IoT Phantom-Delay Attacks: Demystifying and Exploiting IoT Timeout Behaviors

IoT Phantom-Delay Attacks: Demystifying and Exploiting IoT Timeout Behaviors
复制标题

DOI:
10.1109/dsn53405.2022.00050
复制
发表时间:
2022-06
期刊:
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Chenglong Fu;Qiang Zeng;Haotian Chi;Xiaojiang Du;Siva Likitha Valluru
Chenglong Fu;Qiang Zeng;Haotian Chi;Xiaojiang Du;Siva Likitha Valluru
中科院分区:
其他
文献类型:
--
作者:
Chenglong Fu;Qiang Zeng;Haotian Chi;Xiaojiang Du;Siva Likitha Valluru

文献摘要

相似文献

本文推出了一系列针对物联网(IoT)自动化系统的新攻击。我们首先提出了两个新颖的IoT攻击原始图:事件消息延迟和命令消息延迟(事件消息由IoT设备生成以报告设备状态,并使用命令消息来控制IoT设备)。我们的见解是,TCP层中的超时检测与传输层安全性(TLS)层中的数据保护分离。结果,即使会话受到TL的保护,其物联网事件和/或命令消息仍然可以大大延迟而不会触发警报。值得强调的是,通过在智能环境中妥协/控制一台WiFi设备,攻击者可以延迟其他非副标士的IoT设备的IoT消息;因此,我们称攻击IOT幻影 - 戴雷攻击。我们的研究表明,攻击原则可用于建立丰富的攻击,其中一些可以引起持续的影响。提出的攻击与干扰大不相同。 1)与干扰不同,我们的攻击不会丢弃任何数据包,因此不会触发重新传输。 2)我们的攻击不会引起断开或超时警报。 3)与通常依赖特殊硬件的反应性干扰不同,我们的攻击可以从普通的WiFi设备发射。我们的评估涉及50种流行的物联网设备,并证明它们都容易受到幻影攻击的影响。最后,我们讨论对策。我们已经与多个有关脆弱的物联网超时行为联系了多个IoT平台,Google,Ring和Simplisafe已经确认了这个问题。
This paper unveils a set of new attacks against Internet of Things (IoT) automation systems. We first propose two novel IoT attack primitives: Event Message Delay and Command Message Delay (event messages are generated by IoT devices to report device states, and command messages are used to control IoT devices). Our insight is that timeout detection in the TCP layer is decoupled from data protection in the Transport Layer Security (TLS) layer. As a result, even when a session is protected by TLS, its IoT event and/or command messages can still be significantly delayed without triggering alerts. It is worth highlighting that, by compromising/controlling one WiFi device in a smart environment, the attacker can delay the IoT messages of other non-compromised IoT devices; we thus call the attacks IoT Phantom-Delay Attacks. Our study shows the attack primitives can be used to build rich attacks and some of them can induce persistent effects. The presented attacks are very different from jamming. 1) Unlike jamming, our attacks do not discard any packets and thus do not trigger re-transmission. 2) Our attacks do not cause disconnection or timeout alerts. 3) Unlike reactive jamming, which usually relies on special hardware, our attacks can be launched from an ordinary WiFi device. Our evaluation involves 50 popular IoT devices and demonstrates that they are all vulnerable to the phantom-delay attacks. Finally, we discuss the countermeasures. We have contacted multiple IoT platforms regarding the vulnerable IoT timeout behaviors, and Google, Ring and SimpliSafe have acknowledged the problem.