OASIS: An Intrusion Detection System Embedded in Bluetooth Low Energy Controllers

被引:0
|
作者
Cayre, Romain [1 ,2 ]
Nicomette, Vincent [3 ]
Auriol, Guillaume [3 ]
Kaaniche, Mohamed [4 ]
Francillon, Aurelien [1 ]
机构
[1] EURECOM, Sophia Antipolis, France
[2] Apsys Lab, Paris, France
[3] Univ Toulouse, INSA, LAAS, Toulouse, France
[4] CNRS, LAAS, Toulouse, France
关键词
Intrusion Detection; Bluetooth; Controllers; Instrumentation; PLACEMENT;
D O I
10.1145/3634737.3645004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Bluetooth Low Energy has established itself as one of the central protocols of the Internet of Things. Its many features (mobility, low energy consumption) make it an attractive protocol for smart devices. However, numerous critical vulnerabilities affecting BLE have been made public in recent years, some of which are linked to the protocol's design itself. The impossibility of correcting these vulnerabilities without affecting the specification requires the development of effective intrusion detection systems, enabling the detection and prevention of these threats. Unfortunately, the protocol relies on peer-to-peer communications and introduces many complex and dynamic mechanisms (e.g., channel hopping), making monitoring complex, costly and limited. Existing intrusion detection approaches lack flexibility, are limited in scope and introduce high deployment costs. In this paper, we explore a novel approach consisting in embedding an intrusion detection system directly within BLE controllers. This strategic position tackles these challenges by enabling a more advanced analysis and instrumentation of the protocol and opens the way to new defensive applications. We propose OASIS, a framework for injecting detection heuristics into controllers' firmwares in a generic way without affecting the normal operation of the protocol stack. It can be deployed in various contexts during the life cycle of a device, from the chip manufacturer to a software developer making use of proprietary components, or even in a full black box context by a security analyst to harden a commercial product. We describe its modular architecture and present its implementation within five of the most popular BLE chips from three different manufacturers, deployed in billions of devices and embedding heterogeneous protocol stacks. We present five modules for critical low-level protocol attack detection. We show that OASIS has a low impact on the controller performance (power, timing, memory) and evaluate its usage in a real-world setting.
引用
收藏
页码:700 / 715
页数:16
相关论文
共 50 条
  • [11] Network Intrusion Detection System Embedded on a Smart Sensor
    Macia-Perez, Francisco
    Mora-Gimeno, Francisco J.
    Marcos-Jorquera, Diego
    Antonio Gil-Martinez-Abarca, Juan
    Ramos-Morillo, Hector
    Lorenzo-Fonseca, Iren
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2011, 58 (03) : 722 - 732
  • [12] An Embedded Intrusion Detection System Model for Application Program
    Wu, Shaofei
    Chen, Yan
    PACIIA: 2008 PACIFIC-ASIA WORKSHOP ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION, VOLS 1-3, PROCEEDINGS, 2008, : 1861 - +
  • [13] Design and Fabrication of Embedded Wireless Monitoring System Based on Bluetooth Low Energy Transmission for Potentiometric Sensors
    Cao Zhong
    Li Wen-Feng
    Liu Chen
    Peng Yu-Yu
    Huang Ying
    Xiao Zhong-Liang
    CHINESE JOURNAL OF ANALYTICAL CHEMISTRY, 2019, 47 (02) : 229 - 236
  • [14] Intrusion Detection in Bluetooth Enabled Mobile Phones
    Nair, Kishor Krishnan
    Helberg, Albert
    Van der Merwe, Johan
    2015 INFORMATION SECURITY FOR SOUTH AFRICA - PROCEEDINGS OF THE ISSA 2015 CONFERENCE, 2015,
  • [15] Intrusion Detection System for Bluetooth Mesh Networks: Data Gathering and Experimental Evaluations
    Lacava, Andrea
    Giacomini, Emanuele
    D'Alterio, Francesco
    Cuomo, Francesca
    2021 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS AND OTHER AFFILIATED EVENTS (PERCOM WORKSHOPS), 2021, : 661 - 666
  • [16] Penetration Testing of Intrusion Detection and Prevention System in Low-Performance Embedded IoT Device
    Zitta, Tomas
    Neruda, Marek
    Vojtech, Lukas
    Matejkova, Martina
    Jehlicka, Matej
    Hach, Lukas
    Moravec, Jan
    PROCEEDINGS OF THE 2018 18TH INTERNATIONAL CONFERENCE ON MECHATRONICS - MECHATRONIKA (ME), 2018, : 387 - 391
  • [17] A Bluetooth Low Energy based system for personnel tracking
    Ndzukula, S. G.
    Ramotsoela, T. D.
    Silva, B. J.
    Hancke, G. P.
    IECON 2017 - 43RD ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2017, : 8435 - 8440
  • [18] Respiratory monitoring system using Bluetooth Low Energy
    Janik, P.
    Pielka, M.
    Janik, M. A.
    Wrobel, Z.
    SENSORS AND ACTUATORS A-PHYSICAL, 2019, 286 : 152 - 162
  • [19] A Bluetooth Low Energy Implantable Glucose Monitoring System
    Ali, Mai
    Albasha, Lutfi
    Al-Nashash, Hasan
    2011 41ST EUROPEAN MICROWAVE CONFERENCE, 2011, : 1265 - 1268
  • [20] Bluetooth Low Energy (BLE) Based Geomarketing System
    Zaim, Dalai
    Bellafkih, Mostafa
    2016 11TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS: THEORIES AND APPLICATIONS (SITA), 2016,