Security cameras can tell burglars whenyou're not home, study shows

Some popular home security cameras couldallow would-be burglars to work out when you've left the building, according toa study published Monday.

Researchers found they could tell if someonewas in, and even what they were doing in the home, just by looking at datauploaded by the camera and without monitoring the video footage itself.

The international study was carried out byresearchers from Queen Mary University of London (QMUL) and the Chinese Academyof Science, using data provided by a large Chinese manufacturer of InternetProtocol (IP) security cameras.

Cameras like these allow users to monitortheir homes remotely via a video feed on the internet, but the researchers saythe traffic generated by the devices can reveal privacy-compromisinginformation.

Study author Gareth Tyson from QMUL told thatdata uploads of the unencrypted data increase when a camera is recordingsomething moving, so an attacker could tell if the camera was uploading footageof someone in motion, and even different types of motion like running orsitting.

The risk is that "someone who isspecifically targeting an individual household rocks up outside with a deviceto try and start passively monitoring traffic," he said.

Tyson told that an attacker would require adecent level of technical knowledge to monitor the data themselves, but thereis a chance that someone could develop a program that does so and sell itonline.

Noting that he hasn't seen any directevidence of this kind of attack taking place, he said one potential use wouldbe if someone wanted to burgle your house.

"They monitor the camera traffic overan extended period of time, and by looking at the patterns that are generatedby those cameras over maybe a week, they then start predicting the followingweek when you're most likely to be in the house," he said.

In order to reduce the privacy risk,companies could randomly inject data into their systems to make it harder forattackers to spot a pattern, he said.

Tyson said the team are trying to extendtheir research to work out how to maintain camera performance while reducingprivacy risks.

At present, cameras are "fairly stupiditems" in order to keep manufacturing costs down, said Tyson, uploadingdata whenever motion is detected.

"What we want to do is have a moreintelligent system that allows the camera to understand what that motion is,assess the level of risk, and only upload it and alert the user in a case wherethe camera feels that it's worthy doing," he said.

For example, someone who owns a catprobably doesn't want to be alerted every time the camera detects the animalwalking around, but they would certainly want to know if a human intruder werespotted.

Tyson said this is the first study toinvestigate the risks posed by video streaming traffic generated by thecameras.

The global market for the devices isexpected to be worth $1.3 billion by 2023, according to the press release.Popular brands include Xiaomi and Nest, which is owned by Google.

While the study authors did not analyzedata from those brands, they did find that their cameras present the sameprivacy risk. CNN has reached out to Nest and Xiaomi for comment on theresearch.

The study was published at the IEEEInternational Conference on Computer Communications, which brings togetherresearchers in networking and related fields.

研究表明,当你不在家时,安全摄像头可以通知窃贼

周一公布的一项研究表明,一些流行的家庭安全摄像头可以让窃贼判断你是否已经离开寓所。

研究人员发现,他们可以通过查看摄像机上传的数据,而不是监控视频片段本身,就可以判断出是否有人在家,甚至他们在家里做什么。

这项研究是由伦敦玛丽皇后大学(QMUL)和中国科学院的研究人员利用中国一家大型互联网协议(IP)安全摄像头制造商提供的数据进行的。

这样的摄像头允许用户通过互联网上的视频源远程监控自己的家庭,但研究人员说,这些设备产生的流量可以揭示关于隐私泄露的信息。

QMUL的研究作者泰森指出,当摄像机记录着移动的东西时,未加密数据的数据上传会增加,因此攻击者可以判断摄像机是否上传有人在移动的镜头,甚至是不同类型的运动,如跑步或坐着。

风险是,"有人专门瞄准一个家庭与一个设备,试图开始被动监控交通,"他说。

泰森告诉说,攻击者需要相当水平的技术知识来监控数据本身,但有可能有人可以开发一个类似的程序,并在网上销售。

他指出,他没有看到任何直接的证据证明这种攻击发生过,但如果有人潜入你的房子,它就会成为一个潜在的用途。

"他们可以长时间监控摄像机的流量,然后通过观察这些摄像机在一周内产生的模式,他们可以开始预测下周你最有可能在房子里呆的时间,"他说。

他说,为了降低隐私泄露风险,公司可以随机将数据注入到他们的系统中,使攻击者更难发现其中的模式。

泰森说,该团队正在努力扩大他们的研究,以在降低隐私泄露风险的同时确切保持相机的性能。

泰森说,目前,为了降低制造成本,相机变成了"相当愚蠢的物品",只要检测到运动,它就会上传数据。

"我们希望做的是拥有一个更智能的系统,让摄像机了解每个移动的意义是什么,评估其风险水平,并在相机觉得值得做的情况下提醒用户并且只上传这个移动。"他说。

例如,拥有一只猫的人可能不希望每次相机检测到动物四处走动时都会被提醒,但他们肯定想知道是否发现了人类入侵者。

泰森说,这是首次研究由摄像机产生的视频流量带来的风险。

根据该新闻,到2023年,相关设备的全球市场价值将达到13亿美元。其中包括热门品牌谷歌旗下的小米和雀巢。

虽然研究作者没有分析这些品牌的数据,但他们发现他们的相机存在同样的隐私风险。CNN已经联系了雀巢和小米,要求对这项研究发表评论。

这项研究发表在国际计算机通信国际会议上,该会议汇集了网络及相关领域的研究人员。