The Role of Smart TVs in Proxy Networks
Smart TVs have emerged as a convenient tool for routing internet traffic through unsuspecting homes. With their constant connection to high-speed networks and typically idle status, they provide an ideal host for such activities.
Surprisingly, this practice is already prevalent in millions of living rooms, facilitated by an industry that rents out these devices without the owners’ knowledge. By embedding relay kits into apps like games or screensavers, users unknowingly agree to allow their devices to relay web traffic while not in use.
Most of this traffic consists of commercial web scraping, with some more dubious activities such as using sneaker bots to make multiple purchases from a single household to create artificial demand. The nature of the traffic is irrelevant to the device.
The Legality Issue
While these practices may seem unethical, they are mostly legal, which poses a significant problem. Data scrapers from data centers are easily blocked, while traffic from real homes goes undetected. This has led to the creation of a market where app developers are paid to embed relay kits into their applications to harvest users’ idle devices.
However, the security implications of this setup are concerning. The lack of secure connections and authentication mechanisms makes these relay devices vulnerable to exploitation, with the legal version being even less secure than actual malware.
The Consequences of Exploiting Residential Proxies
Exploiting devices as proxy nodes for nefarious activities, such as DDoS attacks, has become increasingly common. The ease of setting up these devices as botnet nodes, coupled with the legal consent obtained from users, has led to a surge in such activities.
These attacks are not hypothetical and have seen a significant rise in recent years. The exploitation of residential proxies has opened up new avenues for attackers to leverage unsuspecting devices for malicious purposes.
The legal and criminal aspects of this supply chain are intertwined, with one side leveraging the consent dialog to gain access to devices for exploitation. The same device used for web scraping can easily be repurposed for conducting cyber attacks.
Addressing the Behavioral Aspect
One of the challenges in detecting and mitigating these threats lies in the static nature of traditional security measures. Rules and blocklists can be easily circumvented by adversaries who can quickly adapt to new restrictions.
Instead, focusing on the behavioral aspect of network traffic can provide a more effective defense. Anomalies in device behavior, such as opening persistent channels to unknown servers or exhibiting relay-like patterns, can be key indicators of malicious activity.
By monitoring and analyzing device behavior, defenders can proactively identify and mitigate potential threats before they escalate into full-blown attacks. This approach offers a more sustainable defense strategy against evolving cyber threats.
Ultimately, the behavior of a device remains a critical signal in detecting malicious activities, highlighting the importance of continuous monitoring and vigilance in network security.
Jérôme, a security researcher with the Nokia Deepfield Emergency Response Team, specializes in tracking DDoS botnets and residential proxy threats. His expertise helps telecommunications providers, AI and cloud companies, and enterprises enhance their network security measures. With a background in sales and pre-sales across Asia-Pacific, Jérôme holds a Master’s degree from INSA Lyon.
For more information about Jérôme and his work, visit our company website at https://www.nokia.com/people/jerome-meyer/.

