Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps

Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps
复制标题

DOI:
10.1145/3319535.3354240
复制
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Chaoshun Zuo;Haohuang Wen;Zhiqiang Lin;Yinqian Zhang
Chaoshun Zuo;Haohuang Wen;Zhiqiang Lin;Yinqian Zhang
中科院分区:
其他
文献类型:
--
作者:
Chaoshun Zuo;Haohuang Wen;Zhiqiang Lin;Yinqian Zhang

文献摘要

被引文献

相似文献

蓝牙低能耗(BLE)作为一种易于部署、经济高效的低功耗无线解决方案,已被物联网(IoT)设备广泛使用。在典型的物联网场景中,物联网设备首先需要与其配套的移动应用程序连接,移动应用程序充当其互联网访问的网关。为了建立连接,设备首先向附近的智能手机应用程序广播带有UUID的广告数据包。利用这些UUID,配套的应用程序能够识别设备,与其配对和绑定,并允许进一步的数据通信。然而,我们发现,目前BLE设备与其配套移动应用程序之间的通信协议的设计和实现存在一个根本性的缺陷,这使得攻击者能够使用应用程序中的静态UUID精确地识别BLE设备。同时,我们还发现,很多BLE IoT设备都采用“Just Works”配对,如果没有APP级身份验证,攻击者就可以主动连接这些设备。更糟糕的是,这个漏洞也可以从移动应用程序中直接发现。此外,我们还发现有数量惊人的易受攻击的应用程序级身份验证应用程序,这意味着这些应用程序连接的设备可以直接被攻击者控制。为了提高公众对物联网设备指纹识别的认识,并在攻击者之前发现这些易受攻击的BLE物联网设备,我们开发了一个自动化移动应用程序分析工具BLESCOPE,并使用Google Play商店中的所有免费BLE IoT应用程序对其进行评估。我们的工具总共识别了1757个易受攻击的移动应用程序。我们还在1.28平方英里的区域进行了现场测试,识别出5822台真实的BLE设备,其中5509台(94.6%)是攻击者可以指纹识别的,431台(7.4%)容易受到未经授权的访问。我们已经向相应的应用程序开发者进行了负责任的披露,并向蓝牙特殊兴趣小组报告了指纹问题。
Being an easy-to-deploy and cost-effective low power wireless solution, Bluetooth Low Energy (BLE) has been widely used by Internet-of-Things (IoT) devices. In a typical IoT scenario, an IoT device first needs to be connected with its companion mobile app which serves as a gateway for its Internet access. To establish a connection, a device first broadcasts advertisement packets with UUIDs to nearby smartphone apps. Leveraging these UUIDs, a companion app is able to identify the device, pairs and bonds with it, and allows further data communication. However, we show that there is a fundamental flaw in the current design and implementation of the communication protocols between a BLE device and its companion mobile app, which allows an attacker to precisely fingerprint a BLE device with static UUIDs from the apps. Meanwhile, we also discover that many BLE IoT devices adopt "just works" pairing, allowing attackers to actively connect with these devices if there is no app-level authentication. Even worse, this vulnerability can also be directly uncovered from mobile apps. Furthermore, we also identify that there is an alarming number of vulnerable app-level authentication apps, which means the devices connected by these apps can be directly controlled by attackers. To raise the public awareness of IoT device fingerprinting and also uncover these vulnerable BLE IoT devices before attackers, we develop an automated mobile app analysis tool BLESCOPE and evaluate it with all of the free BLE IoT apps in Google Play store. Our tool has identified 1,757 vulnerable mobile apps in total. We also performed a field test in a 1.28 square miles region, and identified 5,822 real BLE devices, among them 5,509 (94.6%) are fingerprintable by attackers, and 431 (7.4%) are vulnerable to unauthorized access. We have made responsible disclosures to the corresponding app developers, and also reported the fingerprinting issues to the Bluetooth Special Interest Group.