The researchers found that they could tell if someone was inside and even what they were doing at home, just by looking at the data downloaded by the camera and without monitoring the video images themselves.
The international study was conducted by researchers from Queen Mary University of London (QMUL) and the Chinese Academy of Science, using data provided by a large Chinese manufacturer of Internet Protocol (IP) security cameras .
Cameras like these allow users to monitor their homes remotely via video over the Internet, but researchers say the traffic generated by the devices can reveal information that compromises privacy.
Study author Gareth Tyson of QMUL told CNN that data downloads of unencrypted data increase when a camera records something in motion, so an attacker could know if the camera was downloading images of a person in motion, and even different types of movements such as running or sitting.
Noting that he saw no direct evidence of this type of attack, he said that potential use would be if someone wanted to rob your house.
“They monitor the traffic of the cameras over a long period of time, and by examining the patterns generated by these cameras for perhaps a week, they then start to predict the following week when you are most likely to be in the house “, he said.
To reduce the risk of confidentiality, companies could randomly inject data into their systems to make it more difficult for attackers to spot a pattern, he said.
Tyson said the team is trying to expand their research to determine how to maintain camera performance while reducing the risks to privacy.
Right now, cameras are “pretty dumb items” to cut manufacturing costs, said Tyson, downloading data every time motion is detected.
“What we want to do is have a smarter system that allows the camera to understand what this movement is, assess the level of risk, download it and alert the user only in if the camera thinks it is worth it, “he said.
For example, someone with a cat probably doesn’t want to be alerted every time the camera detects a walking animal, but they would certainly like to know if a human intruder has been spotted.
Tyson said it was the first study to investigate the risks posed by video streaming traffic generated by cameras.
The global device market is expected to be worth $ 1.3 billion by 2023, according to the press release. Popular brands include Xiaomi and Nest, which is owned by Google.
Although the study authors did not analyze the data from these brands, they found that their cameras posed the same privacy risk. CNN contacted Nest and Xiaomi to comment on the research.
The study was published at the IEEE International Conference on Computer Communications, which brings together researchers in networks and related fields.