical worlds, they introduce new threats to each of these aspects. As a result, confidence in smart home technologies and consequently their adoption is undermined where cyber security is not proportionate to realistic threats to home se- curity, well-being, energy efficiency, household finances and vocational flexibility. Figure 4 illustrates the taxonomic cate- gorisation of impact on domestic life.

6.1. DC: direct consequences

Cyber attacks aim to interfere with the usage of devices or services that are provided to the user, where the effects can have direct and possibly long term consequences on the users life. One of the most common consequences, and indeed pur- poses, is related to financial aspects of a successful attack. For example, ransomware ( Guardian, 2017 ) limits a user’s ability to use devices or services that are targeted in the attack un- til they pay a required amount. Targets for this type of at- tacks are most often companies, but attacks on homes may increase significantly. Possibilities of threats and actual at- tacks make the home an unsafe environment that can effect a users well-being. cyber attacks can be aimed toward users health, physical health through interference with implantable

412 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

Fig. 4 – Impact on domestic life taxonomy criteria.

a c o b O 2

6 F c b m a c

t t t t r a e a t

6 O a p o t r i

c o e a F b v t l p b d a t

c h i t w h

6

H t f U t p p i

nd wearable medical devices ( Center, 2016 ), and toward psy- hological well-being. Intrusion to a user’s home in the form f different cyber attacks can affect their psychological well- eing through decreased privacy ( Lombardi and Ciceri, 2016; ulasvirta et al., 2012 ), loss of control ( Infurna and Gerstorf, 013; Owusu-Ansah, 2008 ) and inconvenience.

.1.1. DC-F: financial inancial loss due to the cyber attack of IoT devices at home an be consequence of a burglary, increase of the household ills, malware infection of the user’s software, possible black- ails after spying household members or children, access to

bank account, malfunction of devices or usage of a user’s onfidential information for making unauthorised purchases.

PenTest Partners developed the first Ransomware for smart hermostats that effectively gives an attacker to control the emperature of a household ( Partners, 2016b ). By exploiting he Adobe Air package contained in the system files of the hermostats linux image, the researchers were able to gain oot access to activate the heating and cooling in a household t the same time; wasting lots of power and increasing the en- rgy bills of the homeowner. At the same time they were then ble to lock users out of the thermostat by applying a pin to he device.

.1.2. DC-V: vocational ver the past few decades, the increase in technology avail- bility in the home has enabled it to become an increasingly roductive environment for remote working. For example, the ffice for national statistics in the UK reported that from 1998 o 2014, the proportion of people working from home in the UK ose from 2.9 million to 4.9 million ( statistics, 2014 ). However, ncrease in home working and the advancement of ubiquitous

onnectivity in the household is symptomatically increasing rganisations’ exposure to cyber threats which users are not quipped to mitigate; especially if organisations rely solely on locked-down laptop and VPN software or router for defence. or instance, it is common practice for employees to discuss usiness matters and share company information and data by oice or video (e.g., conference calls), which may be confiden- ial. In the past, threats to this communication medium were ow as only very targeted attacks (such as physical bugging) osed a risk. In the smart home, this information may now e picked up more easily by exploiting poorly protected IoT evices with built-in microphone systems, such as personal ssistant services (e.g., Google Home, Amazon Echo), children oys and other voice-controlled house-hold appliances.

Using a different perspective outside of cyber risk, an arti- le by Digitist magazine ( Boitnott, 2016 ) considered the smart ome as an environment that may begin to have an adverse

mpact on employee productivity due to constant interrup- ions by smart devices and their activity within the household; hich in turn could force organisations away from popular ome working models.

.2. DC-S: health and safety

ere, we refer to impact on physical health rather than emo- ional health. In one of the first security analyses published or smart lights ( Oluwafemi et al., 2013 ), researchers from the niversity of Washington investigated whether it is possible

o cause physical harm in an exploited smart home. Their hy- othesis was that one avenue for this would be to cause com- act fluorescent lamps to explode. Although three of the 10

n their experiments did explode, the effect was not signifi-

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 413

cant. It was perhaps more significant that by taking control of the lamps, they were also able to produce fluctuations at an appropriate frequency to induce seizures, which would be harmful to occupants suffering from epilepsy. This is not an attack that can be discarded as unrealistic. There has been at least one case of a real-world security breach that had such aim (albeit not in the context of a smart home). In 2008, the website of not-for-profit Epilepsy Foundations website was de- faced, introducing flashing animations chosen to cause mi- graines or seizures to visitors that suffer from epilepsy. At least some of the visitors were affected ( Poulsen, 2008 ). Also, more recently, a journalist known to suffer from epilepsy received a twitter message reading “You deserve a seizure for your posts” along with an animated image showing a blinding strobe light, which did in fact cause him a seizure. The person behind the message was arrested a few months later ( Kang, 2017 ).

More recently, household gas cookers have been released with WiFi connectivity that allows for remotely control of the oven with the physical presence of occupants; through the use of an Android application that even includes a chat function ( Samsung, 2017 ). Although there have been no examples of ex- ploitation to date, the security of the oven is underpinned by both the protection of the mobile application and WiFi envi- ronment in which it has been employed. Were such a device to be successfully exploited, the physical consequences could be severe.

6.2.1. DC-P: invasion of privacy As complementary to cyber impact through loss of confiden- tiality (IS-C-C) and physical impact through a breach of physi- cal privacy (IS-P-BPP), here we focus on impact to privacy from the psychological perspective; that is, the regulated activity carried out by an occupant experiencing a violation of pri- vacy with respect to psychological dimensions of privacy (soli- tude, reserve, isolation, anonymity, intimacy) ( Pedersen, 1999 ). Apart from the obvious threat of breaching physical privacy by physical means, an invasion of privacy would occur when an unauthorised party received unacceptable or inappropri- ate access to someones personal information ( Marshall, 1972 ). In 2012, empirical research carried out by Oulasvirta et al. (2012) demonstrated that breaching the psychological dimen- sions of privacy causes annoyance, concern, anxiety and even rage for household occupants. Focusing on continuous video surveillance within homes, the researchers found that the potential of invasion of these dimensions of privacy through video surveillance causes noticeable changes in the behaviour of the participants. Participants were consistently aware of the surveillance and exhibited privacy-seeking behaviour through ceasing specific behaviour completely, hiding, acting privately and manipulating sensors, as well as changing their practices to actively avoid surveillance (e.g., meeting outside the home for private conversations). This kind of behaviour is expected for occupants of a smart home who perceive that their phys- ical privacy may be breached through a compromised IoT de- vice that captures audio or video. Early examples of real world compromise have been reported for Internet-connected baby monitors ( Mirror, 2014 ). However, as IoT devices through sens- ing and actuation continue to augment domestic life, such as tracking occupant activity (e.g., from taking a shower to cooking and evening meal or sleeping), an invasion of pri-

vacy extends to recording daily life, habitual schedules and activity recognition. Whilst experimental results for video surveillance in the home provide early indications of occupant behaviour when there is a noticeable invasion of privacy, un- derstanding how occupants will respond to a realisation that they are being observed in data through a compromised smart home meter, light bulb, scale or TV is an important challenge.

6.2.2. DC-LC: loss of control Control over devices is one of the purposes of the usage of the IoT devices, and it could be taken away through different forms of cyber attacks. Loss of control is manifested through taking control away from a user where third party gains par- tial or complete control and access over user’s IoT devices and household. Loss of the control over the situation can be per- ceived as threatening while increases in perception of con- trol are associated with better physical health, greater social support, self-acceptance, a sense of purpose in life, auton- omy, mastery, growth and positive relationships and a general sense of satisfaction with the quality of ones life and general wellbeing ( Owusu-Ansah, 2008 ). An example of the cyber at- tack with control loss can be random triggering alarms in the users or activation of different IoT devices with a goal of cre- ating fearful and threatening situation.

6.2.3. DC-I: inconvenience One of the most obvious direct consequences of cyber attacks is inconvenience caused by interruption of functionality of IoT devices in the situations when users expect to rely on them. It can be manifested through time consuming as op- posed to time saving that should be one of the benefits of us- age of the IoT devices. Programmed morning routines with the purpose of saving time (alarm clock, preparing coffee, heating the home, closing the garage or entrance doors) can easily be- come an additional task for users if they have to deal with de- lay, malfunctioning or failure of the programmed IoT devices ( Hindi, 2017 ). Instead of enjoying initially desired automation of everyday functions users can face the opposite outcome if their devices are attacked.

6.3. UX: user experience

The degree by which a cyber attack in the smart home is visi- ble to household occupants depends on its immediate or long term effects on the user experience of systems which have been affected. For example, attacks that are noticeable in the moment of the execution (by activation of different devices, Cluley, 2014 , jamming of traffic, Jokar and Leung, 2016 , or re- sulting in the loss of control over devices, Partners, 2016b ) can immediately activate occupants’ awareness that their house- hold may be under attack. On the other hand, some cyber attacks are more discreet in execution, such as providing a back-door to control devices ( CERT, 2014 ) or to conduct recog- naissance ( Shipley, 2015 ), which may not be immediately obvi- ous to occupants until a such time that they observe anoma- lous system behaviour, or never at all if the attack does not impact or alter system functionality and performance.

Users of IoT devices are often unaware of cyber at- tacks or when their devices are used for malicious purposes ( Symantec, 2017 ), which leads to a lack of action and decreases

414 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

a f

6 A v v b n s r g n e e S

6 C a t r m s l 2 b i w o

6 I o t t n ( s f

t a v h p b t

6

T v a l s s a h

a c b e t d c i ( p s t t b t t a

c a t g a c t o a y a o o b n q d c r c o c p f b n t

s t t t s t o e a c t c a

ctions of prevention as well (especially where technical de- ences are unable address such threats).

.3.1. UX-N1: instantly noticeable s occupants of the smart home begin to rely on smart de- ices and systems for every day tasks, disruption to the ser- ices can indicate either a malfunction or also a potential cy- er threat. In both cases, household users may immediately otice degradation of performance, such as decreased respon- iveness of IoT devices, delayed, prevented actuation, incor- ect or unauthorised activation of alarms, garage doors etc. In eneral, an attack in the household that would be instantly oticeable is an attack where the user notices that they have ither lost control of their household devices or that someone lse is controlling them as well ( CERT, 2014; Partners, 2016b; ingh and Singh, 2015 ).

.3.2. UX-N2: noticeable over time ertain attacks against the smart home do not generate cyber nd/or physical impact which is immediately obvious or no- iceable by a user. For example, where an attacker has gained emote access to a system such as security camera or baby

onitor unless the occupant is actively trying to access the ystem at the same time they may be unaware some else is ogged in and viewing the video feed ( Albrecht and Mcintyre, 015 ). However, over a period of time, behaviours exhibited y targeted systems or second-order symptoms observed in nterdependent platforms may generate a visible footprint in

hich household users become aware that an exploitation has ccurred or is indeed still on-going.

.3.3. UX-NN: not noticeable n the case where an attack is not noticeable by household ccupants, attack vectors tend to focus on gaining persis- ent remote access (rather than denying a system) in order o conduct further reconnaissance, such as penetrating the etwork further through lateral movement into other devices Wakefield, 2014 ) or to gain passive control over household ystems as a means to launch external attacks on other plat- orms; building a botnet of smart devices ( CERT, 2014 ).

In general, more often than not, users are not aware that heir IoT devices are being attacked, irrespective of whether n attack exhibits anomalous behaviours that are visibly ob- ious. Nevertheless, attacks that are able to infiltrate the smart ome without exhibiting noticeable signs to household occu- ants pose a significant threat to occupants safety and well- eing; especially if technical defences are also unable to detect hem.

.4. E: emotional

he home is meant to be a safe haven to experience pri- acy, control and personal autonomy. A cyberspace violation ffecting a smart home may thus lead to considerable and ong-lasting emotional impact. Attacks may even be designed pecifically to cause the occupant to experience high levels of tress and discomfort, for example by triggering fake alarms, s demonstrated in Fernandes et al. (2016) , where the authors ave shown how to raise fake physical device events, such

p

s the report of increased levels of carbon monoxide. In a re- ent occurrence, the hijacking of an Internet-connected teddy ear resulted in two million voice recordings between par- nts and children being made publicly available on the in- ernet ( Franceeschi-Bicchierai, 2017 ). Further, Pentest Partners emonstrated how it is possible to gain complete root ac- ess to an Internet-enabled adult sex toy, capturing stream- ng video from the device and changing its configuration Partners, 2017 ). In both cases, access to such sensitive and rivate information leads to significant emotional impact and econd order threats, from blackmailing, publicly shaming on he Internet, damaging a persons reputation, or gaining access o other systems the occupants may use in the household (e.g., y stealing Wi-Fi passwords). In fact, eliciting a particular emo- ional response from a household occupant, with or without heir knowledge, can be used as part of a social engineering ttack ( Heartfield and Loukas, 2016 ).

More generally, emotional distress as a consequence of a yber attack is related to personal sense of the loss of control nd privacy, a decreased ability to function on a daily basis, o work, and even long-lasting deleterious financial and le- al consequences. The realisation that one is a victim of such n attack, specifically targeting the intimacy of one’s home, an trigger an emotional experience akin to physical abuse, in he process also leading to lower trust levels in IoT technol- gy. Further, such emotional consequences are likely to be felt nd re-lived over significant periods of times, over months or ears. Once an occupant realises they have been a victim of n attack and progressively acquires the full understanding f the consequences, it is likely they will experience relapses f related emotional events, affecting their personal well- eing and recovering process, and will have to engage in re- ewed coping strategies, to mitigate such emotional conse- uences. Whereas there is no theoretical framework that fully escribes the emotional engagement of IoT users, a signifi- ant understanding, we posit, can be gained by drawing inspi- ation from emotional psychology. An emotional experience an be measured and compared, and serve in the elaboration f user models and the prediction of behaviour. Communities, omprising cyber-security specialists, industrial interests and olicy makers, can benefit from this information to delineate eatures and courses of conduct that will place the user’s well- eing at the centre of the design of IoT and smart home tech- ology, as well as to help formulate training to condition emo- ional responses as result of suspected or realised attacks.

An emotional experience is best described over time at the pecific granularity that pertains to the aspects that one seeks o exemplify ( Scherer, 2000 ): In other words, emotional reac- ions will vary in duration and amplitude, function to con- extual and personal aspects. Following a smart home cyber ecurity incident, the immediate aftermath is the realisation hat an attack has occurred, and gradually becoming aware f its consequences, as victims evaluate dimensions of the vent against their personal belief system and core person- lity. In the longer term, the user reacts and copes with the onsequences, involving a series of emotional states in rela- ion to the recovering process. Whereas the long term scale orresponds to broader emotional experiences, the immediate ftermath relates to the evaluative processes that support the ersonal understanding of the event by the user. Importantly,

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 415

evaluative processes both drive the amplitude of the experi- ence over time and determine the emotions perceived, such as anger and irritation ( Scherer, 2001 ), that is the valenced re- actions that ensue. In addition to evaluative processes, emo- tional reactions typically comprise reactions in four other sys- tems, action tendencies, bodily reactions, expression and sub- jective feeling, which can also be measured. Activation in all five systems determine the shape, content and intensity of emotional experience ( Scherer, 2000 ).

6.4.1. E-A: appraisal Evaluative processes following a smart home cyber security breach are most likely to engage strongly dimensions about familiarity, privacy, coping resources and power ( Budimir and Fontaine, 2017 ). The same attack can be appraised differently by different persons, depending on personality ( van de Wei- jer and Leukfeldt, 2017 ), expectations and level of knowledge about risks and the consequences of the breached security ( Beris et al., 2015 ). The ensuing emotion process depends on the precise appraisal that is made by the person. In the case of a man-in-the-middle media injection attack on a smart TV ( Jacoby, 2014 ), a user becomes instantly aware that a smart TV is controlled by a third-party. While the attacker is controlling the changing of videos, content images, links or audio files, the user will realise that their device is hijacked and begin to think about how to stop exposure to unwanted content. This is es- pecially the case if the content is not appropriate for children, or if it is harmful for the user (e.g., videos that cause epilep- tic seizures). Appraisal actions here can lead to thoughts about invaded privacy, loss of control, about who is behind the attack and whether the attack is aimed specifically at the victim or if it is random. Instead of immediate action, here different ap- praisals may inadvertently increase an occupant’s exposure to the attacker by leading them to an evaluative state that does not result in a direct mitigating action (e.g., by removing de- vice network connectivity to disrupt attacker control).

6.4.2. E-AT: action tendencies Action tendencies are tendencies to behave in certain ways that are elicited by the emotion process ( Fontaine et al., 2013 ). Experience of the attack can range from having a desire to es- cape from the situation and to stop using devices, to investing all effort into solving the problem that occurred ( Budimir and Fontaine, 2017 ). Beris et al. (2015) have shown that depend- ing on risk perception and emotional stance toward breached security, a range of different tendencies to act can occur. Cate- gorisation of different attitudes and behaviours could be used to predict which members of the household are the “weak- est links” and, with their attitude towards IoT devices increase the home’s cyber risk, and as a result need education or train- ing. Intrusion in the private life and space can make people ready to defend their privacy with any available means. Acting from emotional affect is known to bring intensive reactions of fighting for the justice, especially when anger and fear are ex- perienced ( Dippong and Fitch, 2017; Sherman and Hoffmann, 2007 ). Dramatic cybercrime consequences, in the form of sui- cide, are found at both ends, attackers side ( Bankoff, 2013 ) as well as the victim’s side ( Malm, 2015 ). Ambiguous and geo- graphically diverse legislation for cyber crime ( Oh and Lee,

2014 ) has its share in expectancy, predictability and differ- ences in behavioural outcomes related to cyber attacks.

6.4.3. E-B: bodily symptoms Possible bodily symptoms ( Fontaine et al., 2013 ) during a cy- ber attack can include hyperventilation, blood pressure and heart beat increases ( Budimir and Fontaine, 2017 ). An inter- esting recent example of related research is the experiment carried out by Canetti et al. (2017) , which used salivary cortisol as a measure of the stress caused, to show that cyber attacks make people more likely to express threat perceptions. The intensity of bodily reactions as a result of cyber attack events depends on initial psychological and physical condition of the users, as well as the level of integration and dependency oc- cupants place on smart home systems. Symptoms can also depend on the nature of the cyber attack, and if it was espe- cially aimed to harm a users health. Direct intention to harm a specific person was shown in the case of an epileptic jour- nalist who suffered a seizure after viewing an image that was sent purposely to him, with the intention of causing seizure, as a punishment for his online posts ( Kang, 2017 ).

6.4.4. E-EX: expression Possible emotional reactions ( Fontaine et al., 2013 ) could range from a hopeless expressionless reaction to shaking, frowning and saying loud angry words ( Budimir and Fontaine, 2017 ). Individuals differ whether they are emotionally expressive or unexpressive ( Gross et al., 2000 ). Gross and Levenson (1993) showed that emotional expression can be reduced by suppression, but that suppression would not have an effect on a subjective experience of emotion. In the case of an at- tack on the Home assistant audio loop denial of service, a user could repeatedly try to activate the system by using voice com- mands, and experience inconvenience and annoyance with malfunction of the devices by using loud angry words which can further increase stress. Another person would not express their emotions, but that should not be taken as a sign that the person is not experiencing intensive unpleasant emotions.

6.4.5. E-SF: subjective feeling Subjective feeling refers to the subjective experience that characterises the emotion ( Fontaine et al., 2013 ). The situation of being a victim of a cyber attack presents a stressful event for victims who are likely to experience negative feelings such as anger, fear, sadness, insecurity and shame often accompa- nied with the feeling of surprise ( Budimir and Fontaine, 2017 ). In a study on adolescents ( Holfeld and Sukhawathanakul, 2017 ), it was found that those with greater Internet attach- ment were more likely to experience cyber victimisation and greater symptoms of anxiety and depression. With reliance on IoT devices in the home, it is important to take such results into account to develop strategies for decreasing negative im- pacts of attachment to IoT technology and possible emotional difficulties. In the case of hacking of baby monitors, parents experience an intensive fear for the privacy of their child, as well as fear of potential abuse of the observed and recorded material. It will also lead to anger, which in turn can escalate into undesired actions.

416 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

6

6 T s f g i s c o w t h t c e t o r (

m p c c l c p

6 A c s s e p a p o c t

7

I t o t 2 c h

o H n t b l

a v w w a l b m i w t m

c ( s v o e s c d s o i

.5. Emotion regulation and coping

.5.1. ERC-emotional regulation he most prevalent approach to emotion regulation empha- ises reappraisal and suppression ( Gross, 1998 ) as its two dif- erent styles. It includes re-evaluation of the situation with the oal of better coping with it, and it can modify an emotional mpact. In the case of cyber attack in the household, a per- on can realise that impact of the attack is not significant, and hoose to continue as it did not happen. The adaptive aspect f this style is that a person continues as there was no attack, hile the maladaptive aspect can include repetition of the at-

ack as a consequence of the lack of any activity to protect the ousehold. Suppression includes inhibition of expression of

he emotional process ( Gross, 1998 ). which can have benefi- ial impact by decreasing emotional expression and negative motions, but can also stimulate ignorance of the real threats hat would need attention to be prevented. Rumination is an- ther emotion regulation style which includes repetitive and ecurrent focus on the reasons for the situation that occurred Watkins and Baracaia, 2001 ).

After a cyber attack in one’s smart home, emotions can aintain for a while as well as action tendencies that accom-

any them, so feeling of violation, shame, anxiety and anger an persist as well as desire for justice or revenge can oc- ur ( Budimir and Fontaine, 2017 ). Persistence of emotions re- ated to the cyber attack could bring to behaviour that include hanging IoT devices as a result of dissatisfaction with the rotection ( Budimir and Fontaine, 2017 ).

.5.2. ERC-actual behaviour ctual behaviour depends on the context, emotional pro- esses and emotional regulation. In order to know how a per- on actually behaves during and after a cyber attack in the mart home, one needs to know more about behaviour that is motionally driven and more about accompanied emotional rocesses (appraisal of the event, action tendencies, bodily re- ctions, expression, and subjective feeling). The component rocess model offers ( Scherer, 2001; 2005 ) an integrative the- retical frame to understand all phases of the emotional pro- ess and reactions, which are crucial to understand an emo- ional impact of cyber attack on users well-being.

. Taxonomic classification examples

n this section, we provide an example of four hypothetical at- ack scenarios that are practically facilitated by a combination f insecure smart home devices, configurations and automa- ion rules defined by household occupants. We then classify 4 different smart home cyber threats against the taxonomy riteria to identify shared characteristics between threats that elp to identify key areas for developing defences.

