Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tagliaro, Carlotta, Komsic, Martina, Continella, Andrea, Borgolte, Kevin, Lindorfer, Martina
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910627280191488
author Tagliaro, Carlotta
Komsic, Martina
Continella, Andrea
Borgolte, Kevin
Lindorfer, Martina
author_facet Tagliaro, Carlotta
Komsic, Martina
Continella, Andrea
Borgolte, Kevin
Lindorfer, Martina
contents Internet-of-Things (IoT) devices, ranging from smart home assistants to health devices, are pervasive: Forecasts estimate their number to reach 29 billion by 2030. Understanding the security of their machine-to-machine communication is crucial. Prior work focused on identifying devices' vulnerabilities or proposed protocol-specific solutions. Instead, we investigate the security of backends speaking IoT protocols, that is, the backbone of the IoT ecosystem. We focus on three real-world protocols for our large-scale analysis: MQTT, CoAP, and XMPP. We gather a dataset of over 337,000 backends, augment it with geographical and provider data, and perform non-invasive active measurements to investigate three major security threats: information leakage, weak authentication, and denial of service. Our results provide quantitative evidence of a problematic immaturity in the IoT ecosystem. Among other issues, we find that 9.44% backends expose information, 30.38% CoAP-speaking backends are vulnerable to denial of service attacks, and 99.84% of MQTT- and XMPP-speaking backends use insecure transport protocols (only 0.16% adopt TLS, of which 70.93% adopt a vulnerable version).
format Preprint
id arxiv_https___arxiv_org_abs_2405_09662
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols
Tagliaro, Carlotta
Komsic, Martina
Continella, Andrea
Borgolte, Kevin
Lindorfer, Martina
Cryptography and Security
Networking and Internet Architecture
Internet-of-Things (IoT) devices, ranging from smart home assistants to health devices, are pervasive: Forecasts estimate their number to reach 29 billion by 2030. Understanding the security of their machine-to-machine communication is crucial. Prior work focused on identifying devices' vulnerabilities or proposed protocol-specific solutions. Instead, we investigate the security of backends speaking IoT protocols, that is, the backbone of the IoT ecosystem. We focus on three real-world protocols for our large-scale analysis: MQTT, CoAP, and XMPP. We gather a dataset of over 337,000 backends, augment it with geographical and provider data, and perform non-invasive active measurements to investigate three major security threats: information leakage, weak authentication, and denial of service. Our results provide quantitative evidence of a problematic immaturity in the IoT ecosystem. Among other issues, we find that 9.44% backends expose information, 30.38% CoAP-speaking backends are vulnerable to denial of service attacks, and 99.84% of MQTT- and XMPP-speaking backends use insecure transport protocols (only 0.16% adopt TLS, of which 70.93% adopt a vulnerable version).
title Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2405.09662