Data Exfiltration From Internet of Things Devices: iOS Devices as Case Studies

被引:83
作者
D'Orazio, Christian J. [1 ]
Choo, Kim-Kwang Raymond [1 ,2 ,3 ]
Yang, Laurence T. [4 ,5 ]
机构
[1] Univ South Australia, Sch Informat Technol & Math Sci, Adelaide, SA 5001, Australia
[2] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
[3] China Univ Geosci, Sch Comp Sci, Wuhan 430074, Peoples R China
[4] Huazhong Univ Sci & Technol, Sch Comp Sci & Technol, Wuhan 430074, Peoples R China
[5] St Francis Xavier Univ, Dept Comp Sci, Antigonish, NS B2G 2W5, Canada
来源
IEEE INTERNET OF THINGS JOURNAL | 2017年 / 4卷 / 02期
基金
加拿大创新基金会;
关键词
Big data security; Internet of Things (IoT) ecurity; iOS data exfiltration; iOS pairing;
D O I
10.1109/JIOT.2016.2569094
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Increasingly, big data (including sensitive and commercial-in-confidence data) is being accessible and stored on a range of Internet of Things (IoT) devices, such as our mobile devices. Therefore, any vulnerability in IoT devices, operating system or software can be exploited by cybercriminals seeking to exfiltrate our data. In this paper, we use iOS devices as case studies and highlight the potential for pairing mode in iOS devices (which allows the establishment of a trusted relationship between an iOS device and a personal computer) to be exploited for covert data exfiltration. In our three case studies, we demonstrate how an attacker could exfiltrate data from a paired iOS device by abusing a library and a command line tool distributed with iTunes. With the aim of avoiding similar attacks in the future, we present two recommendations.
引用
收藏
页码:524 / 535
页数:12
相关论文
共 39 条
  • [11] [Anonymous], DESKT OP SYST MARK S
  • [12] [Anonymous], APPLE CLEANS UP IOS
  • [13] [Anonymous], PANDALABS NEUTR 75 M
  • [14] [Anonymous], KEYRAIDER IOS MALWAR
  • [15] [Anonymous], GLOB MARK SHAR HELD
  • [16] [Anonymous], P SENS COMM CONTR CO
  • [17] [Anonymous], J COMMUN
  • [18] [Anonymous], 2013, P ANN INT C MOB SYST, DOI DOI 10.1145/2462456.2464460
  • [19] [Anonymous], UNAUTHORIZED CROSS A
  • [20] [Anonymous], COMPREHENSIVE MOBILE