For each attack, in Table 3 we provide an overview of tax- nomy classification and in Figs. 5 –7 taxonomic attack graphs. ere, an attack graph represents a time-based model of taxo- omic classification for a smart home attack to establish in-

erdependent attack characteristics and elicit key interactions etween attack vectors and associated impact to help formu-

ate approaches of potential defence. In Table 3 , although we

cknowledge that a becoming aware that one has been the ictim of any of such attacks will elicit an emotional reaction, e provide a prediction as to which emotional components ould be most strongly involved, for attacks that a victim re more likely to perceive as threatening. This distinction al- ows us to distinguish, for instance, attacks that would simply e annoying, e.g. powerline jamming, versus attacks that are ore personal and would thus be more saliant, e.g. baby mon-

tor back-door internet reconnaissance. Whereas the former ould elicit cognitive evaluations and some kind of an emo-

ional expression, the latter attack is likely to include much ore visceral reactions. In each attack graph, we also visually encapsulate spe-

ific classification criteria within three distinct areas of study threat prevent, detection and cyber-physical crime victim upport) to highlight attack characteristics which would pro- ide meaningful information to researchers and developers f technical defences, as well as researchers and practition- rs of behavioural, environmental and emotional psychology cience. For example, in the case of the latter, analysing a spe- ific attacks cyber-physical impact and associated affects on omestic life in the smart home can help to develop under- tanding and processes for supporting victims of these kind f attacks. Below we describe each area of study and provide

ndicative selection criteria within an attack graph:

1. Threat prevention . This is an approach to defence that re- lies on preemptive measures to mitigate threats. Exam- ples include identifying and patching vulnerabilities in de- vices or software, enforcing multi-factor authentication, blocking system actions or responses that are potentially dangerous (this may include potentially danger user ac- tions or automation rules that an occupant is attempting to configure). Typically, threat prevention relies on a robust understanding of the technical security of protocols, soft- ware and hardware devices deployed with a smart home and establishing rules and protections for secure inter- communication.

2. Threat detection. This is a pro-active control in defending against attacks, whereby a crucial component in identi- fying anomalous or known malicious activity pro-actively (for triggering threat prevention mechanisms) is the ability to collect and audit interactions between systems in the household (whether machine-to-machine, or machine-to- human). Here, this relies on being able to measure and analyse the footprint generated by cyber-physical systems in a household for intrusion detection; whereby the aggre- gation of cyber and physical indicators can help establish measurable relationship between attack vectors and their associated impact ( Bezemskij et al., 2016 ).

3. Cyber-physical crime victim support. A successful cyber at- tack in the smart home can have a profound effect on do- mestic life, with direct consequences leading to financial loss, breaches of health and safety, as well as cascading emotional impact seriously impacting occupants physical and psychological well-being. Understanding how differ- ent kinds of cyber and physical impact in a smart home cyber attack affect domestic life, can help to inform the de- velopment of processes and systems for support of such victims.

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 417

Table 3 – Taxonomic classification of smart home cyber threats.

Ref Threat description Attack vector (AV)

Impact on systems (IS)

Impact on domestic life (DC)

Cyber Physical Direct consequences

UX Emotional

Kennedy and Simon (2011)

Power-line device jamming CM-WD-X C-A P-PA DC-LC, DC-I UX-N1 E-A, E-AT, E-Exp

Partners (2016b) Thermostat embedded ransomware and root access

CS-3PA, CS-OS

C-A, C-NP P-UA, P-PA DC-F, DC-S, DC-LC, DC-I

UX-N1 E-A, E-AT, E-B, E-Ex, E-SF

MITRE (2017) Dishwasher web server directory traversal

CS-F C-C, C-A P-UA, P-IA DC-F, DC-S, DC-LC, DC-I

UX-NN -

Wakefield (2014) Lightbulb to Lightbulb WiFi credentials sniffing

CS-WI-W C-C P-BPP DC-F, DC-V DC-LC UX-NN -

Akdemir et al. (2010)

Ultrasonic presence sensor spoofing

S1-U C-I P-IA DC-S, DC-LC UX-N1 E-A, E-AT, E-B, E-Ex, E-S

Albrecht and Mcintyre (2015)

Baby monitor back-door Internet reconnaissance

CM-WI-W, CS-3PA

C-C P-BPP DC-S, DC-LC, DC-I, DC-P

UX-N2 E-A, E-AT, E-B, E-Ex, E-SF

Ho et al. (2016) BLE automated smart lock door opening

CM-WI-B, CS-3PA

C-I P-IA DC-F, DC-S, DC-LC UX-N2 E-A, E-AT, E-B, E-Ex, E-SF

Technology (2016)

Spoofed voice activating smart lock

CM-WI-B, S1-V

C-I P-UA DC-F, DC-S, DC-LC UX-N2 E-A, E-AT, E-B, E-Ex, E-SF

Partners (2016a) Doctored eDoll app apk CS-3PA C-I P-IA DC-F, DC-S, DC-LC UX-N2 E-A, E-AT, E-B, E-Ex, E-SF

Enev et al. (2011) Side-channel power-line data sniffing

S1-EMI C-I P-BPP DC-V,DC-S UX-NN -

Singh and Singh (2015)

Audio eavesdropping through smart hub controller

CS-3PA C-I C-BPP DC-F, DC-V UX-NN -

Shipley (2015) Insteon node ID sniffing CM-WD-I C-C P-BPP DC-LC UX-NN - Tarala (2009) Digital photo frame malware CS-OS C-I P-UA DC-F, DC-LC UX-N2 E-A, E-AT, E-Exp Liu et al. (2016) Smart home power generator

tripping CS-F C-A P-PA DC-F,DC-V,DC-S,

DC-I UX-N1 E-A, E-AT, E-B,

E-Ex, E-SF Brauchli and Li (2015)

Device data/sensor readings exfiltration

CM-WD-D, CS-3PA

C-C P-BPP DC-F, DC-S, DC-LC UX-NN -

DailyMail (2016) Home assistant audio loop denial of service

S1-V C-I P-IA, P-UA DC-LC, DC-I UX-N1 E-A, E-AT, E-B, E-Ex, E-SF

Fernandes et al. (2016)

Smart lock backdoor pin code injection

CS-3PA C-I P-IA DC-F,DC-V,DC-S, DC-I

UX-NN -

Hindi (2017) AWS S3 cloud-service outage denial of service

CS-3PA, CS-OS

C-A P-IA, P-PA DC-S, DC-LC, DC-I UX-N1 E-A, E-AT, E-B, E-Ex, E-SF

Coppolino et al. (2015)

ZigBee sinkhole attack CM-WI-Z1 C-I P-PA, P-DA, IA

DC-LC, DC-I UX-N2 E-A, E-AT, E-Ex

CERT (2014) Remote access for WeMo command and control

CM-WI-W C-I, C-C P-UA, P-PA DC-F,DC-S, DC-LC UX-N2 E-A, E-AT, E-Ex

Jacoby (2014) Man-in-the-middle smart TV injection

CS-3PA C-C, C-I, P-BPP DC-F, DC-I, DC-LC UX-N1 E-A, E-AT, E-B, E-Ex, E-SF

Morley (2017) Rogue payment via audio-triggered home assistant

S1-V C-I P-UA DC-F, DC-LC UX-N2 E-A, E-AT, E-B, E-Ex, E-SF

Tasker (2014) Rogue HomePlug AV network infiltration

CM-WD-H C-C, C-I P-BPP DC-F,DC-LC,DC-S UX-N2 E-A, E-AT, E-B, E-Ex, E-SF

Kitchen and Kinne (2017)

WiFi device de-authentication CM-WI-W, CS-F

C-A, C-I P-PA DC-LC, DC-I UX-N1 E-A, E-AT, E-Ex

Cluley (2014) Workflow automation phishing

CS-3PA, CS-WA

C-A, C-C P-PA DC-LC, DC-I UX-N1 E-A, E-AT, E-B, E-Ex, E-SF

7.1. Second-order threats to smart homes: vulnerabilities in configuration and automation

Following on from the Attack Vector and Impact on Systems cat- egories described in the previous section, here we demon- strate how the combination of different interacting technolo- gies in the smart home can expose further second-order vulnerabilities which manifest as a consequence of automa- tion and system configuration in the smart home.

7.2. Rogue voice-injection actuation

Here we demonstrate the viability of audio sniffing and injec- tion as cyber threat through the Cayla Doll ( Partners, 2016a ). In Fig. 5 , an attacker with local proximity (e.g., 30m depend- ing on equipment) connects to the Cayla Doll ’s open Bluetooth interface (1), activates the microphone function to record oc- cupant conversations (2) (here a comparative approach would be to exploit a compromised Bluetooth enabled device such a

418 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

Fig. 5 – Example of household audio sniffing and injection attack and taxonomic attack graph of rogue voice-injection actuation (arrowhead lines indicate attack impact steps, dashed lines indicate second-order impact facilitated by a previous step in the same category, but not directly caused by it).

s a t a v a f c p t c f b m t a ( (

t a

7

H t a e W s fi t i e t t S

mart phone or tablet the same attack vector exists (2)). The ttacker plays a voice audio file through the Cayla doll (or Blue- ooth smart device) speaker (3) which relays the command via home automation hub (e.g., Amazon Echo), or directly to a oice-controlled actuation/sensing device (4) to execute actu- tion on a sensor - in this case unlocking a smart lock on the ront door when the occupants are not in Lombardi and Ci- eri (2016) . Today, most smart locks require a pin in order to erform locking and unlocking from audio or an app, however he remote audio access provided by the Cayla Doll this pin an recorded when it is used and replayed later to unlock the ront door. Obviously, audio sniffing and rogue injection can e used to conduct a host activities (such as ordering equip- ent from Amazon via the Echo), however here it is the au-

omation configuration within the household the facilities the ttack end-to-end; requiring only a single vulnerable device i.e., Cayla Doll ) to compromise the otherwise secure systems Echo, smart lock etc.). Fig. 5 also shows the respective the at-

s

ack graph taxonomy classification for rogue voice-injection ttack.

.3. WiFi de-authentication (with Evil-Twin)

ere, we describe the execution of a WiFi Evil Twin attack hrough de-authenticating a households WiFi devices. In Fig. 5 , n attacker with local proximity (e.g., 30–100m depending on quipment) scans (1) for WiFi access points using a portable iFi de-authentication device ( Kitchen and Kinne, 2017 ). On

electing a target WiFi access point, (2) the attacker identi- es connected WiFi nodes and targets specific MAC address o de-authenticate from the WiFi access point. On receiv- ng de-authentication requests from the attacker for targeted ndpoints MACs (3), the WiFi access point de-authenticates he endpoints from the WiFi network. At this stage, the at- acker has launched a duplicate access point with a spoofed SID and MAC address of the household WiFi at a greater ignal-strength than the legitiamte household access point

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 419

Fig. 6 – Example of household WiFi de-authentication attack on targeted WiFi endpoints and taxonomic attack graph of household WiFi de-authentication attack (arrowhead lines indicate attack impact steps, dashed lines indicate second-order impact facilitated by a previous step in the same category, but not directly caused by it).

(4), where the de-authenticated endpoints configurations au- tomatically re-connect, but this time to the attacker access point. On connection to the Evil Twin WiFi, the endpoints attempt to conduct a WPA 4-way handshake and inadver- tently reveal the household WiFi password allowing the at- tacker to both sniff all the traffic of the connected end- points, conduct denial of service against them, as well as ac- cess the household WiFi for further exploitation. An alterna- tive, at stage 4, would be to prompt for a password to the Evil Twin WiFi access point where occupants would manu- ally supply the household WiFi password ( Chatzisofroniou, 2016 ). Fig. 6 also shows the respective attack graph taxon- omy classification for the Evil Twin WiFi de-authentication attack.

