Home security cameras (HSCs) are becoming increasingly important in protecting people’s household property and caring for family members. As an emerging type of home IoT devices, HSCs are distinct from… Click to show full abstract
Home security cameras (HSCs) are becoming increasingly important in protecting people’s household property and caring for family members. As an emerging type of home IoT devices, HSCs are distinct from traditional IoT devices in that they are often installed in intimate places, detecting movements constantly. Such close integration with users’ daily life may result in distinct user behavioral patterns and privacy concerns. To explore this, we perform a detailed measurement study based on a large-scale service log dataset from a major HSC service provider. Our analysis reveals unique usage patterns of HSCs, including significant wasted uploads, asymmetrical upload and download traffic, skewed user engagement, and limited watching locations. We further identify three types of privacy risks in current HSC services using both passive logs and active measurements. These risks can be exploited by attackers, through observing only the traffic rates of HSCs, to infer the working state of cameras and even the daily activity routine in places where the camera is installed. Moreover, we find the premium users who pay an extra fee are especially vulnerable to such privacy inferences. We propose countermeasures from the perspectives of susceptible users and HSC providers to mitigate the risks.
               
Click one of the above tabs to view related content.