Delay Wreaks Havoc on Your Smart Home: Delay-based Automation Interference Attacks

Delay Wreaks Havoc on Your Smart Home: Delay-based Automation Interference Attacks
复制标题

DOI:
10.1109/sp46214.2022.9833620
复制
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Haotian Chi;Chenglong Fu;Qiang Zeng;Xiaojiang Du
Haotian Chi;Chenglong Fu;Qiang Zeng;Xiaojiang Du
中科院分区:
其他
文献类型:
--
作者:
Haotian Chi;Chenglong Fu;Qiang Zeng;Xiaojiang Du

文献摘要

相似文献

随着物联网(IoT)设备和平台的激增,与不同物联网平台关联的物联网设备在智能家居中共存已成为一种趋势,呈现出以下特征。首先,智能家居可能使用多个平台来支持其设备和自动化。其次,家庭的物联网设备可能通过不同的路径传输消息。通过有选择地延迟物联网消息,我们的研究发现,攻击者可能会严重加剧不一致和无序这两个问题。然后,我们探讨如何利用这些问题,并提出七种类型的利用,统称为基于延迟的自动化干扰 (DAI) 攻击。 DAI 攻击导致家庭自动化产生错误的交互结果,使物联网设备和智能家居处于不安全、不安全或意外的状态。值得强调的是,DAI 攻击不依赖于任何物联网实施漏洞或泄露的密钥/令牌,并且不会在物联网协议栈的任何层触发警报。为了演示和评估新的攻击,我们建立了两个真实世界的测试平台,其中部署了商业物联网设备和应用程序。两个测试平台为期一周的实验表明,攻击者有足够的机会发起 DAI 攻击,从而导致安全或安全问题。
With the proliferation of Internet of Things (IoT) devices and platforms, it becomes a trend that IoT devices associated with different IoT platforms coexist in a smart home, demonstrating the following characteristics. First, a smart home may use more than one platform to support its devices and automation. Second, IoT devices of a home may transmit messages over different paths. By selectively delaying IoT messages, our study finds that two issues, inconsistency and disorder, can be exacerbated by attackers significantly. We then explore how these issues can be exploited and present seven types of exploitation, collectively referred to as Delay-based Automation Interference (DAI) attacks. DAI attacks cause home automation to yield incorrect interaction results, placing the IoT devices and smart home in insecure, unsafe, or unexpected states. It is worth highlighting that DAI attacks do not depend on any IoT implementation vulnerabilities or leaked keys/tokens, and they do not trigger alarms at any layers of the IoT protocol stack. To demonstrate and evaluate the new attacks, we set up two real-world testbeds, where commercial IoT devices and apps are deployed. The week-long experiments from both testbeds show that an attacker has adequate opportunities to launch DAI attacks that cause security or safety issues.