7.4. Workflow automation phishing

In this attack, we show how a semantic social engineering at- tack ( Heartfield and Loukas, 2016 ) can be used to gain cyber- physical control of a smart home by utilising targeted phishing

e-mails to capture household occupants credentials to wor- fklow automation platforms (note IFTTT is shown here as a hypothetical example, but crucially has been subject to re- lated semantic attacks in 2014, Cluley, 2014 ). Initially an at- tacker will craft a targeted e-mail to an occupant requesting them to reset their IFTTT credentials through a malicious URL (1), which subsequently leads the occupant to a spoofed login webpage for IFTTT (2), assuming the occupant is deceived and enters their credentials they are redirected to the legitimate website whilst at the same time supplying their IFTTT creden- tials to the attacker. The attacker now has access to the occu- pants account in which existing integration with household devices and system is available to the attacker to manipulate, in Fig. 7 we assume that the household have integrated their internal video camera CCTV system (which also has motion detection capabilities). Using this particular scenario, the at- tacker is now free to add an existing trigger event to the cam- era system (3), which sends a picture from the camera to them on activation of the camera’s motion sensor detection. Consid- ering this breach of physical privacy in the household and the

420 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

Fig. 7 – Example of workflow account phishing and injection of automation rules in compromised account and taxonomic attack graph of workflow account phishing and rule injection attack (arrowhead lines indicate attack impact steps, dashed lines indicate second-order impact facilitated by a previous step in the same category, but not directly caused by it).

r s p c e r t a t t

8 t

S a T t h a

d a a l ( m t o t t m t u

a w d t h t o

elative simplicity of executing this semantic attack to gain uch access, the impact can be particular sinister. For exam- le, in this household scenario, were the attacker aiming to apture indecent pictures of children, by accessing the cam- ra system and adjusting the worfklow automation platform ules they are able to forward pictures which may capture ac- ivity of the child living in this household every-time the child ctivates the motion sensor. Fig. 7 also shows the respective he attack graph taxonomy classification for a workflow au- omation phishing attack.

. Defending against cyber-physical threats in he smart home

ecurity in the smart home is quickly becoming a complex nd unique information security challenge in its own right. he emergence of pervasive and heterogeneous machine-

o-machine and human-to-machine connectivity in the ousehold forms a formidable threat landscape that combines ctuators, sensors, computational, electronic and mechanical

evices and humans. So, it is not only the adoption of vulner- ble Internet-connected devices that places the smart home t risk, but also the cyber-physical fusion of previously iso- ated systems, where the effects of an attack in cyberspace e.g., exploiting a smart home device’s cloud service software)

ay now result to impact in physical space (e.g., turning on he cooker’s gas stove) ( Loukas, 2015 ). Although the concept f the smart home is still maturing, sophisticated attack vec- ors have already moved from the research lab environment o real-world deployment ( Proofpoint, 2014a; 2014b ), which

eans that it is now imperative that defenses are developed o protect against attack vectors that would undermine the ptake and practical benefits of smart home technology.

There are many facets of traditional cyber security that pply to the smart home, as well as elements of security hich have much wider application. For example, at an IoT evice level, chipset manufactures have proposed architec- ures ( ARM, 2017; Moran et al., 2018 ) and developed dedicated ardware security modules for secure boot and firmware in-

egrity, authentication and update security ( Digi-Key, 2018 ), all f which are highly applicable to the security of devices in

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 421

smart cities and industrial environments. However, in the con- text of the smart home, defence that relies on hardware mod- ules dedicated to firmware device security can be impracti- cal, as it is primarily a pre-emptive security control by nature, and typically required to be integrated in devices at the de- sign and development stage, thus leaving many existing de- vices in the household without these components vulnerable to attack. Here, our focus is specifically on defences that have been designed for or evaluated specifically on smart homes.

As early as 2000, the concept of securing embedded smart home systems was first explored by Al-Muhtadi et al. (2000) , who introduced a prototype extension of the SESAME (Se- cure European System for Applications in a Multi-vendor En- vironment) security protocol ( McMahon, 1995 ). Their adapted Tiny SESAME system utilised an embedded Java virtual ma- chine module to perform the SESAME protocol’s functions for authentication, authorisation, confidentiality, integrity and access services within resource constrained smart home de- vices. The researchers presented an experimental deploy- ment within a smart home testbed consisting of Tiny SESAME equipped toaster, door, videocassette recorder, alarm system and fridge. However, no actual attacks on the security platform were evaluated to demonstrate its empirical utility.

Naturally, early research on the security of smart homes re- lates to authentication and authorisation. A simple approach implemented by Al-Qutayri et al. (2008) in 2008 requires the user to enter a username and a password, which is sent via SMS to a home server that establishes the authenticity of the user against a database. Then, the home server initiates a session including the phone number that sent the SMS and a randomly generated number which expires after the ses- sion ends. The users are assigned access levels based on their role (e.g., a supervisor can setup accounts for other users), and there is also provision for encryption of the communi- cation between the mobile station and the home server. The same year, Jeong et al. (2008) explored the idea of using low- cost smartcards for authentication, focusing particularly on the challenges posed by smart home devices’ resource restric- tions. What they proposed was a lightweight scheme based on a one-time password protocol and simple operations using one-way hash functions, so as to incur very low computation load. The protocol assumes that a symmetric key is shared be- tween a home gateway server and an integrated authentica- tion server, which sits outside the home network, is trusted by the users and performs authentication, authorisation and ac- counting. Users are authenticated through single-sign-on and can access other home services without additional authenti- cation procedures. The protocol was analysed only theoreti- cally and rather briefly for replay, man-in-the-middle, denial of service and stolen-verifier attacks, and there was no prac- tical implementation or experimental evaluation of its practi- cality.

Chifor et al. (2017) have introduced a lightweight identity stack providing a digital identity to the users and the individ- ual devices. Its purpose is to be integrated in existing oper- ating systems or smart home IoT frameworks. The applica- tion scenario is on a smart home device which is connected to an untrusted Cloud platform and relays input commands to a users smartphone for authorisation. Their work extends the authentication messages of the passwordless “Fast IDen-

tity Online” (FIDO) mode, which was originally designed for smartphones. Some degree of theft resistance is achieved by adding a keep-alive mechanism. The authors ensured that their approach is practical from a network delay perspective by implementing and evaluating it on the open-source Kaa IoT Cloud platform. The delay added for 30 nodes was around 150– 200ms, which should be acceptable for most smart home ap- plications. However, this value did not take into account the time taken by the cryptographic operations running on the devices, as this part of their evaluation was simulated on a desktop device.

Much less lightweight but certainly attractive is the direc- tion of utilising Blockchain technologies to decentralise se- curity measures. While generally very challenging in terms of computational overhead, energy consumption and net- work delays, it has been shown by Dorri et al. (2017) that a lightweight instantiation eliminating the concepts of coins and of Proof of Work can be practical in a smart home. In their proposed system, each smart home is equipped with a “miner” device, which is both powerful and always online, and is re- sponsible for handling all communication within and external to the home. The miner also preserves a private blockchain, which controls and audits communications. Evaluated in sim- ulation, their system appears to introduce only minimal over- head in terms of traffic, processing time and energy consump- tion. Along similar lines, the European project GHOST ( Collen et al., 2018 ) proposes a defence infrastructure where it is the integrity of the code running on smart home gateways that is certified by the use of Blockchain technology. However, this work has not yet been evaluated experimentally.

Rahmati et al. (2018) have observed that emerging smart home platforms use permission models, which, inspired by smartphone operating systems, group functionally similar de- vice operations into separate units and require users to grant apps access to devices at that granularity. This leads to over- privileged access for apps that do not require access to all of the granted device operations, and higher risk to users than needed because physical device operations are risk- asymmetric. For instance, from their example, “door.unlock” provides access to burglars, while “door.lock” may lead to get- ting locked out. So, the authors have argued that the com- bination of overprivileged apps and mixed-risk operations increases the damage potential. Their solution is to move away from grouping based on functional similarity to group- ing based on risk similarity. Their proposed scheme, Tyche, uses app rewriting techniques to enforce risk-based permis- sions. Through a survey of 400 users, they measured risk per- ceptions for different types of smart home cyber threats that could be caused by overprivilege. Based on their findings, they grouped a physical devices operations into three groups of risk (low, medium, high), for 146 operations across 61 types of de- vices. Evaluating this new model on three existing SmartApps, they found that these apps can be written in a way that re- duces access to high-risk operations by 60% without decreas- ing functionality or increasing user decision overhead.

Beyond preventative measures, such as authentication and authorisation, researchers have also worked on security mon- itoring, verification, detection, countermeasure decision sup- port and other more active security measures. For example, assuming a software defined network (SDN) underlying the

422 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

i p t s e i a i p t e i s s t t t

r a r e e a s s r v s s

h a m w t ( 2 h r I s r o i a i c b i T d o e r a i t r t

d p h d r t t m o o t v t f p I f s

9

9

E c p p t n i l e b t s h b t

9

S V f p F v t n S p c t

9

T p

nfrastructure for a smart home, Wang et al. (2016) have pro- osed a model whereby Android programs perform dynamic aint propagation to analyse the spread of risks posed by uspicious apps connected to a smart home’s gateway. For ach taint path, probabilistic risk analysis assists the defender n recognising network threats caused by malware infection nd to estimate the losses of associated taint sources. They ncorporated a finite state machine to represent the taint ropagation analysis situations at various configuration set- ings and deployments of safeguards. Their experimental valuation was performed on a smart home setup involv- ng a smart home gateway, a SDN controller, and OpenFlow witch and a wireless access point. Using behavioural analy- is associated with 60 families of real malware, they showed hat the approach is promising, especially as the number of aint paths associated with the propagation rules discovered hrough taint analysis is increased.

In the wider sphere of information security, there is cur- ently a distinct lack of digital forensics methodologies for IoT nd cyber-physical systems. Some initial work has been car- ied out by Do et al. (2018) on smart home information gath- ring for the purposes of digital forensics. A first model is valuated on the forensic examination of LIFX smart lights nd a Belkin WEMO switch, starting from a passive foren- ic adversary constrained by the strict principles of forensic oundness and comparing against stronger adversaries with educed constraints. While generalisation beyond these de- ices is risky, an interesting observation is that even the pas- ive forensic adversary can obtain significant evidential data, uch as determining the identities and locations of devices.

In the commercial space, traditional anti-virus vendors ave entered the emerging smart home security market by dapting the concept of traditional unified threat manage- ent gatewaysm commonly deployed within enterprise net- orks, for smart home networks. Platforms developed by Nor-

on ( Symantec, 2017 ), F-Secure ( Bitdefender, 2018 ), McAfee McAfee, 2018 ), BitDefender ( Bitdefender, 2018 ), Dojo ( Lomas, 015 ) and Cujo ( Cujo, 2017 ) seemlessly integrate into house- old networks by either replacing an existing home WiFi outer or by assuming the role of its network gateway to the nternet. Each vendor security platform are very similar in de- ign to each other and employ conceptually the same secu- ity architecture and protection mechanisms. For example, in rder to provide access to high-end threat detection capabil-

ties (historically reserved to enterprise security systems) via resource-constrained home router, network and device data s collected by each platform locally and then sent to vendor loud infrastructure where the smart home data is processed y proprietary threat detection analytics using machine learn- ng and heuristics algorithms to establish attack signatures. his architecture allows for efficient crowd-sourcing of threat etection which is shared between all smart home subscribers f the security platform (as per the approach taken by mod- rn anti-virus software). It is here where a wide array of secu- ity services such as anti-malware/virus protection, parental ccess control, secure DNS services, deep packet inspection, ntrusion detection and prevention functionality, authentica- ion and authorisation policy, as well as user security incident eporting and system configuration dashboards are provided; he latter in the form of an online or mobile user application.

