IoTLS: understanding TLS usage in consumer IoT devices

IoTLS: understanding TLS usage in consumer IoT devices
复制标题

DOI:
10.1145/3487552.3487830
复制
发表时间:
2021-11
期刊:
Proceedings of the 21st ACM Internet Measurement Conference
影响因子:
--
通讯作者:
Muhammad Talha Paracha;Daniel J. Dubois;Narseo Vallina-Rodriguez;D. Choffnes
Muhammad Talha Paracha;Daniel J. Dubois;Narseo Vallina-Rodriguez;D. Choffnes
中科院分区:
其他
文献类型:
--
作者:
Muhammad Talha Paracha;Daniel J. Dubois;Narseo Vallina-Rodriguez;D. Choffnes

文献摘要

相似文献

消费者物联网设备越来越受欢迎,大多数设备都利用TLS来提供连接安全性。在这项工作中,我们研究了大量启用TLS的消费者物联网设备,以了解它们在建立安全连接和正确验证证书方面如何有效地使用TLS,以及观察到的行为如何随时间变化。为此,我们从物联网设备收集了两年多的TLS网络流量,进行主动探测以测试漏洞,并开发了一种新的黑盒技术,通过TLS警报消息利用侧通道来探索物联网设备中的可信根存储。我们发现设备之间存在各种各样的行为,其中一些采用了最佳安全实践,但大多数在以下一种或多种方式中存在漏洞:使用旧的/不安全的协议版本和/或密码套件,缺乏证书验证以及根存储的维护不善。具体来说,我们发现至少有8个物联网设备在其根存储中仍然包含不可信的证书,11/32的设备容易受到TLS拦截攻击,并且随着时间的推移,许多设备无法采用现代协议功能。我们的研究结果促使物联网制造商需要以一致和统一的方式审计,升级和维护其设备的TLS实现,以保护其所有网络流量。
Consumer IoT devices are becoming increasingly popular, with most leveraging TLS to provide connection security. In this work, we study a large number of TLS-enabled consumer IoT devices to shed light on how effectively they use TLS, in terms of establishing secure connections and correctly validating certificates, and how observed behavior changes over time. To this end, we gather more than two years of TLS network traffic from IoT devices, conduct active probing to test for vulnerabilities, and develop a novel blackbox technique for exploring the trusted root stores in IoT devices by exploiting a side-channel through TLS Alert Messages. We find a wide range of behaviors across devices, with some adopting best security practices but most being vulnerable in one or more of the following ways: use of old/insecure protocol versions and/or ciphersuites, lack of certificate validation, and poor maintenance of root stores. Specifically, we find that at least 8 IoT devices still include distrusted certificates in their root stores, 11/32 devices are vulnerable to TLS interception attacks, and that many devices fail to adopt modern protocol features over time. Our findings motivate the need for IoT manufacturers to audit, upgrade, and maintain their devices' TLS implementations in a consistent and uniform way that safeguards all of their network traffic.