Three practical attacks against ZigBee security: Attack scenario definitions, practical experiments, countermeasures, and lessons learned

Three practical attacks against ZigBee security: Attack scenario definitions, practical experiments, countermeasures, and lessons learned
复制标题

针对 ZigBee 安全的三种实际攻击:攻击场景定义、实际实验、对策和经验教训

DOI:
10.1109/his.2014.7086198
复制
发表时间:
2014
期刊:
2014 14th International Conference on Hybrid Intelligent Systems
影响因子:
--
通讯作者:
Pekka J. Toivanen
Pekka J. Toivanen
中科院分区:
--
文献类型:
--
作者:
Olayemi Olawumi;Keijo Haataja;Mikko Asikainen;Niko Vidgren;Pekka J. Toivanen

文献摘要

被引文献

相似文献

本文在我们的实验室环境中进行了三次针对ZigBee安全的实用攻击。攻击场景是基于利用从ZigBee技术的主要安全组件中发现的几个漏洞。第一次攻击是基于发现范围内所有支持ZigBee的网络以及相应支持ZigBee的设备的配置:这些至关重要的基本基本信息可用于对发现的支持ZigBee的设备/网络执行进一步和更严重的攻击。第二次攻击可以被视为第一次攻击的延伸,因此,成功完成第一次攻击是第二次攻击的先决条件。在第二次攻击中,攻击者窃听启用ZigBee的网络的未加密或加密流量,以获取和利用任何敏感/有用信息。第三种攻击基于重放(重新传输)捕获的数据,就好像原始发送者再次发送数据一样。为了使这种攻击非常简单、直接和实用,我们决定设计和实施它,而不在受害者设备之间有中间人(MITM),因为MITM的存在将使攻击在实践中非常困难,从而仅提供理论上的相关性。事实上,我们用实验数据证明,通过使用我们的三个攻击场景,针对支持ZigBee的设备的攻击变得切实可行。此外,还设计了使攻击变得不切实际的对策,尽管不能完全消除它们的潜在危险。此外,还提出了一些在今后的研究工作中可以采用的新思路。
In this paper, three practical attacks against ZigBee security are carried out in our laboratory environment. The attack scenarios are based on utilizing several vulnerabilities found from the main security components of ZigBee technology. The first attack is based on discovering all ZigBee-enabled networks within range as well as the configurations of the corresponding ZigBee-enabled devices: This vital and fundamental basic information can be used for performing further and more severe attacks against the discovered ZigBee-enabled devices/networks. The second attack can be seen as an extension to the first attack and thus the prerequisite for it is the successful completion of the first attack. In the second attack, an attacker eavesdrops on the unencrypted or encrypted traffic of a ZigBee-enabled network in order to obtain and utilize any sensitive/useful information. The third attack is based on replaying (re-transmitting) the captured data as if the original sender is sending the data again. To keep this attack extremely simple, straightforward, and practical, we decided to devise and implement it without having a Man-In-The-Middle (MITM) between the victim devices, since the presence of the MITM would have made the attack very difficult to implement in practice, thus giving it only a theoretical relevance. Indeed, we demonstrate with experimental figures that attacks against ZigBee-enabled devices become practical by using our three attack scenarios. In addition, countermeasures that render the attacks impractical, although not totally eliminating their potential danger, are devised. Moreover, some new ideas that will be used in our future research work are proposed.