Whilst the concept of offloading resource intensive threat etection to the cloud certainly provides an economical and ractical means to provider high-end security services in the ousehold, it remains unclear how such systems can respond ynamically and autonomously to cyber-physical threats in eal-time; especially as access to the advanced threat detec- ion capabilities of the vendor cloud system is subject to end- o-end network delay and Internet availability. Current com-

ercial smart home security platforms focus almost entirely n IP network and device traffic analysis, which constitutes nly a small portion of the potential connectivity landscape in he smart home. As shown in Section 1 , smart home attacks ectors can manifest over a vast set of different communica- ion mediums, control systems and sensory channels, that so ar have received little attention from a security monitoring erspective. Therefore, in practice, sole reliance on traditional

P network analysis for capturing the full remit of existing and uture potential cyber threats in the household is no longer ufficient.

. Open research challenges

.1. Smart home living labs for cyber security research

xperimentation in IoT is progressing well across the research ommunity, but usually at the level of individual devices, es- ecially when users are involved. However, there is much less rogress in developing smart home living labs, so as to be able o evaluate different threats, their impact and the effective- ess and appropriateness of corresponding countermeasures

n the real conditions of living in a household. This would al- ow to study the second order effects of different attacks and xploitation of interdependencies and unwanted interactions etween systems, such as the “rogue voice-injection actua- ion” example presented in Section 7.2 . It would also allow to tudy the human-system interaction considerations of smart ome cyber security, and the additional challenge introduced y the potentially different preferences and cyber security at- itudes of the different members of a household.

.2. Cyber-physical intrusion detection for smart homes

imilarly to cyber-physical systems ( Bezemskij et al., 2016; uong et al., 2015 ), intrusion detection not only can benefit

rom but may even necessitate the use of data sources from hysical space, in addition to network and processing data. or example, attacks that exploit the audio link between de- ices (such as the speaker of a babycam issuing a voice ac- ivation command) cannot be detected by monitoring only etwork traffic, as in conventional network environments. imilarly, information from physical sensors (such as occu- ancy sensors) on the absence of occupants a home at a spe- ific point in time can be valuable information for the detec- ion of command injection attacks.

.3. Privacy metrics for smart homes

he vast majority of IoT technologies employ a cloud ap- roach, even if not strictly necessary for technical reasons.

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 423

For example, a simple on/off actuation command for a smart lightbulb could be delivered directly from the user’s smart- phone to the smart lights hub and to the light bulb. Instead, most manufacturers involve transmission of this information to their cloud, which raises privacy concerns. At the same time, the presence or not of people in a smart home can be inferred through the level of wireless network activity (e.g., of ZigBee traffic). IoT privacy is currently a vibrant area of research, looking at IoT systems usually in isolation. In the context of a smart home, an interesting research question is whether it is possible to define smart home privacy metrics (i.e., how much privacy is offered by a smart home of a given configuration?).

9.4. Support for smart home security breach victims

While for physical crime, societies have created a range of sup- port systems for the victims, there is no equivalent provision for cyber crime. For victims of cyber attacks in smart homes, where there may be physical damage caused and the emo- tional impact can be profound, there is perhaps greater need for establishing frameworks for recovering from the cyber and physical damage caused, and also for designing counselling to be provided to the occupants affected. As we have shown in Section 7 , here the taxonomy attack graphs can help to guide investigations for different smart home attacks (to highlight key attack behaviours) in order to aid understanding of their impact on victims.

9.5. Smart home cyber hygiene and human-as-a-security-sensor

A common approach towards prevention of cyber threats is to improve the security posture of individuals and organisa- tions by developing guidance and advice for implementing ba- sic security measures (e.g., keeping software updated, using multi-factor authentication online, choosing complex pass- words etc.). However, existing “cyber hygiene” recommenda- tions are likely to cover only a small portion of the smart home threat landscape, especially as many attack vectors manifest as a result of cyber-physical connectivity. We anticipate that new smart home cyber hygiene efforts leading to the defi- nition of simple, best-practice techniques for IoT systems in the household will lead to improved prevention and detec- tion efficacy against cyber-physical threats by equipping users with the efficacy to detect potential threats to the household through a core set of recommendations (e.g., that it probably is not good security practice to connect one’s cooker to the cloud via their WiFi network if it cannot be turned off when the service is unavailable, Hindi, 2017 ). Linked to this is the Human-as-a-Security-Sensor (HaaSS) paradigm of actively in- volving users as human sensors. The concept has already been proven for conventional desktop systems ( Heartfield and Loukas, 2018 ), but in the space-constrained interface of smart- phones and embedded systems within smart homes environ- ments, the user is afforded a lot less information or time to spot suspicious activity and the potential impact of threats can introduce physical and emotional consequences which influence user decision making processes. Development of mechanisms for HaaSS reporting, as well as measuring the

reliability of these reports can facilitate integration within a technical smart home security platform. User telemetry helps influence the decision making and response of defence systems, but also augments threat detection performance through human sensing of context, which a technical system would not have access to. Furthermore, by integrating the user as part of the defence, second-order benefits may be realised, such as conditioning the emotional state of users when ex- posed to the impact of an attack or the nurturing of proactive coping strategies to tune user response in a way that supports defense.

9.6. The cyber security economics of smart homes

The introduction of cyber security in smart homes naturally comes with increased financial costs for the manufacturers and buyers, but also carries an economic value in terms of the assets and wellbeing of occupants that it contributes in protecting. Related concepts, such as security pricing, security investment ( Chronopoulos et al., 2017 ) and cyber insurance ( Pal et al., 2017 ) at the level of organisations and enterprise network environments, are being investigated, but there is no equivalent work for smart homes. Of particular interest is the concept of smart home cyber insurance, which can comple- ment traditional home insurance.

10. Conclusions

A first hurdle in carrying out research on the security of smart homes is to identify the mechanisms for launching attacks against them and their potential impact. We have conducted a survey of cyber threats in a smart home environment and produced a taxonomy to categorise these threats systemati- cally, considering the attack vectors, as well as the impact on systems and consequently on the occupants of a smart home. Taking into consideration the different characteristics of these attacks, we have also identified where existing technical de- fences practical to household users are applicable to address such threats. In doing so, we have aimed to help establish the problem space, allowing researchers from a variety of disci- plines to identify areas where they can contribute, and specif- ically for cyber-physical and IoT security researchers to pick attacks and systems for evaluating their technologies.

Acknowledgement

This work has been funded by the European Coordinated Re- search on Long-term Challenges in Information and Commu- nication Sciences and Technologies ERA-NET ( CHIST-ERA ), un- der project COCOON, EPSRC grant number EP/P016448/1 .

R E F E R E N C E S

Ahmed E , Yaqoob I , Gani A , Imran M , Guizani M . Internet-of- things-based smart environments: state of the art, taxonomy, and open research challenges. IEEE Wirel Commun 2016;23(5):10–16 .

424 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

A

A

A

A

A

A

A

B

B

B

B

B

B

B

B

B

B

C

C

C

C

C

C

C

C

C

C

C

C

C

C

C

C

D

D

D

D

D

kdemir KD , Karakoyunlu D , Padir T , Sunar B . An emerging threat: eve meets a robot. Proceedings of international conference on trusted systems. Springer; 2010. p. 271–89 .

l-Muhtadi J , Anand M , Mickunas MD , Campbell R . Secure smart homes using jini and UIUC SESAME. Proceedings of the 6th annual conference on computer security applications (ACSAC). IEEE; 2000. p. 77–85 .

l-Qutayri M , Barada H , Al-Mehairi S , Nuaimi J . A framework for an end-to-end secure wireless smart home system. Proceedings of the 2008 2nd annual IEEE systems conference. IEEE; 2008. p. 1–7 .

lbrecht K , Mcintyre L . Privacy nightmare: when baby monitors go bad. Technol Soc Mag 2015;34(3):14–19 .

lliance, W. (2019). Discover wi-fi - security. https://www.//www.wi-fi.org/discover-wi-fi/security .

ntonini A , Maggi F , Zanero S . A practical attack against a knx-based building automation system. Proceedings of the 2nd international symposium on ICS and SCADA cyber security research 2014. BCS; 2014. p. 53–60 .

RM. Technical Report. Arm platform security architecture overview; 2017 . http://www.pages.arm.com/rs/312- SAX- 488/ images/PSA-Introductory-Architecture-Overview.pdf.

abar S , Mahalle P , Stango A , Prasad N , Prasad R . Proposed security model and threat taxonomy for the internet of things (IOT). Recent Trends Netw Secur Appl 2010;89:420–9 .

adenhop, C. Ramsey, B. (2016). Carols of the z-wave security layer; or, robbing keys from peter to unlock paul. http://www. openwall.info/wiki/ _ media/people/solar/pocorgtfo12.pdf.

ankoff, C. (2013). Reddit co-founder and JSTOR hacker aaron swartz commits suicide. http://www.nymag.com/daily/intelligencer/2013/01/ jstor-hacker-aaron-swartz-commits-suicide.html .

eris O , Beautement A , Sasse MA . Employee rule breakers, excuse makers and security champions: mapping the risk perceptions and emotions that drive security behaviors. Proceedings of the 2015 new security paradigms workshop. ACM; 2015. p. 73–84 .

ezemskij A, Loukas G, Anthony RJ, Gan D. et al. (2016). Behaviour-based anomaly detection of cyber-physical attacks on a robotic vehicle.

itdefender (2018). Bitdefender BOX. https://www.bitdefender.com/box/ .

oitnott, J. (2016). Are smart homes distracting your employees? http://www.digitalistmag.com/digital-economy/2017/05/11/ big- data- problem- with- machine- learning- 05084700 .

rauchli A , Li D . A solution based analysis of attack vectors on smart home systems. Proceedings of the 2015 international conference on cyber security of smart cities, industrial control system and communications (SSIC). IEEE; 2015. p. 1–6 .

right, P. (2017). Samsungs tizen is riddled with security flaws, amateurishly written. https://www.arstechnica.co.uk/gadgets/2017/04/ samsungs- tizen- is- riddled- with- security- flaws- amateurishly -written/ .

udimir S, & Fontaine J. (2017). Emotion psychology meets cyber-security, qualitative research, preliminary data.

anetti D , Gross M , Waismel-Manor I , Levanon A , Cohen H . How cyberattacks terrorize: cortisol and personal insecurity jump in the wake of cyberattacks. Cyberpsychol Behav Soc Netw 2017;20(2):72–7 .

arlini N , Mishra P , Vaidya T , Zhang Y , Sherr M , Shields C , Zhou W . Hidden voice commands. Proceedings of usenix security symposium. USENIX; 2016. p. 513–30 .

enter IRG . Governing cybersecurity risks and benefits of the internet of things: connected medical and health devices and connected vehicles. Proceedings of IRGC expert workshop swiss Re CGD 15–16 november, 2016 .

