论文标题

邪恶屏幕攻击:智能电视通过多通道遥控器模仿

EvilScreen Attack: Smart TV Hijacking via Multi-channel Remote Control Mimicry

论文作者

Zhang, Yiwei, Ma, Siqi, Chen, Tiancheng, Li, Juanru, Deng, Robert H., Bertino, Elisa

论文摘要

现代智能电视经常使用其遥控器(包括那些智能手机模拟的电视)使用多个无线通道(例如,红外,蓝牙和Wi-Fi)进行通信。但是,这种多通道遥控通信引入了新的攻击表面。固有的安全漏洞是,大多数智能电视的遥控器旨在在良性环境中而不是对抗性环境中工作,因此智能电视及其遥控器之间的无线通信并没有受到强烈的保护。攻击者可以利用这种缺陷来滥用遥控通信并妥协智能电视系统。在本文中,我们提出了一种新颖的攻击,这是一种新颖的攻击,该攻击利用受保护不良的遥控通信访问智能电视的受保护资源,甚至控制屏幕。 Evilscreen利用了当今智能电视中存在的多渠道遥控模仿漏洞。与其他攻击通过利用代码漏洞或恶意第三方应用程序损害电视系统的其他攻击,邪恶的屏幕直接重复了不同遥控器的命令,将它们结合在一起以绕过部署的身份验证和隔离政策,并最终远程访问或控制电视资源。我们评估了八台主流智能电视,发现它们都容易受到邪恶屏幕攻击的影响,包括采用ISO/IEC安全规范的三星产品。

Modern smart TVs often communicate with their remote controls (including those smart phone simulated ones) using multiple wireless channels (e.g., Infrared, Bluetooth, and Wi-Fi). However, this multi-channel remote control communication introduces a new attack surface. An inherent security flaw is that remote controls of most smart TVs are designed to work in a benign environment rather than an adversarial one, and thus wireless communications between a smart TV and its remote controls are not strongly protected. Attackers could leverage such flaw to abuse the remote control communication and compromise smart TV systems. In this paper, we propose EvilScreen, a novel attack that exploits ill-protected remote control communications to access protected resources of a smart TV or even control the screen. EvilScreen exploits a multi-channel remote control mimicry vulnerability present in today smart TVs. Unlike other attacks, which compromise the TV system by exploiting code vulnerabilities or malicious third-party apps, EvilScreen directly reuses commands of different remote controls, combines them together to circumvent deployed authentication and isolation policies, and finally accesses or controls TV resources remotely. We evaluated eight mainstream smart TVs and found that they are all vulnerable to EvilScreen attacks, including a Samsung product adopting the ISO/IEC security specification.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源