Security Analysis of AWS-based Video Surveillance Systems

被引:0
|
作者
Aklamati, Davies [1 ]
Abdus-Shakur, Basheerah [2 ]
Kacem, Thabet [1 ]
机构
[1] Univ Dist Columbia, Dept Comp Sci & Informat Technol, Washington, DC 20008 USA
[2] Univ Dist Columbia & Informat Technol, Dept Comp Sci, Washington, DC USA
基金
美国国家科学基金会;
关键词
Cloud computing; Cloud Video Surveillance; Video Surveillance Systems; Amazon Web Services (AWS); Video Surveillance Cyber Security; MECHANISM;
D O I
10.1109/ICEET53442.2021.9659574
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the last few years, Cloud computing technology has benefited many organizations that have embraced it as a basis for revamping the IT infrastructure. Cloud computing utilizes Internet capabilities in order to use other computing resources. Amazon Web Services (AWS) is one of the most widely used cloud providers that leverages the endless computing capabilities that the cloud technology has to offer. AWS is continuously evolving to offer a variety of services, including but not limited to, infrastructure as a service (IaaS), platform as a service (PaaS) and packaged software as a service. Among the other important services offered by AWS is Video Surveillance as a Service (VSaaS) that is a hosted cloud-based video surveillance service. Even though this technology is complex and widely used, some security experts have pointed out that some of its vulnerabilities can be exploited in launching attacks aimed at cloud technologies. In this paper, we present a holistic security analysis of cloud-based video surveillance systems by examining the vulnerabilities, threats, and attacks that these technologies are susceptible to. We illustrate our findings by implementing several of these attacks on a test bed representing an AWS-based video surveillance system. The main contributions of our paper are: (1) we provided a holistic view of the security model of cloud based video surveillance summarizing the underlying threats, vulnerabilities and mitigation techniques (2) we proposed a novel taxonomy of attacks targeting such systems (3) we implemented several related attacks targeting cloud-based video surveillance system based on an AWS test environment and provide some guidelines for attack mitigation. The outcome of the conducted experiments showed that the vulnerabilities of the Internet Protocol (IP) and other protocols granted access to unauthorized VSaaS files. We aim that our proposed work on the security of cloud-based video surveillance systems will serve as a reference for cybersecurity researchers and practitioners who aim to conduct research in this field.
引用
收藏
页码:804 / 809
页数:6
相关论文
共 50 条
  • [1] Reachability Analysis for AWS-Based Networks
    Backes, John
    Bayless, Sam
    Cook, Byron
    Dodge, Catherine
    Gacek, Andrew
    Hu, Alan J.
    Kahsai, Temesghen
    Kocik, Bill
    Kotelnikov, Evgenii
    Kukovec, Jure
    McLaughlin, Sean
    Reed, Jason
    Rungta, Neha
    Sizemore, John
    Stalzer, Mark
    Srinivasan, Preethi
    Subotic, Pavle
    Varming, Carsten
    Whaley, Blake
    COMPUTER AIDED VERIFICATION, CAV 2019, PT II, 2019, 11562 : 231 - 241
  • [2] The Security of IP-Based Video Surveillance Systems
    Kalbo, Naor
    Mirsky, Yisroel
    Shabtai, Asaf
    Elovici, Yuval
    SENSORS, 2020, 20 (17) : 1 - 27
  • [3] Optimal Control for AWS-Based Wave Energy Conversion System
    Wu, Feng
    Zhang, Xiao Ping
    Ju, Ping
    Sterling, Michael J. H.
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2009, 24 (04) : 1747 - 1755
  • [4] Social Security Video Surveillance Systems
    Mao, Lin
    Yong, Wang
    Gang, Shi
    MATERIALS SCIENCE AND INFORMATION TECHNOLOGY, PTS 1-8, 2012, 433-440 : 5906 - 5910
  • [5] Accelerometer Based Digital Video Stabilization for Security Surveillance Systems
    Drahansky, Martin
    Orsag, Filip
    Hanacek, Petr
    SECURITY TECHNOLOGY, PROCEEDINGS, 2009, 58 : 225 - 233
  • [6] A Literature Review on AWS-Based Cloud Computing: A Case in South Korea
    Lee, Byeongcheon
    Oh, Jinyeong
    Shon, Woojin
    Moon, Jihoon
    2023 IEEE INTERNATIONAL CONFERENCE ON BIG DATA AND SMART COMPUTING, BIGCOMP, 2023, : 403 - 406
  • [7] Accelerometer Based Digital Video Stabilization for General Security Surveillance Systems
    Drahansky, Martin
    Orsag, Filip
    Hanacek, Petr
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2010, 4 (01): : 1 - 9
  • [8] MPPT strategy based on speed control for AWS-based wave energy conversion system
    Marei, Mostafa I.
    Mokhtar, Mohamed
    El-Sattar, Ahmed A.
    RENEWABLE ENERGY, 2015, 83 : 305 - 317
  • [9] Impact of Video Surveillance Systems on ATM PIN Security
    Seneviratne, Piyumi
    Perera, Dilanka
    Samarasekara, Harinda
    Keppitiyagama, Chamath
    Thilakarathna, Kenneth
    De Soyza, Kasun
    Wijesekara, Primal
    2020 20TH INTERNATIONAL CONFERENCE ON ADVANCES IN ICT FOR EMERGING REGIONS (ICTER-2020), 2020, : 59 - 64
  • [10] Modeling and control of AWS-based wave energy conversion system integrated into power grid
    Wu, Feng
    Zhang, Xiao-Ping
    Ju, Ping
    Sterling, Michael J. H.
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2008, 23 (03) : 1196 - 1204