ERT (2014). Vulnerability note VU 656302. http://www.kb.cert.org/vuls/id/656302 .

ERT-UK (2015). Cyber-security risks in the supply chain. https://www.ncsc.gov.uk/content/files/protected _ files/ guidance _ files/Cyber- security- risks- in- the- supply- chain.pdf.

hapman, A. (2014). Hacking into internet connected light bulbs. https://www.contextis.com/resources/blog/ hacking- internet- connected- light- bulbs/ .

hatzisofroniou, G. (2016). Getting the most out of evil twin. https://www.census-labs.com/media/ bsidesath2016-wifiphisher.pdf.

heckmarx. Technical Report. Amazon Echo: Alexa leveraged as a silent eavesdropper; 2018 . https://www.info.checkmarx.com/wp-alexa .

hifor B-C, Bica I, Patriciu V-V, Pop F. A security authorization scheme for smart home internet of things devices. Futur Gener Comput Syst 2017. doi: 10.1016/j.future.2017.05.048 . http://www.sciencedirect.com/science/article/pii/ S0167739X17311020 .

hronopoulos M , Panaousis E , Grossklags J . An options approach to cybersecurity investment. IEEE Access 2017 .

hung TY , Mashal I , Alsaryrah O , Hsu TH , Chang CH , Kuo WH . Design and implementation of light-weight smart home gateway for social web of thing. Proceedings of 2014 sixth international conference on ubiquitous and future networks (ICUFN). IEEE; 2014. p. 425–30 .

luley, G. (2014). In the wake of heartbleed, watch out for phishing attacks, disguised as password reset emails. https://www.hotforsecurity.bitdefender.com/blog/ in- the- wake- of- heartbleed- watch- out- for- phishing- attacks - disguised- as- password- reset- emails- 8372.html .

ollen A , Nijdam NA , Augusto-Gonzalez J , Katsikas SK , Giannoutakis KM , Spathoulas G , Gelenbe E , Ghavami N , Volkamer M , Haller P , et al . Ghost-safe-guarding home iot environments with personalised real-time risk control. Proceedings of ISCIS, 2018 .

oppolino L , DAlessandro V , DAntonio S , Levy L , Omano L . My smart home is under attack. Proceedings of 2015 IEEE 18th international conference on computational science and engineering (CSE). IEEE; 2015. p. 141–51 .

orporation, E. (2010). 90 million energy-aware lonworks devices worldwide. http://www.businesswire.com/news/home/20100412005544/ en/90- Million- Energy- Aware- LonWorks- Devices- Worldwide (2010).

ujo (2017). Why would anyone want to hack your thermostat? https://www.getcujo.com .

ailyMail (2016). The ’smart’ speakers that won’t stop talking to each other: watch amazon’s echo dot get stuck in an ’infinite loop’ chatting to google’s home. http://www.dailymail.co.uk/sciencetech/article-3987694/ The- smart- speakers- won- t- stop- talking- Watch- Amazon- s - Echo- Dot- stuck- infinite- loop- chatting- Google- s- Home.html .

awadi PN , Cook DJ , Schmitter-Edgecombe M , Parsey C . Automated assessment of cognitive health using smart home technologies. Technol Health Care 2013;21(4):323–43 .

emiris G , Hensel BK . Technologies for an aging society: a systematic review of “smart home” applications. Yearbook of medical informatics, 3. International Medical Informatics Association; 2008. p. 33–40 .

iao W , Liu X , Zhou Z , Zhang K . Your voice assistant is mine: how to abuse speakers to steal information and control your phone. Proceedings of the 4th ACM workshop on security and privacy in smartphones & mobile devices. ACM; 2014. p. 63–74 .

igi-Key (2018). Add firmware security to an iot design with a single chip. https://www.digikey.co.uk/en/articles/techzone/2018/jan/ add-firmware-security-to-an-iot-design-with-a-single-chip .

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 425

r- ad/

digitalStrom. Technical Report. digitalSTROM basic concepts; 2015 . http: //www.developer.digitalstrom.org/Architecture/ds-basics.pdf.

Dippong J , Fitch C . Emotions in criminological theory: Insights from social psychology. Sociol Compass 2017;11(4) .

Do Q, Martini B, Choo K-K R. Cyber-physical systems information gathering: a smart home case study. Comput Netw 2018;138:1–12. doi: 10.1016/j.comnet.2018.03.024 . http://www. sciencedirect.com/science/article/pii/S1389128618301440 .

Domingo MC. An overview of the internet of things for people with disabilities. J Netw Comput Appl 2012;35(2):584–96 . https://www.cutter.com/article/ social- engineering- internet- everything-492251 .

Dorri A, Kanhere SS, Jurdak R, Gauravaram P. Blockchain for iot security and privacy: the case study of a smart home. Proceedings of the 2017 IEEE international conference on pervasive computing and communications workshops (percom workshops); 2017. p. 618–23 doi: 10.1109/PERCOMW.2017.7917634 .

Drozhzhin, A. (2017). Tizen OS: 40 new vulnerabilities. https://www.blog.kaspersky.com/tizen- 40- bugs/14525/ .

Du H . Nfc technology: today and tomorrow. Int J Futur Comput Commun 2013;2(4):351 .

Dudek, S. (2015). HomePlugAV PLC: practical attacks and backdooring. http://www.synacktiv.com/ressources/ NSC2014- HomePlugAV _ attacks- Sebastien _ Dudek.pdf.

Enev M , Gupta S , Kohno T , Patel SN . Televisions, video privacy, and powerline electromagnetic interference. Proceedings of the 18th ACM conference on computer and communications security. ACM; 2011. p. 537–50 .

Engadget (2017). Burger king wreaks havoc on google assistant with whopper ad (update). [Online; accessed 30-June-2017] https://www.engadget.com/2017/04/12/ burger- king- wreaks- havoc- on- google- assistant- with- whoppe

Evtyushkin D , Ponomarev D . Covert channels through random number generator: mechanisms, capacity estimation and mitigations. Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. ACM; 2016. p. 843–57 .

Exploiteers (2017). Lg smart refrigerator (lfx31995st). https://www.exploitee.rs/index.php/LG_Smart _Refrigerator_(LFX31995ST)%E2%80%8B.

Fernandes E , Jung J , Prakash A . Security analysis of emerging smart home applications. Proceedings of IEEE symposium on security and privacy (sp). IEEE; 2016. p. 636–54 .

Fontaine JJ, Scherer KR, & Soriano C.E. (2013). Components of emotional meaning: a sourcebook.

Fouladi B , Ghanoun S . Security evaluation of the z-wave wireless protocol. Black hat USA. Black Hat, 2013 .

Franceeschi-Bicchierai, L. (2017). Internet of things teddy bear leaked 2 million parent and kids message recordings. https://www.motherboard.vice.com/en _ us/article/ internet- of- things- teddy- bear- leaked- 2- million- parent- and ]- kids- message- recordings .

Francillon A , Danev B , Capkun S . Relay attacks on passive keyless entry and start systems in modern cars. Proceedings of the 18th annual network and distributed system security symposium. The Internet Society, 2011 .

Francis L , Hancke G , Mayes K , Markantonakis K . Potential misuse of NFC enabled mobile phones with embedded security elements as contactless attack platforms. Proceedings of international conference for internet technology and secured transactions (ICITST). IEEE; 2009. p. 1–8 .

Frimmel A, Tawfik A, Wagner H, Zach M. Projektarbeit “Secure Smart Home”; 2016 . https: //www.leanstartupsecurity.com/wp-content/uploads/2017/01/ Projektarbeit _ Secure _ SmartHome _ Dokumentation _ v1. 2 _ 20150628.pdf.

.

Ghansah I . Smart grid cyber security potential threats, vulnerabilities and risks. California Energy Commission; 2009 . PIER Energy-Related Environmental Research Program, CEC-500-2012-047.

Goodwin, D. (2017). How a hacked amazon echo could secretly capture your most intimate moments. https://www.arstechnica.co.uk/information-technology/2017/ 08/how- hackers- could- turn- an- amazon- echo- into- a- secret - bugging- device/ .

Gross JJ , Levenson RW . Emotional suppression: physiology, self-report, and expressive behavior. J Personal Soc Psychol 1993;64(6):970 .

Gross JJ . Antecedent-and response-focused emotion regulation: divergent consequences for experience, expression, and physiology. J Personal Soc Psychol 1998;74(1):224 .

Gross JJ , John OP , Richards JM . The dissociation of emotion expression from emotion experience: a personality perspective. Personal Soc Psychol Bull 2000;26(6):712–26 .

Guardian, D. (2017). A history of ransomware attacks: the biggest and worst ransomware attacks of all time. https://www.digitalguardian.com/blog/ history-ransomware-attacks-biggest-and-worst -ransomware-attacks-all-time .

Guri M, Bykhovsky D, Elovici, Y. (2017). aIR-jumper: covert air-gap exfiltration/infiltration via security cameras and infrared (IR). arXiv preprint arXiv:1709.05742, (pp. 1–15). https://arxiv.org/abs/1709.05742

Guri M, Solewicz Y, Daidakulov A, & Elovici Y. (2016). Fansmitter: acoustic data exfiltration from (speakerless) air-gapped computers. arXiv preprint arXiv:1606.05915, (pp. 1–19). https://arxiv.org/abs/1606.05915

Hall J, & Ramsey B. (2018). Tools for evaluating and exploiting z-wave networks using software-defined radios. https://www.github.com/cureHsu/EZ-Wave .

HAPCAN (2017). HAPCAN: about project – basic information. http://www.hapcan.com/project/basis/ .

Haselsteiner E , Breitfuß K . Security in near field communication (NFC). Proceedings of workshop on RFID security; 2006. p. 12–14 .

Heartfield R , Loukas G . A taxonomy of attacks and a survey of defence mechanisms for semantic social engineering attacks. ACM Comput Surv 2016;48(3):37 .

Heartfield R , Loukas G . Detecting semantic social engineering attacks with the weakest link: implementation and empirical evaluation of a human-as-a-security-sensor framework. Comput Secur 2018;76:101–27 .

Hindi, R. (2017). Thanks for breaking our connected homes, amazon. https://www.medium.com/snips-ai/ thanks- for- breaking- our- connected- homes- amazon -c820a8849021 .

Ho G , Leung D , Mishra P , Hosseini A , Song D , Wagner D . Smart locks: lessons for securing commodity internet of things devices. Proceedings of the 11th ACM on asia conference on computer and communications security. ACM; 2016. p. 461–72 .

Holfeld B , Sukhawathanakul P . Associations between internet attachment, cyber victimization, and internalizing symptoms among adolescents. Cyberpsychol Behav Soc Netw 2017;20(2):91–6 .

Independent, T. (2016). Baby monitors ’hacked’: parents warned to be vigilant after voices heard coming from speakers. http: //www.independent.co.uk/life- style/gadgets- and- tech/news/ baby- monitors- hacked- parents- warned- to- be- vigilant- after - voices- heard- coming- from- speakers- a6843346.html .

Infurna FJ , Ram N , Gerstorf D . Level and change in perceived control predict 19-year mortality: findings from the americans changing lives study. Dev Psychol 2013;49(10):1833 .

Vanderauwera, J. Puppe, A, (2010). Research project: homeplug security. http://www.delaat.net/rp/2009-2010/p19/report.pdf0 .

426 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

J

J

J

J

J

J

J

J

K

.

