Securing Smart Homes and Buildings: Threats and Risks to Complex IoT Environments

The evolution of smart homes and smart buildings into complex IoT environments reflects the continuing developments in home and industrial automation. Security should not be left behind as increased complexity also means new threats and risks.
One of the most enticing images of the future has been that of technology that allows ordinary objects to seemingly come to life to cater to our personal needs. A certain version of that future has already materialized in present time. The internet-of-things (IoT) has made possible a new kind of space where that future exists — complex IoT environments (CIE).
A CIE consists of at least 10 IoT devices that are functionally chained together and integrated into an environment using an IoT automation platform. CIEs are more commonly exemplified by smart homes, but are not restricted to them. IoT automation platforms can be scaled up to control devices in larger structures like smart buildings.
For a better understanding of CIEs, we can look at the most familiar implementation: the smart home. Integral to a smart home is internet connection throughout the entire CIE, which requires Ethernet or fiber wiring and modems and Wi-Fi routers. Devices integrated into the environment can include a gateway, smart bulbs, smart locks, speakers, TVs, and many others. Even traditional appliances like toasters can take on more complicated functions through smart plugs. The number and the types of devices in a CIE dictate the possible commands, interactions, and functionalities. The number should be significant enough to create dynamic interactions.
As mentioned previously, what enables these individual devices to work together are software products called IoT automation platforms (also called automation servers). An IoT automation platform serves as a brain of sorts for the CIE and allows the creation of smart applications by functionally chaining the devices through custom rules, thus allowing devices to interact and affect each other’s actions. The complexity afforded by automation platforms expands the possibilities in smart homes and buildings and other setups in various settings. But the increasing complexity with each additional device and automation rule also means an expanding attack surface. Therefore, we must look at the challenges CIEs pose, specifically cybersecurity risks.
To look into the security of CIEs and automation servers, we set up smart home labs and tested possible threat scenarios on actual CIEs. A comprehensive discussion on what we learned can be found in our research, Cybersecurity Risks in Complex IoT Environments. We highlight some of our findings here.
A CIE integrates various devices and systems. For smart homes, it ranges from lighting and entertainment to security. This means the automation platform also has control over functions that are essential to the safety and privacy of the home’s residents, like keeping entryways secured or setting up security alarms. In our research, we explored scenarios wherein attackers can seize control of a CIE. One scenario that we tested involves compromising the CIE’s automation server. As mentioned earlier, the automation server is where all the automation rules that govern the function and interaction of devices in the CIE are stored. We had full read-write control to modify/update those rules. Several possible risks arise when this server is exposed online and the rule set is compromised. If smart locks are installed and connected to the CIE, then attackers could modify automation rules that would allow them entry into the home. These rule modifications could make the sensors either recognize the attacker as one of the homeowners or leave the doors unlocked.


