EvilScreen Attack: Smart TV Hijacking via Multi-channel Remote Control Mimicry

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Zhang, Yiwei, Ma, Siqi, Chen, Tiancheng, Li, Juanru, Deng, Robert H., Bertino, Elisa
Format: Preprint
Veröffentlicht: 2022
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866917801444245504
author Zhang, Yiwei
Ma, Siqi
Chen, Tiancheng
Li, Juanru
Deng, Robert H.
Bertino, Elisa
author_facet Zhang, Yiwei
Ma, Siqi
Chen, Tiancheng
Li, Juanru
Deng, Robert H.
Bertino, Elisa
contents Modern smart TVs often communicate with their remote controls (including those smart phone simulated ones) using multiple wireless channels (e.g., Infrared, Bluetooth, and Wi-Fi). However, this multi-channel remote control communication introduces a new attack surface. An inherent security flaw is that remote controls of most smart TVs are designed to work in a benign environment rather than an adversarial one, and thus wireless communications between a smart TV and its remote controls are not strongly protected. Attackers could leverage such flaw to abuse the remote control communication and compromise smart TV systems. In this paper, we propose EvilScreen, a novel attack that exploits ill-protected remote control communications to access protected resources of a smart TV or even control the screen. EvilScreen exploits a multi-channel remote control mimicry vulnerability present in today smart TVs. Unlike other attacks, which compromise the TV system by exploiting code vulnerabilities or malicious third-party apps, EvilScreen directly reuses commands of different remote controls, combines them together to circumvent deployed authentication and isolation policies, and finally accesses or controls TV resources remotely. We evaluated eight mainstream smart TVs and found that they are all vulnerable to EvilScreen attacks, including a Samsung product adopting the ISO/IEC security specification.
format Preprint
id arxiv_https___arxiv_org_abs_2210_03014
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle EvilScreen Attack: Smart TV Hijacking via Multi-channel Remote Control Mimicry
Zhang, Yiwei
Ma, Siqi
Chen, Tiancheng
Li, Juanru
Deng, Robert H.
Bertino, Elisa
Cryptography and Security
Modern smart TVs often communicate with their remote controls (including those smart phone simulated ones) using multiple wireless channels (e.g., Infrared, Bluetooth, and Wi-Fi). However, this multi-channel remote control communication introduces a new attack surface. An inherent security flaw is that remote controls of most smart TVs are designed to work in a benign environment rather than an adversarial one, and thus wireless communications between a smart TV and its remote controls are not strongly protected. Attackers could leverage such flaw to abuse the remote control communication and compromise smart TV systems. In this paper, we propose EvilScreen, a novel attack that exploits ill-protected remote control communications to access protected resources of a smart TV or even control the screen. EvilScreen exploits a multi-channel remote control mimicry vulnerability present in today smart TVs. Unlike other attacks, which compromise the TV system by exploiting code vulnerabilities or malicious third-party apps, EvilScreen directly reuses commands of different remote controls, combines them together to circumvent deployed authentication and isolation policies, and finally accesses or controls TV resources remotely. We evaluated eight mainstream smart TVs and found that they are all vulnerable to EvilScreen attacks, including a Samsung product adopting the ISO/IEC security specification.
title EvilScreen Attack: Smart TV Hijacking via Multi-channel Remote Control Mimicry
topic Cryptography and Security
url https://arxiv.org/abs/2210.03014