Identifiering och Utnyttjande av Sårbarheter hos en IP-Kamera
2021 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesisAlternative title
Identification and Exploitation of Vulnerabilities in an IP-Camera (English)
Abstract [sv]
Idag blir det vanligare och vanligare att system såsom kameror eller kylskåp är eller har kapabiliteten att vara anslutna till internet och kommunicera över nätet av sig själva, så kallade IoT-system. Att ett system är anslutet till internet innebär att risken för angrepp på systemet ökar, och att systemet, om infekterat, har potentialen att kommunicera med omvärlden för att exempelvis utföra denial-of-service-attacker. Detta examensarbete undersöker säkerheten hos en internetansluten kamera (IP-kamera). Målet är att identifiera sårbarheter, och om möjligt, utveckla angrepp som utnyttjar sårbarheter hos kameran, för att testa säkerheten hos systemet. Resultatet visar att systemet är sårbart för ett antal olika angrepp, främst man-in-the-middle och cross-site-request-forgery.
Abstract [en]
Today systems such as cameras or fridges with the capability of being connected to the internet and communicating without human intervention are becoming increasingly common, so called IoT-systems. A system being connected to the internet means that the system’s attack surface is increased, and the system can, if infected, be used by the attacker to communicate with the outside world to perform denial-of-service- or other types of attacks. This thesis examines the security of an internet connected security camera, (IP-camera). The aim is to identify vulnerabilities in the system, and if possible to develop attacks that exploit these vulnerabilities in the goal of evaluating the security of the system. The results show that the system is vulnerable to some attacks, mainly including man-in-the-middle aswell as cross-site-request-forgery based attacks.
Place, publisher, year, edition, pages
2021. , p. 56
Series
TRITA-EECS-EX ; 2021:248
Keywords [en]
Pentesting, Threat modeling, Security, IP-camera, CSRF, MITM, Exploiting, DOS, IoT
Keywords [sv]
Penetrationstesting, Hotmodelling, Säkerhet, IP-kamera, CSRF, MITM, Utnyttjande, DOS, IoT
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:kth:diva-299640OAI: oai:DiVA.org:kth-299640DiVA, id: diva2:1584726
Subject / course
Information Technology
Educational program
Master of Science in Engineering - Information and Communication Technology
Supervisors
Examiners
2021-08-162021-08-132022-06-25Bibliographically approved