From 0afe49053cb62dbdba0bdd9dd49cd4253902348d Mon Sep 17 00:00:00 2001 From: malmert Date: Thu, 2 Apr 2026 22:40:36 +0200 Subject: [PATCH] first thesis start --- documentation/thesis/.gitignore | 23 ++++ documentation/thesis/00-acronyms.tex | 18 ++++ documentation/thesis/00-commands.tex | 18 ++++ documentation/thesis/00-oath.tex | 35 ++++++ documentation/thesis/00-packages.tex | 153 +++++++++++++++++++++++++++ documentation/thesis/00-settings.tex | 73 +++++++++++++ documentation/thesis/00-title.tex | 39 +++++++ documentation/thesis/appendix.tex | 74 +++++++++++++ documentation/thesis/main.tex | 107 +++++++++++++++++++ 9 files changed, 540 insertions(+) create mode 100644 documentation/thesis/.gitignore create mode 100644 documentation/thesis/00-acronyms.tex create mode 100644 documentation/thesis/00-commands.tex create mode 100644 documentation/thesis/00-oath.tex create mode 100644 documentation/thesis/00-packages.tex create mode 100644 documentation/thesis/00-settings.tex create mode 100644 documentation/thesis/00-title.tex create mode 100644 documentation/thesis/appendix.tex create mode 100644 documentation/thesis/main.tex diff --git a/documentation/thesis/.gitignore b/documentation/thesis/.gitignore new file mode 100644 index 0000000..629529c --- /dev/null +++ b/documentation/thesis/.gitignore @@ -0,0 +1,23 @@ +# LaTeX build artifacts +*.aux +*.bbl +*.bcf +*.blg +*.fdb_latexmk +*.fls +*.idx +*.ilg +*.ind +*.lof +*.log +*.lot +*.out +*.run.xml +*.synctex.gz +*.toc + +# Latexmk / cache +_latexmk* + +# PDFs generated during local editing +*.pdf diff --git a/documentation/thesis/00-acronyms.tex b/documentation/thesis/00-acronyms.tex new file mode 100644 index 0000000..45ee240 --- /dev/null +++ b/documentation/thesis/00-acronyms.tex @@ -0,0 +1,18 @@ +\chapter*{List of Acronyms} +\addcontentsline{toc}{chapter}{List of Acronyms} + +\begin{acronym}[HTTPS] % Give the longest label here so that the list is nicely aligned + \acro{API}{Application Programming Interface} + \acro{HTML}{HyperText Markup Language} + \acro{HTTPS}{Hypertext Transfer Protocol Secure} + \acro{HTTP}{Hypertext Transfer Protocol} + \acro{IP}{Internet Protocol} + \acro{MAC}{Media Access Control} + \acro{SSID}{Service Set Identifier} + \acro{SSL}{Secure Sockets Layer} + \acro{TCP}{Transmission Control Protocol} + \acro{TLS}{Transport Layer Security} + \acro{UDP}{User Data Protocol} + \acro{URI}{Uniform Resource Identifier} + \acro{URL}{Uniform Resource Locator} +\end{acronym} diff --git a/documentation/thesis/00-commands.tex b/documentation/thesis/00-commands.tex new file mode 100644 index 0000000..1515979 --- /dev/null +++ b/documentation/thesis/00-commands.tex @@ -0,0 +1,18 @@ +\newcommand{\AES}{\textbf{\texttt{AES}}\xspace} + +\newcommand{\subbytes}{\textbf{\texttt{SubBytes}}\xspace} +\newcommand{\SB}{\textbf{\texttt{SB}}\xspace} + +\newcommand{\mixcolumns}{\textbf{\texttt{MixColumns}}\xspace} +\newcommand{\MC}{\textbf{\texttt{MC}}\xspace} + +\newcommand{\shiftrows}{\textbf{\texttt{ShiftRows}}\xspace} +\newcommand{\SR}{\textbf{\texttt{SR}}\xspace} + +\newcommand{\addrk}{\textbf{\texttt{AddRoundKey}}\xspace} +\newcommand{\ARK}{\textbf{\texttt{ARK}}\xspace} + +\newcommand{\term}[2]{\textbf{#1:}\\#2\\} +%\newcommand{\term}[2]{\textbf{#1:}\\\begingroup\leftskip#2\endgroup} + +\newcommand{\cmt}[2]{\textcolor{red}{\sout{#1}#2}} diff --git a/documentation/thesis/00-oath.tex b/documentation/thesis/00-oath.tex new file mode 100644 index 0000000..e418751 --- /dev/null +++ b/documentation/thesis/00-oath.tex @@ -0,0 +1,35 @@ +%----------------------------------------------------------------------- +\chapter*{Eidesstattliche Erklärung} +%----------------------------------------------------------------------- + +I, \theauthor, hereby declare that I have authored this master's thesis with title +\begin{quote} + \thetitle +\end{quote} +independently, that I have not used other than the declared sources / resources, +and that I have explicitly marked all material which has been quoted either +literally or by content from the used sources. The work was not submitted in same +or similar form or in parts in the context of another examination yet. + +\vspace{4em} + + +Ich, \theauthor, versichere hiermit, dass ich meine +Masterarbeit mit dem Thema +\begin{quote} + \thetitle +\end{quote} +selbstständig verfasst und keine anderen als die angegebenen Quellen und +Hilfsmittel benutzt habe, wobei ich alle wörtlichen und sinngemäßen +Zitate als solche gekennzeichnet habe. Die Arbeit wurde bisher keiner +anderen Prüfungsbehörde vorgelegt und auch nicht veröffentlicht. + +\vspace{4em} + +\noindent +\begin{minipage}{\columnwidth} +\rule{7cm}{.1pt}\\ +\tiny{\theauthor} +\end{minipage} +\\[2em] +Weimar, TBD\\ diff --git a/documentation/thesis/00-packages.tex b/documentation/thesis/00-packages.tex new file mode 100644 index 0000000..a62f3b6 --- /dev/null +++ b/documentation/thesis/00-packages.tex @@ -0,0 +1,153 @@ +%----------------------------------------------------------------------- +% Packages +%----------------------------------------------------------------------- + +\usepackage{geometry} +\usepackage[T1]{fontenc} +\usepackage{lmodern} +\usepackage{microtype} +\usepackage[english]{babel} +\usepackage[dvipsnames]{xcolor} +\usepackage{float} +\usepackage[noend]{algpseudocode} +\usepackage{algorithm} +\usepackage{amsmath} +\usepackage{amsthm} +\usepackage{amssymb} +\usepackage{graphicx} +\usepackage{enumitem} +\usepackage{listings} +%\usepackage[numbers,sort&compress]{natbib} +%\usepackage[zerostyle=d]{newtxtt} +\usepackage{hyphenat} +\usepackage{xspace} +\usepackage{ifthen} +\usepackage[format=hang +%singlelinecheck=off +]{caption} +\usepackage{subcaption} +\usepackage{wrapfig} +\usepackage{booktabs} % for tables: \toprule, \midrule, \bottomrule +\usepackage{multirow} +\usepackage{acronym} +\usepackage{csquotes} +\usepackage[normalem]{ulem} +\usepackage{scrhack} +\usepackage[automark]{scrlayer-scrpage} +\usepackage{siunitx} + +\usepackage[ +sortcites, +backend=biber, +natbib=true, +style=numeric, +sorting=nyt +]{biblatex} + +\usepackage{hyperref} +\usepackage{bookmark} +\usepackage[nameinlink,noabbrev]{cleveref} + +\usepackage{tikz} +\usetikzlibrary{arrows.meta} +\usetikzlibrary{positioning} +\usetikzlibrary{decorations.pathreplacing} +%\usetikzlibrary{keccaktree} + + +\usepackage{fancyvrb} +\usepackage{verbatimbox} +%\usepackage{tgcursor} + + + + +\colorlet{punct}{red!60!black} +\definecolor{background}{HTML}{EEEEEE} +\definecolor{delim}{RGB}{20,105,176} +\colorlet{numb}{magenta!60!black} + + +% --------------------------------------------------------------------- +% Listings +% --------------------------------------------------------------------- + + +\lstdefinestyle{verbatim}{ + basicstyle=\small\ttfamily, + breaklines=true, + columns=fullflexible, + basewidth=0.5em, + escapechar=\%, + numbers=none, + numbersep=none, + captionpos=b, + frame=none, + escapeinside={(*}{*)}, + xleftmargin=0em +} + +%\lstset{% +% language=Ada, +% basicstyle=\footnotesize\ttfamily, +% frame=l, +% xleftmargin=\parindent, +% % rulecolor=\color{blue}, +% framerule=2pt, +% captionpos=b, +% keywordstyle=\bfseries, +% % stringstyle=\color{green}, +% % commentstyle=\color{gray}, +% showstringspaces=false} +% + + +\lstset{ % +backgroundcolor=\color{white}, % choose the background color; you must add \usepackage{color} or \usepackage{xcolor} +basicstyle=\footnotesize\ttfamily, % the size of the fonts that are used for the code +breakatwhitespace=false, % sets if automatic breaks should only happen at whitespace +breaklines=true, % sets automatic line breaking +captionpos=b, % sets the caption-position to bottom +commentstyle=\color{red}, % comment style +deletekeywords={...}, % if you want to delete keywords from the given language +escapeinside={\%*}{*)}, % if you want to add LaTeX within your code +extendedchars=true, % lets you use non-ASCII characters; for 8-bits encodings only, does not work with UTF-8 +frame=l, % adds a frame around the code +keepspaces=true, % keeps spaces in text, useful for keeping indentation of code (possibly needs columns=flexible) +keywordstyle=\bfseries, % keyword style +%language=Python, % the language of the code +morekeywords={*,...}, % if you want to add more keywords to the set +numbers=left, % where to put the line-numbers; possible values are (none, left, right) +numbersep=5pt, % how far the line-numbers are from the code +numberstyle=\tiny\color{black}, % the style that is used for the line-numbers +rulecolor=\color{black}, % if not set, the frame-color may be changed on line-breaks within not-black text (e.g. comments (green here)) +showspaces=false, % show spaces everywhere adding particular underscores; it overrides 'showstringspaces' +showstringspaces=false, % underline spaces within strings only +showtabs=true, % show tabs within strings adding particular underscores +stepnumber=1, % the step between two line-numbers. If it's 1, each line will be numbered +stringstyle=\color{blue}, % string literal style +tabsize=2, % sets default tabsize to 2 spaces +title=\lstname, % show the filename of files included with \lstinputlisting; also try caption instead of title +xleftmargin=1.5em +} + +\lstdefinelanguage{json}{ + basicstyle=\scriptsize\ttfamily, + numbers=left, + numberstyle=\scriptsize, + stepnumber=1, + numbersep=8pt, + showstringspaces=true, + breaklines=true, + frame=none, + numberstyle=\scriptsize\color{black}, + backgroundcolor=\color{white}, + literate= + *{:}{{{\color{punct}{:}}}}{1} + {,}{{{\color{punct}{,}}}}{1} + {\{}{{{\color{delim}{\{}}}}{1} + {\}}{{{\color{delim}{\}}}}}{1} + {[}{{{\color{delim}{[}}}}{1} + {]}{{{\color{delim}{]}}}}{1}, +} + diff --git a/documentation/thesis/00-settings.tex b/documentation/thesis/00-settings.tex new file mode 100644 index 0000000..213f844 --- /dev/null +++ b/documentation/thesis/00-settings.tex @@ -0,0 +1,73 @@ +% --------------------------------------------------------------------- +% General Settings +% --------------------------------------------------------------------- + +\graphicspath{{./images/}} +\renewcommand{\baselinestretch}{1.2} +\setcounter{tocdepth}{1} +\setcounter{secnumdepth}{3} +\setlength{\parindent}{1.5em} +\setlength{\parskip}{0pt} +%\setlanguage{english} + +% \renewcommand{\ttdefault}{txtt} + +% \definecolor{myblue}{rgb}{0.0,0.37,0.69} +% \definecolor{mygray}{rgb}{0.62,0.62,0.62} +% \definecolor{myorange}{rgb}{0.84,0.53,0.0} + + +% --------------------------------------------------------------------- +% Headings +% --------------------------------------------------------------------- + +%\let\Chaptermark\chaptermark +%\def\chaptermark#1{ +% \def\Chaptername{#1}\Chaptermark{#1} +% \markright{\chaptermarkformat\Chaptername \hfill}} +%\let\Sectionmark\sectionmark +%\def\sectionmark#1{ +% \def\Sectionname{#1}\Sectionmark{#1} + % \markright{\chaptermarkformat\Chaptername \hfill +% \sectionmarkformat\Sectionname}} + +% --------------------------------------------------------------------- +% Acronyms +% --------------------------------------------------------------------- + +% \newlist{acronyms}{description}{1} +% \setlist[acronyms]{ +% labelwidth=4em, +% leftmargin=4.5em, +% % noitemsep, +% itemindent=0pt +% } + +% \acsetup{ +% single=false, +% hyperref=true, +% long-format=\itshape, +% list-long-format=, +% list-type=acronyms +% } + +% \newcommand{\acro}[2]{ +% \DeclareAcronym{#1}{ +% short = #1, +% long = #2 +% }} + + +% --------------------------------------------------------------------- +% Example Float +% --------------------------------------------------------------------- + + + +% --------------------------------------------------------------------- +% Hyphenation +% --------------------------------------------------------------------- + +%\touchttfonts{} % hyphenation inside texttt (hyphenat package) + +\hyphenation{Pfad-va-li-die-rung Per-for-mance} diff --git a/documentation/thesis/00-title.tex b/documentation/thesis/00-title.tex new file mode 100644 index 0000000..5756cf7 --- /dev/null +++ b/documentation/thesis/00-title.tex @@ -0,0 +1,39 @@ +\begin{titlepage} + +% \linespread{1} +% \Large + +\noindent +Bauhaus-Universität Weimar\\ +Faculty of Media\\ +Program Computer Science for Digital Media + +\vspace{6em} + +\begin{center} + {\bfseries \sffamily \huge + \thetitle} + \\[2em] + {\bfseries \sffamily \LARGE Master's Thesis} +\end{center} + +\vspace{12em} + +\noindent +\theauthor +\hfill +Matriculation Number: 119915\\ +born 22.09.1999 in Bad Salzungen + +\vspace{6em} + +\noindent +1st~Reviewer: PD Dr. Andreas Jakoby\\ +2nd~Reviewer: TBD + +\vspace{6em} + +\noindent +Date of Submission: TBD\\ + +\end{titlepage} diff --git a/documentation/thesis/appendix.tex b/documentation/thesis/appendix.tex new file mode 100644 index 0000000..79456a9 --- /dev/null +++ b/documentation/thesis/appendix.tex @@ -0,0 +1,74 @@ +%----------------------------------------------------------------------- +\chapter{Appendix} +\label{ch:appendix} +%----------------------------------------------------------------------- +The following listing shows example data accessible via the \ac{HTTP} request shown in Listing~\ref{lst:userid-request}. +This data is can be gathered by an adversary through an \ac{URL}-manipulation attack on the \texttt{userID} parameter.\\[0.2cm] +\begin{lstlisting}[language=json, caption={Example data gathered through the URL-manipulation attack on the Victure VD300 backend using the request shown in Listing~\ref{lst:userid-request}.