The goal of the Mon(IoT)r research group is to provide awareness of the privacy implications of Internet of Things devices, and ultimately produce a means to inform users about what information they share.
What we do
The key research questions we are investigating in the Mon(IoT)r research group are:
- What personally identifiable information (PII) is being leaked, intentionally or otherwise, from IoT devices?
- What can we do to mitigate privacy risks beyond simply encrypting, modifying, or blocking PII?
Our methodology entails recording and analyzing all network traffic generated by a variety of IoT devices that we have acquired. We not only inspect traffic for PII in plaintext, but attempt to man-in-the-middle SSL connections to understand the contents of encrypted flows. Our analysis allows us to uncover how IoT devices are currently protecting users’ PII, and determine how easy or difficult it is to mount attacks against user privacy.
The Mon(IoT)r Lab
The Mon(IoT)r Lab is a first-of-its-kind IoT “living lab” for measuring IoT device network leakage. The lab consists of a “fishbowl” (glass walls) that encloses a space replete with smart devices. Specifically, all of the IoT devices in the lab are configured to use a router instrumented with packet-recording software. We use this lab to conduct controlled experiments, to observe IoT behavior in uncontrolled experiments (through its use by consenting researchers in the research group), and to provide demonstrations of security and privacy research.
There are two ways to get involved in the lab activities:
Personal data collection typically starts on user devices, in a range of application domains (web, mobile, IoT). Data are then shared with service providers as well as with a large number of trackers.
The ProperData project seeks to protect personal data, by improving the transparency and control of personal data flow on the Internet. We take a multidisciplinary approach, combining methodologies from computer science and engineering (theory, network measurement, systems, security) with policy and concepts from economics.
The goal of BehavIoT is to explore the extent to which network-inferred behavioral analysis of IoT deployments, combined with control over the network traffic they generate, can identify and mitigate misbehavior of IoT systems.