Camveil: Unveiling Security Camera Vulnerabilities Through Multi-Protocol Coordinated Fuzzing
Fuchen Ma, Yuqiao Yang, Yuanliang Chen, Yanyang Zhao, Ting Chen, Yu Jiang
摘要
Security cameras are widely deployed in safetycritical environments, supporting real-time video streaming and device control via protocols such as RTSP, ONVIF, and HTTP. Vulnerabilities in these systems can lead to frozen video feeds or surveillance failures, potentially resulting in property or safety losses. While fuzzing is a useful technique for discovering vulnerabilities, existing protocol and IoT fuzzers typically treat each protocol independently, overlooking the cross-protocol dependencies present in real-world cameras. To address this gap, we propose CAMVEIL, a fuzzing framework designed to uncover vulnerabilities in security cameras through multi-protocol coordinated fuzzing. The key insight is that certain protocols can modify the internal state of the camera, indirectly affecting the behavior of other protocols, making some vulnerabilities only discoverable through state-dependent, cross-protocol interaction. To exercise such interactions, CAMVEIL builds a protocol-aware camera status model that abstracts internal camera states and defines their dependencies across protocols. Guided by this model, CAMVEIL generates coordinated test sequences to explore interleaved protocol behaviors. Additionally, it integrates a logic-aware monitoring component that continuously analyzes response packets to detect semantic inconsistencies or abnormal control flows. Using this approach, CAMVEIL has discovered 22 previously unknown vulnerabilities across 9 industrial camera models from Hikvision, Honeywell, TP-Link, FOSCAM, EZVIZ, and Santachi. These flaws could allow attackers to disrupt live video streams or disable camera functionality, potentially causing critical surveillance failures.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- CMFuzz: Parallel Fuzzing of IoT Protocols by Configuration Model Identification and SchedulingQi Xu, Fuchen Ma, Yuanliang Chen, Wanli Chen 等DAC 2025 · 被引用 1 次
- PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous VehiclesFeilong Zuo, Zhengxiong Luo, Junze Yu, Zhe Liu 等DAC 2021 · 被引用 30 次
- SPFuzz: Stateful Path based Parallel Fuzzing for Protocols in Autonomous VehiclesJunze Yu, Zhengxiong Luo, Fangshangyuan Xia, Yanyang Zhao 等DAC 2024 · 被引用 11 次
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen 等WWW 2026
- DRVFuzz: Data-Sensitive RISC-V CPU FuzzingZehong Yu, Yuanliang Chen, Zhen Yan, Xudong Zhang 等USENIX Security 2026
