Dissecting Operational Cellular IoT Service Security: Attacks and Defenses

Dissecting Operational Cellular IoT Service Security: Attacks and Defenses
复制标题

DOI:
10.1109/tnet.2023.3313557
复制
发表时间:
2024-04
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
Sihan Wang;Tian Xie;Min-Yue Chen;Guan-Hua Tu;Chi-Yu Li;Xinyu Lei;Polun Chou;Fu-Cheng Hsieh;Yiwen Hu;Li Xiao;Chunyi Peng
Sihan Wang;Tian Xie;Min-Yue Chen;Guan-Hua Tu;Chi-Yu Li;Xinyu Lei;Polun Chou;Fu-Cheng Hsieh;Yiwen Hu;Li Xiao;Chunyi Peng
中科院分区:
其他
文献类型:
--
作者:
Sihan Wang;Tian Xie;Min-Yue Chen;Guan-Hua Tu;Chi-Yu Li;Xinyu Lei;Polun Chou;Fu-Cheng Hsieh;Yiwen Hu;Li Xiao;Chunyi Peng

文献摘要

相似文献

全球超过150个蜂窝网络已经推出了LTE - M(LTE - 机器类型通信)和/或NB - IoT(窄带物联网)技术,以支持诸如智能计量和环境监测等大规模物联网服务。此类蜂窝物联网服务与非物联网(例如智能手机)服务共享现有的蜂窝网络架构。当它们新集成到蜂窝网络中时,由于集成不当可能会出现新的安全漏洞。在这项工作中,我们从系统集成和服务集成两个方面探究蜂窝物联网的安全漏洞。我们发现了几个漏洞,涵盖蜂窝标准设计缺陷、网络运营失误以及物联网设备实现缺陷。具有威胁性的是,它们使得攻击者能够远程识别分配给蜂窝物联网设备的IP地址和电话号码,中断其节能服务,并发起各种攻击,包括数据/文本垃圾邮件、电池耗尽、使设备休眠等攻击。我们使用经认证的蜂窝物联网设备在美国和台湾的五家主要蜂窝物联网运营商网络上验证了这些漏洞。攻击评估结果显示,攻击者可以用不到120MB的垃圾流量使物联网数据费用增加高达226美元,以每秒5美元的速度增加物联网短信费用,并阻止物联网设备进入/退出节能模式;此外,蜂窝物联网设备可能会遭受物联网服务拒绝。最后,我们提出、制作原型并评估了推荐的解决方案。
More than 150 cellular networks worldwide have rolled out LTE-M (LTE-Machine Type Communication) and/or NB-IoT (Narrow Band Internet of Things) technologies to support massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover several vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices, interrupt their power saving services, and launch various attacks, including data/text spamming, battery draining, device hibernation against them. We validate these vulnerabilities over five major cellular IoT carriers in the U.S. and Taiwan using their certified cellular IoT devices. The attack evaluation result shows that the adversary can raise an IoT data bill by up to ${\$}226$ with less than 120 MB spam traffic, increase an IoT text bill at a rate of ${\$}5$ per second, and prevent an IoT device from entering/leaving power saving mode; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions.