Tagliaro, C., Komsic, M., Continella, A., Borgolte, K., & Lindorfer, M. (2024). Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols. In RAID ’24: Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses (pp. 561–578). https://doi.org/10.1145/3678890.3678899
RAID '24: Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses
-
ISBN:
9798400709593
-
Datum (veröffentlicht):
2024
-
Veranstaltungsname:
27th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2024)
en
Veranstaltungszeitraum:
30-Sep-2024 - 2-Oct-2024
-
Veranstaltungsort:
Padua, Italy
-
Umfang:
18
-
Peer Reviewed:
Ja
-
Keywords:
Internet of Things (IoT); Backend Security; Large-scale Measurements; Message Queue Telemetry Transport (MQTT); Constrained Application Protocol (CoAP); Extensible Messaging and Presence Protocol (XMPP); Network Security; Information Leakage; Denial of Service; Weak Authentication
en
Abstract:
Internet-of-Things (IoT) devices, ranging from smart home assistants to health devices, are pervasive: Forecasts estimate their number to reach 29 billion by 2030. Understanding the security of their machine-to-machine communication is crucial. Prior work focused on identifying devices’ vulnerabilities or proposed protocol-specific solutions. Instead, we investigate the security of backends speaking IoT protocols, that is, the backbone of the IoT ecosystem.
We focus on three real-world protocols for our large-scale analysis: MQTT, CoAP, and XMPP. We gather a dataset of over 337,000 backends, augment it with geographical and provider data, and perform non-invasive active measurements to investigate three major security threats: information leakage, weak authentication, and denial of service. Our results provide quantitative evidence of a problematic immaturity in the IoT ecosystem. Among other issues, we find that 9.44% backends expose information, 30.38% CoAP-speaking backends are vulnerable to denial of service attacks, and 99.84% of MQTT- and XMPP-speaking backends use insecure transport protocols (only 0.16% adopt TLS, of which 70.93% adopt a vulnerable version).
en
Projekttitel:
IoTIO: Analyse des Internet der Unsicheren Dinge: ICT19-056 (WWTF Wiener Wissenschafts-, Forschu und Technologiefonds)