User experiences with simulated cyber‑physical attacks on smart home IoT

dc.contributor.authorHuijts, N. M. A.
dc.contributor.authorHaans, A.
dc.contributor.authorBudimir, S.
dc.contributor.authorFontaine, J. R. J.
dc.contributor.authorLoukas, G.
dc.contributor.authorBezemskij, A.
dc.contributor.authorOostveen, Anne-Marie
dc.contributor.authorFilippoupolitis, A.
dc.contributor.authorRas, I.
dc.contributor.authorIJsselsteijn, W. A.
dc.contributor.authorRoesch, E. B.
dc.date.accessioned2023-10-02T14:36:41Z
dc.date.available2023-10-02T14:36:41Z
dc.date.issued2023-09-22
dc.description.abstractWith the Internet of Things (IoT) becoming increasingly prevalent in people’s homes, new threats to residents are emerging such as the cyber-physical attack, i.e. a cyber-attack with physical consequences. In this study, we aimed to gain insights into how people experience and respond to cyber-physical attacks to their IoT devices. We conducted a naturalistic field experiment and provided 9 Dutch and 7 UK households, totalling 18 and 13 participants respectively, with a number of smart devices for use in their home. After a period of adaptation, simulated attacks were conducted, leading to events of varying noticeability (e.g., the light going on or off once or several times). After informing people simulated attacks had occurred, the attacks were repeated one more time. User experiences were collected through interviews and analysed with thematic analyses. Four relevant themes were identified, namely (1) the awareness of and concern about privacy and security risks was rather low, (2) the simulated attacks made little impression on the participants, (3) the participants had difficulties with correctly recognizing simulated attacks, and (4) when informed about simulated attacks taking place; participants noticed more simulated attacks and presented decision rules for them (but still were not able to identify and distinguish them well—see Theme 3). The findings emphasise the need for training interventions and an intrusion detection system to increase detection of cyber-physical attacks.en_UK
dc.description.sponsorshipEuropean Union funding: G0H6416N-FWOOPR201600970; Engineering and Physical Sciences Research Council (EPSRC): EP/P016448/1; NWO: 651.002.002en_UK
dc.identifier.citationHuijts NMA, Haans A, Budimir S, et al., (2023) User experiences with simulated cyber‑physical attacks on smart home IoT, Personal and Ubiquitous Computing, Volume 27, December 2023, pp. 2243–2266en_UK
dc.identifier.eissn1617-4917
dc.identifier.issn1617-4909
dc.identifier.urihttps://doi.org/10.1007/s00779-023-01774-5
dc.identifier.urihttps://dspace.lib.cranfield.ac.uk/handle/1826/20315
dc.language.isoenen_UK
dc.publisherSpringeren_UK
dc.rightsAttribution 4.0 International*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/*
dc.subjectcyber-attacken_UK
dc.subjectIoTen_UK
dc.subjectsmart homeen_UK
dc.subjectthematic analysisen_UK
dc.subjectrisk perceptionen_UK
dc.titleUser experiences with simulated cyber‑physical attacks on smart home IoTen_UK
dc.typeArticleen_UK

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Smart_home_IoT-2023.pdf
Size:
715.93 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.63 KB
Format:
Item-specific license agreed upon to submission
Description: