All Your IoT Devices Are Belong to Us: Security Weaknesses in IoT Management Platforms


연구 분야: Safety



학회: CODASPY '23: Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy


초록

IoT devices have become an integral part of our day to day activities, and are also being deployed to fulfil a number of industrial, enterprise and agricultural use cases. To efficiently manage and operate these devices, the IoT ecosystem relies on several IoT management platforms. Given the security-sensitive nature of the operations performed by these platforms, analyzing them for security vulnerabilities is critical to protect the ecosystem from potential cyber threats. In this work, by exploring the core functionalities offered by leading platforms, we first design a security evaluation framework. Subsequently, we use our framework to analyze 42 IoT management platforms. Our analysis uncovers a number of high severity unauthorized access vulnerabilities in 9/42 platforms, which could lead to attacks such as remote SIM deactivation, IoT SIM overcharging and device data forgery. Furthermore, we find broken authentication in 11/42 platforms, including complete account takeover on 7/42 platforms, along with remote code execution on one of the platforms. Overall, on 11/42 platforms, we find vulnerabilities that could lead to platform-wide attacks, that affect all users and all devices connected to those platforms.


Author Profile
Bhaskar Tejaswi

Concordia University Montreal PQ Canada

Canada
Author Profile
Mohammad Mannan

Concordia University Montreal PQ Canada

Canada
Author Profile
Amr Mohamed Youssef

Concordia University Montreal PQ Canada

Canada

📄 논문 정보

발행 연도 2023년
인용수 2
출판 국가 Canada
사이트 ACM
좋아요 수 0

연관 논문 목록 (612건)