The proliferation of Set-Top Boxes and other uncertified Android devices in homes has opened a new front for Internet service providers. Compromised devices have begun to appear on the networks of various ISPs, operating normally from the user’s perspective while using residential connectivity in the background for malicious activities such as residential proxying, denial-of-service attacks, port scanning and generating anomalous traffic.
Gastón Péchieu, director of Netlink Wireless Internet, and Diego F. Rodríguez, partner at Starnetworks, told Convergencia that between 10% and 50% of an ISP’s customer base could be affected, depending on the area, with the risk higher among providers that do not offer pay TV services. Providers that offer Sensa or Flow, for example, tend to have fewer users with devices bought “around the corner” to access streaming services.
After purchasing these devices cheaply and outside official channels, users believe they have bought a “box” to access content without paying for it. However, behind that function, additional components are downloaded, the customer may become part of a botnet and the home’s connectivity is used for activities the user is unaware of. In some cases observed by operators, the devices generated more than 100 Mbps of upstream traffic, enough to degrade the experience of other devices connected to the Wi-Fi network.
The problem originates with unofficial Android STBs used to access audiovisual content, but has since spread to cameras, projectors, lesser-known-brand televisions and other IoT devices. These infected devices consume capacity on residential connections, generate anomalous traffic, participate in attacks and can turn a subscriber’s IP address into a node in a residential proxy infrastructure.
Residential proxying is particularly sensitive for ISPs. Under this scheme, a third party can use a subscriber’s residential IP address to route traffic through a compromised device. The IP address remains assigned to the customer, but the actual source of certain connections may be an external infrastructure. This creates a gray area between the identity of the connection and the actual source of the traffic, potentially resulting in situations where activity carried out from a residential IP address was not initiated by the user, such as accessing child sexual abuse material.
Cultural dimension. ISPs can identify the behavior, block the traffic and protect their IP address ranges. However, the infection remains inside the home.
The most effective measure may be to disconnect the box itself, but that creates another conflict: the device belongs to the subscriber and is part of their private network. In most cases, this leads to a dispute between the ISP and the customer, who refuses to stop using the “box” (or appears to stop using it) because they are unaware of the risks involved. In this regard, the cultural dimension weighs more heavily than the technical one, the sources warned.