Evaluating Security of MQTT Protocol in Internet of Things

被引:2
|
作者
Al-Ani, Ayman [1 ]
Shen, Wong Kang [2 ]
Al-Ani, Ahmed K. [3 ]
Laghari, Shams A. [4 ]
Elejla, Omar E. [5 ]
机构
[1] Univ Malaysia Sabah, Fac Comp & Informat, Cybersecur Res Grp, Jalan UMS, Kota Kinabalu 88400, Sabah, Malaysia
[2] Xiamen Univ Malaysia, Sch Comp & Data Sci, Jalan Sunsuria, Sepang 43900, Selangor, Malaysia
[3] Centennial Coll, Sch Engn Technol & Appl Sci, Toronto, ON, Canada
[4] Univ Sains Malaysia USM, Natl Adv IPv6 Ctr NAv6, Gelugor 11800, Penang, Malaysia
[5] Al Aqsa Univ, Dept Comp Sci, Gaza 4051, Palestine
来源
2023 IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, CCECE | 2023年
关键词
Internet of Things (IoT); IoT Protocols; MQTT; AES-CBC; RSA; ECC AES Hybrid;
D O I
10.1109/CCECE58730.2023.10288857
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The Internet of Things (IoT) has revolutionized the way people interact, communicate, and perform daily activities in various domains ranging from households to industries and cities. MQTT is one of the commonly adopted protocols for implementing IoT. However, IoT systems that are connected through MQTT are susceptible to security breaches as MQTT was not originally designed with security as a priority. The credentials and messages transmitted in plaintext by default, thereby compromising data confidentiality and integrity. This study presents a comprehensive analysis of the MQTT protocol, including experimentation on an MQTT system using various cryptographic implementations, such as AES-CBC, RSA, and ECC AES Hybrid Scheme, to assess the processing time and message size. The findings indicate that payload encryption increases processing time and message bytes. Among the cryptographic implementations, RSA incurs the highest processing time, followed by ECC AES Hybrid Scheme and AES- CBC. Furthermore, the study demonstrates the effectiveness of attack prevention between standard MQTT and secured MQTT implementations by simulating various IoT attacks, such as black-box penetration attack, identity spoofing, DoS attack, and MITM attack. The results and subsequent discussion provide insights that answer the research question, revealing the cryptographic algorithms that result in the most overhead on the standard MQTT implementation and their capacity to resist common attacks.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Security Analysis of the MQTT-SN Protocol for the Internet of Things
    Roldan-Gomez, Jose
    Carrillo-Mondejar, Javier
    Castelo Gomez, Juan Manuel
    Ruiz-Villafranca, Sergio
    APPLIED SCIENCES-BASEL, 2022, 12 (21):
  • [2] PERFORMANCE EVALUATION OF MQTT PROTOCOL IN INTERNET OF THINGS
    Murthy M.Y.B.
    Kumar G.V.S.
    Mrudula K.
    Shaik R.
    Prasad S.K.
    Telecommunications and Radio Engineering (English translation of Elektrosvyaz and Radiotekhnika), 2023, 82 (08): : 51 - 57
  • [3] AES and MQTT based security system in the internet of things
    Ahamed, Jameel
    Zahid, Md
    Omar, Mohd
    Ahmad, Khaleel
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2019, 22 (08): : 1589 - 1598
  • [4] Internet of Things: Survey and open issues of MQTT Protocol
    Yassein, Muneer Bani
    Shatnawi, Mohammed Q.
    Aljwarneh, Shadi
    Al-Hatmi, Razan
    2017 INTERNATIONAL CONFERENCE ON ENGINEERING & MIS (ICEMIS), 2017,
  • [5] Enhancing MQTT Security in the Internet of Things with an Enhanced Symmetric Algorithm
    Mahajan, Rupali Atul
    Mahajan, Rupesh G.
    Tatiya, Manjusha
    Mandekar, Ujjwala Hemant
    Shahakar, Minal
    Patil, Yogendra
    JOURNAL OF ELECTRICAL SYSTEMS, 2024, 20 (01) : 126 - 137
  • [6] A Novel DevSecOps Model for Robust Security in an MQTT Internet of Things
    Ekoramaradhya, Manasa
    Thorpe, Christina
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2022), 2022, : 63 - 71
  • [7] The internet of things healthcare monitoring system based on MQTT protocol
    Alshammari, Hamoud H.
    ALEXANDRIA ENGINEERING JOURNAL, 2023, 69 : 275 - 287
  • [8] Security Mechanism in the Internet of Things by Interacting HTTP and MQTT Protocols
    Almazroi, Abdulaleem Ali
    2019 IEEE 11TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN 2019), 2019, : 181 - 186
  • [9] Formal Specification, Verification and Evaluation of the MQTT Protocol in the Internet of Things
    Houimli, Manel
    Kahloul, Laid
    Benaoun, Sihem
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON MATHEMATICS AND INFORMATION TECHNOLOGY (ICMIT), 2017, : 214 - 221
  • [10] Protocol Security in the Industrial Internet of Things
    Dahlmanns, Markus
    Wehrle, Klaus
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,