}, label={lst:userid_url}] +{ + "light": [], + "doorbell": [ + { + "nvrID": 0, + "devStatus": 1, + "updateVersion": false, + "bellVoice": "", + "iotType": 1, + "deviceImg": null, + "deviceName": , + "userID": , + "closePush": 0, + "devUid": "", + "nvrNum": "", + "cloudType": 1, + "deviceP2P": "ppcs", + "isBindingTY": "D", + "radius": "-1", + "relayLicenseID": "", + "deviceUUID": , + "longitude": "200", + "hasAlertMsg": true, + "deviceTypeName": "https://meari-eu.oss-eu-central-1.aliyuncs.com/deviceInfo/bell7s.png", + "timeZone": "UTC01:00", + "snNum": , + "updatePersion": "N", + "devTypeID": 4, + "cloudSupport": 0, + "userAccount": ", + "voicemail": + "trialCloud": 0, + "region": "Europe/Berlin", + "nvrKey": "", + "userFlag": "Y", + "latitude": "200", + "p2pInit": "", + "deviceVersionID": "ppstrong-b5-apeman-3.1.2.20200324", + "sleep": "off", + "capability": "{\"ver\":21,\"cat\":\"bell\",\"caps\":{\"pdt\":13,\"dnm\":1,\"cs2\":113,\"alp\":1,\"cst\":1,\"pwm\":1,\"rng\":3,\"vtk\":4,\"nst\":1,\"hms\":2,\"sd\":1,\"spp\":1,\"cse\":1,\"ecs\":0,\"cct\":0,\"esd\":50,\"pir\":4,\"btl\":0,\"ota\":1,\"ovc\":1,\"wkp\":1}}", + "firmID": 8, + "nvrUUID": "", + "wifiName": "", + "cloudstatus": 4, + "asFriend": false, + "protocolVersion": 4, + "timeZone2": "CET01:00:00CEST02:00:00,M3.5.0,M10.5.0", + "awsThingName": "", + "awsCloudCompat": 1, + "shareAccessSign": 0, + "hostKey": "", + "hostKey1": "", + "deviceID": , + "tp": "", + "nvrPort": -1, + "p2pInitApp": ":WeEye2ppStronGer" + } + ], + "resultCode": "1001", + "nvr": [], + "fourthGeneration": [], + "ipc": [], + "snap": [], + "voiceBell": [], + "chime": [] + } +\end{lstlisting} diff --git a/documentation/thesis/main.tex b/documentation/thesis/main.tex new file mode 100644 index 0000000..130fa81 --- /dev/null +++ b/documentation/thesis/main.tex @@ -0,0 +1,107 @@ +\documentclass[a4paper,11pt,headlines=2.1,bibliography=totoc,numbers=noenddot]{scrreport} + +\usepackage{setspace} + + +%----------------------------------------------------------------------- +\input{00-commands} +\input{00-packages} +\input{00-settings} +\setlength{\aboverulesep}{0pt} +\setlength{\belowrulesep}{0pt} + +% fixes inserted empty space if text does not fit +\raggedbottom + +%\bibliography{ba} +\addbibresource{ba.bib} +%----------------------------------------------------------------------- + +\newcommand{\thetitle} +{An Investigation of the Security of Smart Doorbells} +\newcommand{\theauthor}{Marcus Jan Almert} + +\title{\thetitle} +\author{\theauthor} + +\hypersetup{ + pdftitle={\thetitle}, + pdfauthor={\theauthor}, + pdfsubject={Master's Thesis}, + pdfcreator={LaTeX}, + colorlinks=true, + linkcolor=black, + citecolor=black, + urlcolor=blue +} + +\clearpairofpagestyles +\ihead{\headmark} +\ohead{} +\cfoot*{\pagemark} + +\RedeclareSectionCommand[ + beforeskip=-1sp +]{chapter} + +%----------------------------------------------------------------------- +\begin{document} +%----------------------------------------------------------------------- + +\pagenumbering{gobble} + +\include{00-title} + + + +\makeatletter +\let\ACplacelabel\AC@placelabel +\makeatother + +\pagenumbering{Roman} + +\include{00-abstract} +%\include{acknowledgements} + +\include{00-oath} + +\pagenumbering{arabic} + +\begin{spacing}{1.05} + \tableofcontents +\end{spacing} + +\include{00-acronyms} + +%\listoftables +%\listoffigures +%\lstlistoflistings + + +%----------------------------------------------------------------------- + +%\printacronyms[heading=chapter*] +%\markright{Acronyms} +%\newpage + + +%----------------------------------------------------------------------- +\pagestyle{scrheadings} +%\include{01-introduction} +%\include{02-preliminaries} + + + +%----------------------------------------------------------------------- + +\newpage +\emergencystretch=4em + +\printbibliography +\newpage +\appendix +\include{appendix} + +%----------------------------------------------------------------------- + +\end{document}