K K

K

K K

K

E

logy

L

L

L

L

L

L

L

L

M

M M

M

M

M

M

M

M

M

M

M

M

M

N

O

acoby, D. (2014). How I hacked my home. https: //www.blog.kaspersky.com/how- i- hacked- my- home/5756/ .

ahn M , Jentsch M , Prause CR , Pramudianto F , Al-Akkad A , Reiners R . The energy aware smart home. Proceedings of the 2010 5th international conference on future information technology (futuretech). IEEE; 2010. p. 1–8 .

enkins IR , Shapiro R , Bratus S , Goodspeed T , Speers R , Dowd D . Short paper: speaking the local dialect: exploiting differences between ieee 802.15. 4 receivers with commodity radios for fingerprinting, targeted attacks, and wids evasion. Proceedings of the 2014 ACM conference on security and privacy in wireless and mobile networks. ACM; 2014. p. 63–8 .

eong J , Chung MY , Choo H . Integrated OTP-based user authentication scheme using smart cards in home networks. Proceedings of the 41st annual hawaii international conference on system sciences. IEEE; 2008. p. 294 .

ing Q , Vasilakos AV , Wan J , Lu J , Qiu D . Security of the internet of things: perspectives and challenges. Wirel Netw 2014;20(8):2481–501 .

okar P , Leung V . Intrusion detection and prevention for zigbee-based home area networks in smart grids. IEEE Trans Smart Grid 2016;9(3):1800–11 .

okar P , Nicanfar H , Leung VCM . Specification-based intrusion detection for home area networks in smart grids. Proceedings of IEEE international conference on smart grid communications (smartgridcomm). IEEE; 2011. p. 208–13 .

ovanovic P , Neves S . Practical cryptanalysis of the open smart grid protocol. Proceedings of international workshop on fast software encryption. Berlin, Heidelberg: Springer; 2015. p. 297–316 .

ang, C. (2017). A tweet to kurt eichenwald, a strobe and a seizure. now, an arrest. https://www.nytimes.com/2017/03/17/technology/ social- media- attack- that- set- off- a- seizure- leads- to- an- arrest html? _ r=0 .

ennedy D , Simon R . Pentesting over power lines, 2011 . ennedy T , Hunt R . A review of WPAN security: attacks and

prevention. Proceedings of the international conference on mobile technology, applications, and systems. ACM; 2008. p. 56 .

itchen D, & Kinne S. (2017). The wifi pineapple wireless auditing platform. https://www.wifipineapple.com/ .

odra, S. (2016). Smart home hacking. Master’s thesis. NTNU. omninos N , Philippou E , Pitsillides A . Survey in smart grid and

smart home security: issues, challenges and countermeasures. IEEE Commun Surv Tutor 2014;16(4):1933–54 .

une DF , Backes J , Clark S , Kramer D , Reynolds M , Fu K , Kim Y , Xu W . Ghost talk: mitigating EMI signal injection attacks against analog sensors. Proceedings of the 2013 IEEE symposium on security and privacy. IEEE; 2013. p. 145–59 .

lliptic Labs, (2017). Elliptic labs introduces ultrasonic presence detection technology, INNER PEACE, for intelligent personal assistants and other home devices. http://www.ellipticlabs.com/2017/02/28/ elliptic- labs- introduces- ultrasonic- presence- detection- techno - inner- peace- for- intelligent- personal- assistants- and- other - home- devices/ .

aufer S, Mallas C. Attacking homematic; 2013 . https://www. media.ccc.de/v/30C3 _ - _ 5444 _ - _ en _ - _ saal _ g _ - _ 201312301600 _ - _ attacking _ homematic _ - _ sathya _ - _ malli#video&t=84 .

eijdekkers P , Gay V , Lawrence E . Smart homecare system for health tele-monitoring. Proceedings of first international conference on digital society (ICDS). IEEE; 2007. p. 3 .

i J , Han G , Zhu C , Sun G . An indoor ultrasonic positioning system based on TOA for internet of things. Mob Inf Syst 2016;2016:10

4502867 .

in H , Bergmann NW . Iot privacy and security challenges for smart home environments. Information 2016;7(3):44 .

iu Y , Hu S , Zomaya AY . The hierarchical smart home cyberattack detection considering power overloading and frequency disturbance. IEEE Trans Ind Inform 2016;12(5):1973–83 .

omas, N. (2015). Dojo is designed to protect your smart home from itself. https://www.techcrunch.com/2015/11/19/dojo-labs/ .

ombardi DB , Ciceri MR . More than defense in daily experience of privacy: the functions of privacy in digital and physical environments. Eur J Psychol 2016;12(1):115 .

oukas G . Cyber-physical attacks: a growing invisible threat. Butterworth-Heinemann; 2015 .

alm, S. (2015). Two suicides are linked to Ashley Madison leak: Texas police chief takes his own life just days after his email is leaked in cheating website hack. http://www.dailymail.co.uk/news/article-3208907/ The- Ashley- Madison- suicide- Texas- police- chief- takes- life - just- days- email- leaked- cheating- website- hack.html .

arshall NJ . Privacy and environment. Hum Ecol 1972;1(2):93–110 . ayes KE , Markantonakis K , Francis L , Hancke GP . Nfc security

threats. Smart card technology international magazine; 2010. p. 42–7 .

cAfee (2018). Mcafee secure home platform. http://www.securehomeplatform.mcafee.com/docs/ SHP- Whitepaper- Protecting- the- Home- Front _ hires.pdf.

cMahon PV . Sesame v2 public key and authorisation extensions to kerberos. Network and distributed system security. IEEE; 1995. p. 114–31 .

edim, T. (2015). Doll hacking: the good, the bad(words) and the ugly (features). http://www.blog.threat.actor/2015/11/ doll- hacking- good- badwords- and- ugly.html .

iller, F. J. (2013). Supply chain attack framework and attack patterns. https://www.ncsc.gov.uk/content/files/protected _ files/ guidance _ files/Cyber- security- risks- in- the- supply- chain.pdf.

irror, T. (2014). Wake up baby: man HACKS into 10-month-old’s baby monitor to watch sleeping infant. http://www.mirror.co.uk/news/world-news/ man- hacks- 10- month- olds- baby- monitor- 3468827 .

ITRE. Technical Report. CVE-2017-7240; 2017 . http://www.cve. mitre.org/cgi-bin/cvename.cgi?name=CVE- 2017- 7240 .

oran B, Meric M, & Tschofenig H. (2018). A firmware update architecture for internet of things devices draft-moran-suit-architecture-00. https: //www.tools.ietf.org/html/draft-moran-suit-architecture-00 .

oreham NA . Beyond information: physical privacy in english law. Camb Law J 2014;73(2):350–77 .

orley, K. (2017). Amazon echo rogue payment warning after TV show causes alexa to order dolls houses. http://www.telegraph.co.uk/news/2017/01/08/ amazon- echo- rogue- payment- warning- tv- show- causes - alexa- order/ .

orsley, K. (2017). Amazon echo rogue payment warning after TV show causes ‘alexa’ to order dolls houses. http://www.telegraph.co.uk/news/2017/01/08/ amazon- echo- rogue- payment- warning- tv- show- causes - alexa- order/ .

ukherjee S , Shirazi H , Ray I , Daily J , Gamble R . Practical dos attacks on embedded networks in commercial vehicles. Information systems security. Springer; 2016. p. 23–42 .

awir M , Amir A , Yaakob N , Lynn OB . Internet of things (iot): taxonomy of security attacks. Proceedings of the 2016 3rd international conference on electronic design (ICED). IEEE; 2016. p. 321–6 .

h S, Lee K. The need for specific penalties for hacking in criminal law. Sci World J 2014;2014:6 736738 . https://doi.org/10.1155/2014/736738

c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8 427

Oluwafemi T , Kohno T , Gupta S , Patel S . Experimental security analyses of non-networked compact fluorescent lamps: a case study of home automation security. Proceedings of laser; 2013. p. 13–24 .

Oulasvirta A , Pihlajamaa A , Perki J , Ray D , Vhkangas T , Hasu T , Vainio N , Myllymki P . Long-term effects of ubiquitous surveillance in the home. Proceedings of the 2012 ACM conference on ubiquitous computing. ACM; 2012. p. 40–50 .

Owusu-Ansah FE . Control perceptions and control appraisal: relation to measures of subjective well-being. Ghana Med J 2008;42(2):61–7 .

Pal R, Golubchik L, Psounis K, Hui P. Security pricing as enabler of cyber-insurance a first look at differentiated pricing markets. IEEE Trans Depend Secure Comput 2017. doi: 10.1109/TDSC.2017.2684801 .

Park Y , Son Y , Shin H , Kim D , Kim Y . This aint your dose: Sensor spoofing attack on medical infusion pump. Proceedings of the 10th USENIX workshop on offensive technologies. USENIX, 2016 .

Partners, P. (2016a). New, easier ways to make my friend cayla swear. https://www.pentestpartners.com/blog/ new- easier- ways- to- make- my- friend- cayla- swear/ .

Partners, P. (2016b). Thermostat ransomware: a lesson in iot security. https://www.pentestpartners.com/blog/ thermostat-ransomware-a-lesson-in-iot-security/ .

Partners, P. (2017). Vulnerable wi-fi dildo camera endoscope. yes really. https://www.pentestpartners.com/security-blog/ vulnerable- wi- fi- dildo- camera- endoscope- yes- really/ .

Pedersen DM . Model for types of privacy by privacy functions. J Environ Psychol 1999;19(4):397–405 .

Poulsen, K. (2008). Hackers assault epilepsy patients via computer. Proofpoint (2014a). Proofpoint uncovers internet of things (iot)

cyberattack. http://www.investors.proofpoint.com/ releasedetail.cfm?releaseid=819799 .

Proofpoint (2014b). Your fridge is full of SPAM, part II: details. https://www.proofpoint.com/us/threat-insight/post/ Your- Fridge- is- Full- of- SPAM- Part- 2 .

Proofpoint (2016). Droidjack uses side-loadit’s super effective! backdoored pokemon GO android app found. https://www.proofpoint.com/us/threat-insight/post/ droidjack- uses- side- load- backdoored- pokemon- go- android-app .

Rahmati A, Fernandes E, Eykholt K, & Prakash A. (2018). Tyche: risk-based permissions for smart home platforms. arXiv preprint arXiv:1801.04609, (pp. 1–15). https://www.arxiv.org/pdf/1801.04609.pdf.

Resno (2017). Welcome to the exploitee.rs wiki. https://www.exploitee.rs/ .

Robles RJ , Kim T-h , Cook D , Das S . A review on security in smart home development. Int J Adv Sci Technol 2010;15:13–22 .

Sabath F . What can be learned from documented intentional electromagnetic interference (IEMI) attacks?. Proceedings of the 2011 XXX general assembly and scientific symposium, URSI. IEEE; 2011. p. 1–4 .

Sabath F . Threat of electromagnetic terrorism. Proceedings of Euroem 2012 book of abstracts, 2012 .

Samsung (2017). Slide-in gas flex duo range with dual door. http: //www.samsung.com/us/home- appliances/ranges/slide- in/ nx58k9850ss- slide- in- gas- flex- duo- range- with- dual- door - stainless- steel- nx58k9850ss- aa/ .

Scherer KR . Emotions. Introduction to social psychology: a European perspective. Oxford: Blackwell, 2000 .

Scherer KR . Appraisal considered as a process of multilevel sequential checking. Appraisal processes in emotion: theory, methods, research, 44; 2001. p. 695–729 . Level and change in perceived control predict 19-year mortality: findings from the americans changing lives study.

Scherer KR . What are emotions? and how can they be measured? Soc Sci Inf 2005;44(4):695–729 .

Sedighpour S , Čapkun S , Ganeriwal S , Srivastava M . Distance enlargement and reduction attacks on ultrasound ranging. Proceedings of the 3rd international conference on embedded networked sensor systems. ACM; 2005. p. 312 .

Sherman SJ , Hoffmann JL . The psychology and law of voluntary manslaughter: what can psychology research teach us about the “heat of passion” defense? J Behav Decis Mak 2007;20(5):499–519 .

Shipley, P. (2015). Insteon: false security and deceptive. https://www.youtube.com/watch?v=dy1LTQLmPtM .

Singh S , Singh N . Internet of things (iot): security challenges, business opportunities & reference architecture for e-commerce. Proceedings of international conference on green computing and internet of things (ICGCIot). IEEE; 2015. p. 1577–81 .

Smith, M. (2018). Ez-wave: A z-wave hacking tool capable of breaking bulbs, abusing z-wave devices. https://www.csoonline.com/article/3024217/security/ ez-wave-z-wave-hacking-tool-capable-of-breaking-bulbs-and - abusing- z- wave- devices.html .

spacehuhn (2017). Esp8266 deauther - github project. ESP8266 Deauther.

Stamm S , Ramzan Z , Jakobsson M . Drive-by pharming. Proceedings of international conference on information and communications security. Berlin, Heidelberg: Springer; 2006. p. 495–506 .

statistics, O. f. n. (2014). Record proportion of people in employment are home workers. http://www.webarchive. nationalarchives.gov.uk/20160105210705/ ,http://www.ons.gov. uk/ons/rel/lmac/characteristics- of- home- workers/2014/ sty- home- workers.html .

Symantec (2017). Introducing norton core. https://www.us.norton.com/core .

Tarala, K. K. (2009). Dangers of digital photo frames. http://www. enclavesecurity.com/dangers- of- digital- photo- frames/ .

Tasker, B. (2014). Vulnerability: infiltrating a network via powerline (HomePlugAV) adapters. https://www.bentasker.co.uk/documentation/security/ 282- infiltrating- a- network- via- powerline- homeplugav- adapters .

Technology, B. (2016). How hackers could use doll to open your front door. http://www.bbc.co.uk/news/technology-38966285 .

Vanhoef M , Piessens F . Key reinstallation attacks: forcing nonce reuse in WPA2. Proceedings of the 24th ACM conference on computer and communications security (CCS). ACM, 2017 .

Vuong TP , Loukas G , Gan D . Performance evaluation of cyber-physical intrusion detection on a robotic vehicle. Proceedings of the 2015 IEEE international conference on pervasive intelligence and computing (CIT/IUCC/DASC/PICOM). IEEE; 2015. p. 2106–13 .

Wakefield, J. (2014). Smart LED light bulbs leak wi-fi passwords. http://www.bbc.co.uk/news/technology-28208905 .

Wang P , Chao KM , Lo CC , Lin WH , Lin HC , Chao W . Using malware for software-defined networking based smart home security management through a taint checking approach. Int J Distrib Sens Netw 2016;12(8):1–23 .

Watkins E , Baracaia S . Why do people ruminate in dysphoric moods? Pers Individ Differ 2001;30(5):723–34 .

van de Weijer SG , Leukfeldt ER . Big five personality traits of cybercrime victims. Cyberpsychol Behav Soc Netw 2017;20(7):407–12 .

Wright J . Killerbee: practical zigbee exploitation framework. Proceedings of the 11th toorcon conference, San Diego, 2009 .

Zhang G, Yan C, Ji X, Zhang T, Zhang T, & Xu W. (2017). Dolphin attack: inaudible voice commands.arXiv preprint arXiv:1708.09537. https://arxiv.org/abs/1708.09537 .

428 c o m p u t e r s & s e c u r i t y 7 8 ( 2 0 1 8 ) 3 9 8 – 4 2 8

Z

H i d

J D L

a

iegeldorf JH , Morchon OG , Wehrle K . Privacy in the internet of things: threats and challenges. Secur Commun Netw 2014;7(12):2728–42 .

Dr. Ryan Heartfield is a Research Associate in Cyber Security at the University of Green- wich, UK. He is currently involved in mul- tiple UK and European research projects in cybersecurity, ranging from the security of autonomous vehicles, measuring the trust- worthiness of human sensor platforms (EU Horizon 2020 project TRILLION), as well as studying cyber threats and the emotional impact of security breaches in smart home environments (EPSRC CHIST-ERA project CO- COON). Dr. Heartfield has a Ph.D. in Cyber Security from the University of Greenwich.

is research interests include semantic social engineering threats, ntrusion detection systems, cyber-physical attacks, software- efined networks, cloud computing and network security.

Dr. George Loukas is a Senior Lecturer in cy- ber security at the University of Greenwich. He teaches and leads research projects in cyber-physical security, cyber-crime, social engineering and digital communications, and has authored or co-authored 65 refer- eed journal articles, books, book chapters and conference publications. He is currently principal investigator for the EU Horizon 2020 project TRILLION, EPSRC CHIST-ERA COCOON and British Council’s Blockchain- based Secure Hajj and Umrah. He is also on the editorial board of the BCS Computer

ournal and Elsevier’s Simulation Modelling Practice and Theory. r. Loukas has a PhD in Network Security from Imperial College ondon.

Dr. Sanja Budimir has a background in psy- chology and cognitive science, with a focus on emotion psychology and emotion pro- cessing, where she taught courses experi- mental methods, non-experimental meth- ods and qualitative methods in psychology at Ghent University. Currently, she works as a postdoctoral researcher at Ghent Univer- sity on the EPSRC CHIST-ERA project CO- COON. Dr. Budimir has a Ph.D. in Cognitive Sciences from the University of Zagreb.

Dr. Anatolij Bezemskij is a Research Asso- ciate in Cyber Security at the University of Greenwich, UK. He is currently working on the experimental study of security breaches in smart home environments (EPSRC CHIST- ERA project COCOON). Dr. Anatolij Bezem- skij has a Ph.D. in Cyber Security from the University of Greenwich, which focused on the security of autonomous robotic vehicles. His research interests include IoT and Smart Home cyber-security, robotic vehicle cyber- physical security, network security and au- tonomous robotic systems. He is currently

lso involved in teaching penetration testing and smart systems.

Johnny R.J. Fontaine is Associate Profes- sor at the faculty of psychology and edu- cational sciences of Ghent University, Bel- gium. He teaches psychological assessment and cross-cultural psychology. He is presi- dent of the European Association for Psycho- logical Assessment. His research focuses on the assessment of emotions and emotional competence across cultural groups.

Dr. Avgoustinos Filippoupolitis is a Senior Lecturer in Disruptive Technologies in the Computing and Information Systems De- partment at the University of Greenwich, UK. His research interests are in the problems of indoor localisation and occupancy detection, human activity recognition, anomaly detec- tion in Internet of Things applications, and emergency management. Dr. Filippoupolitis as Ph.D. in Emergency Response Simulation from Imperial College.

Etienne Roesch is Associate Professor of Cog- nitive Science, at the University of Reading, UK, affiliated to the Centre for Integrative Neuroscience and Neurodynamics, and the School of Psychology and Clinical Language Sciences. His work focuses on the psycholog- ical and neuroscientific aspects underlying our experience of a technology-driven envi- ronment.

  • A taxonomy of cyber-physical threats and impact in the smart home
    • 1 Introduction
    • 2 Related work
    • 3 A taxonomy of cyber threats to smart home
    • 4 Attack vector
      • 4.1 CM (communication medium)
        • 4.1.1 CM-HI: home internet
        • 4.1.2 CM-WD: wired
        • 4.1.3 CM-WD-X: X10
        • 4.1.4 CM-WD-K: KNX
        • 4.1.5 CM-WD-H: HAPCAN
        • 4.1.6 CM-WD-U: universal power bus
        • 4.1.7 CM-WD-H: HomePlug AV
        • 4.1.8 CM-WD-L: LonTalk
        • 4.1.9 CM-WD-DS: digitalSTROM
        • 4.1.10 CM-wireless
        • 4.1.11 CM-WI-W: WiFi
        • 4.1.12 CM-WI-ZG: ZigBee
        • 4.1.13 CM-WI-Z: ZWave
        • 4.1.14 CM-WI-B: bluetooth
        • 4.1.15 CM-WI-N: NFC
        • 4.1.16 CM-BC: BidCos
        • 4.1.17 CM-WI-I: Insteon
      • 4.2 CS: control software
        • 4.2.1 CS-3PA: third party apps
        • 4.2.2 CS-OS: host OS
      • 4.3 CS-F: firmware
        • 4.3.1 CS-WA: workflow automation
      • 4.4 S1: sensory channel
        • 4.4.1 S1-U: ultrasonic
        • 4.4.2 S1-V: voice
        • 4.4.3 S1-IR: infrared
      • 4.5 S2: supply chain
        • 4.5.1 S2-S: software
        • 4.5.2 S2-H: hardware
      • 4.6 S3: side-channel
        • 4.6.1 S3-EMA (electromagnetic emanations)
        • 4.6.2 S3-EMI (electromagnetic interference)
    • 5 Impact on systems
      • 5.1 Physical impact
        • 5.1.1 P-BPP: breach of physical privacy
        • 5.1.2 P-UA: unauthorised actuation
        • 5.1.3 P-IA: incorrect actuation
        • 5.1.4 P-DA: delayed actuation
        • 5.1.5 P-PA: prevented actuation
      • 5.2 Cyber impact
        • 5.2.1 C-C: confidentiality
        • 5.2.2 C-I: integrity
        • 5.2.3 C-A: availability
        • 5.2.4 C-NP: non-repudiation
    • 6 Impact on domestic life
      • 6.1 DC: direct consequences
        • 6.1.1 DC-F: financial
        • 6.1.2 DC-V: vocational
      • 6.2 DC-S: health and safety
        • 6.2.1 DC-P: invasion of privacy
        • 6.2.2 DC-LC: loss of control
        • 6.2.3 DC-I: inconvenience
      • 6.3 UX: user experience
        • 6.3.1 UX-N1: instantly noticeable
        • 6.3.2 UX-N2: noticeable over time
        • 6.3.3 UX-NN: not noticeable
      • 6.4 E: emotional
        • 6.4.1 E-A: appraisal
        • 6.4.2 E-AT: action tendencies
        • 6.4.3 E-B: bodily symptoms
        • 6.4.4 E-EX: expression
        • 6.4.5 E-SF: subjective feeling
      • 6.5 Emotion regulation and coping
        • 6.5.1 ERC-emotional regulation
        • 6.5.2 ERC-actual behaviour
    • 7 Taxonomic classification examples
      • 7.1 Second-order threats to smart homes: vulnerabilities in configuration and automation
      • 7.2 Rogue voice-injection actuation
      • 7.3 WiFi de-authentication (with Evil-Twin)
      • 7.4 Workflow automation phishing
    • 8 Defending against cyber-physical threats in the smart home
    • 9 Open research challenges
      • 9.1 Smart home living labs for cyber security research
      • 9.2 Cyber-physical intrusion detection for smart homes
      • 9.3 Privacy metrics for smart homes
      • 9.4 Support for smart home security breach victims
      • 9.5 Smart home cyber hygiene and human-as-a-security-sensor
      • 9.6 The cyber security economics of smart homes
    • 10 Conclusions
    • Acknowledgement
  • Reference