On the Security and Data Integrity of Low-Cost Sensor Networks for Air Quality Monitoring

被引:18
作者
Luo, Lan [1 ]
Zhang, Yue [2 ]
Pearson, Bryan [1 ]
Ling, Zhen [3 ]
Yu, Haofei [4 ]
Fu, Xinwen [1 ]
机构
[1] Univ Cent Florida, Dept Comp Sci, Orlando, FL 32816 USA
[2] Jinan Univ, Coll Informat Sci & Technol, Guangzhou 510632, Guangdong, Peoples R China
[3] Southeast Univ, Sch Comp Sci & Engn, Nanjing 211189, Jiangsu, Peoples R China
[4] Univ Cent Florida, Dept Civil Environm & Construct Engn, Orlando, FL 32816 USA
基金
美国国家科学基金会; 国家重点研发计划;
关键词
IoT; data integrity; low-cost sensor; air quality monitoring; MITM; FIELD CALIBRATION; AVAILABLE SENSORS; POLLUTION; INTERNET; THINGS; CLUSTER; PART;
D O I
10.3390/s18124451
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The emerging connected, low-cost, and easy-to-use air quality monitoring systems have enabled a paradigm shift in the field of air pollution monitoring. These systems are increasingly being used by local government and non-profit organizations to inform the public, and to support decision making related to air quality. However, data integrity and system security are rarely considered during the design and deployment of such monitoring systems, and such ignorance leaves tremendous room for undesired and damaging cyber intrusions. The collected measurement data, if polluted, could misinform the public and mislead policy makers. In this paper, we demonstrate such issues by using a.com, a popular low-cost air quality monitoring system that provides an affordable and continuous air quality monitoring capability to broad communities. To protect the air quality monitoring network under this investigation, we denote the company of interest as a.com. Through a series of probing, we are able to identify multiple security vulnerabilities in the system, including unencrypted message communication, incompetent authentication mechanisms, and lack of data integrity verification. By exploiting these vulnerabilities, we have the ability of "impersonating" any victim sensor in the a.com system and polluting its data using fabricated data. To the best of our knowledge, this is the first security analysis of low-cost and connected air quality monitoring systems. Our results highlight the urgent need in improving the security and data integrity design in these systems.
引用
收藏
页数:22
相关论文
共 38 条
[1]   Proliferation of low-cost sensors. What prospects for air pollution epidemiologic research in Sub-Saharan Africa? [J].
Amegah, A. Kofi .
ENVIRONMENTAL POLLUTION, 2018, 241 :1132-1137
[2]  
[Anonymous], CC3220 SIMPLELINK WI
[3]  
[Anonymous], SAML11 XPLAIN PROEV
[4]  
[Anonymous], IS GEOL IP ADDR
[5]  
[Anonymous], TECHNICAL REPORT
[6]  
[Anonymous], INT PROT ADDR IP GEO
[7]  
[Anonymous], INT J RES ADVENT TEC
[8]  
[Anonymous], 2014, Int. J. Comput. Appl.
[9]   High-Resolution Air Pollution Mapping with Google Street View Cars: Exploiting Big Data [J].
Apte, Joshua S. ;
Messier, Kyle P. ;
Gani, Shahzad ;
Brauer, Michael ;
Kirchstetter, Thomas W. ;
Lunden, Melissa M. ;
Marshall, Julian D. ;
Portier, Christopher J. ;
Vermeulen, Roel C. H. ;
Hamburg, Steven P. .
ENVIRONMENTAL SCIENCE & TECHNOLOGY, 2017, 51 (12) :6999-7008
[10]   The Internet of Things: A survey [J].
Atzori, Luigi ;
Iera, Antonio ;
Morabito, Giacomo .
COMPUTER NETWORKS, 2010, 54 (15) :2787-2805