SlowTT: A Slow Denial of Service against IoT Networks

被引:17
作者
Vaccari, Ivan [1 ,2 ]
Aiello, Maurizio [1 ]
Cambiaso, Enrico [1 ]
机构
[1] Consiglio Nazl Ric CNR, IEIIT Inst, I-16149 Genoa, Italy
[2] Univ Genoa, Dept Informat Bioengn Robot & Syst Engn DIBRIS, I-16145 Genoa, Italy
基金
欧盟地平线“2020”;
关键词
Internet of Things; protocols security; cyber security; network security; slow DoS attack; MQTT; SECURITY; INTERNET; THREATS; THINGS; MQTT;
D O I
10.3390/info11090452
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security of Internet of Things environments is a critical and trending topic, due to the nature of the networks and the sensitivity of the exchanged information. In this paper, we investigate the security of the Message Queue Telemetry Transport (MQTT) protocol, widely adopted in IoT infrastructures. We exploit two specific weaknesses of MQTT, identified during our research activities, allowing the client to configure the KeepAlive parameter and MQTT packets to execute an innovative cyber threat against the MQTT broker. In order to validate the exploitation of such vulnerabilities, we propose SlowTT, a novel "Slow" denial of service attack aimed at targeting MQTT through low-rate techniques, characterized by minimum attack bandwidth and computational power requirements. We validate SlowTT against real MQTT services, by considering both plaintext and encrypted communications and by comparing the effects of the attack when targeting different application daemons and protocol versions. Results show that SlowTT is extremely successful, and it can exploit the identified vulnerability to execute a denial of service against the IoT network by keeping the connection alive for a long time.
引用
收藏
页数:18
相关论文
共 84 条
[1]  
Aiello G, 2016, APPLIED STUDIES OF COASTAL AND MARINE ENVIRONMENTS, P13, DOI 10.5772/61738
[2]  
Aiello Maurizio, 2013, 2013 IEEE Symposium on Computers and Communications (ISCC), P000430, DOI 10.1109/ISCC.2013.6754984
[3]   Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications [J].
Al-Fuqaha, Ala ;
Guizani, Mohsen ;
Mohammadi, Mehdi ;
Aledhari, Mohammed ;
Ayyash, Moussa .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04) :2347-2376
[4]   An overview of security and privacy in smart cities' IoT communications [J].
Al-Turjman, Fadi ;
Zahmatkesh, Hadi ;
Shahroze, Ramiz .
TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (03)
[5]   Internet of Things: A survey on the security of IoT frameworks [J].
Ammar, Mahmoud ;
Russello, Giovanni ;
Crispo, Bruno .
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2018, 38 :8-27
[6]  
Andrea I, 2015, 2015 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), P180, DOI 10.1109/ISCC.2015.7405513
[7]  
Andy S, 2017, 2017 4TH INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING, COMPUTER SCIENCE AND INFORMATICS (EECSI), P571
[8]  
[Anonymous], 2014, IEEE ETFA
[9]   Synthetic lethality between androgen receptor signalling and the PARP pathway in prostate cancer [J].
Asim, Mohammad ;
Tarish, Firas ;
Zecchini, Heather I. ;
Sanjiv, Kumar ;
Gelali, Eleni ;
Massie, Charles E. ;
Baridi, Ajoeb ;
Warren, Anne Y. ;
Zhao, Wanfeng ;
Ogris, Christoph ;
McDuffus, Leigh-Anne ;
Mascalchi, Patrice ;
Shaw, Greg ;
Dev, Harveer ;
Wadhwa, Karan ;
Wijnhoven, Paul ;
Forment, Josep V. ;
Lyons, Scott R. ;
Lynch, Andy G. ;
O'Neill, Cormac ;
Zecchini, Vincent R. ;
Rennie, Paul S. ;
Baniahmad, Aria ;
Tavare, Simon ;
Mills, Ian G. ;
Galanty, Yaron ;
Crosetto, Nicola ;
Schultz, Niklas ;
Neal, David ;
Helleday, Thomas .
NATURE COMMUNICATIONS, 2017, 8
[10]   IoT real time data acquisition using MQTT protocol [J].
Atmoko, R. A. ;
Riantini, R. ;
Hasin, M. K. .
INTERNATIONAL CONFERENCE ON PHYSICAL INSTRUMENTATION AND ADVANCED MATERIALS, 2017, 853