Cleartext Data Transmissions in Consumer IoT Medical Devices

Daniel Wood,Noah Apthorpe,Nick Feamster
DOI: https://doi.org/10.48550/arXiv.1803.10147
2018-03-27
Cryptography and Security
Abstract:This paper introduces a method to capture network traffic from medical IoT devices and automatically detect cleartext information that may reveal sensitive medical conditions and behaviors. The research follows a three-step approach involving traffic collection, cleartext detection, and metadata analysis. We analyze four popular consumer medical IoT devices, including one smart medical device that leaks sensitive health information in cleartext. We also present a traffic capture and analysis system that seamlessly integrates with a home network and offers a user-friendly interface for consumers to monitor and visualize data transmissions of IoT devices in their homes.
What problem does this paper attempt to address?