IoT-Penn: A Security Penetration Tester for MQTT in the IoT Environment

被引:1
|
作者
Roets, Armand [1 ]
Tait, Bobby L. [1 ]
机构
[1] Univ South Africa, Pretoria, South Africa
关键词
IoT; MQTT; Application layer; Attack vector; Penetration testing; Security; Privacy;
D O I
10.1007/978-3-031-20160-8_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The IoT (Internet of Things) represents a technological evolution in the way that human beings can now control, monitor, and study the world by enabling the connection of different devices around the globe, facilitating data delivery and services. However, the advantages of this increased connectivity does not come without a price. Various security issues have been discovered that can affect the confidentiality, availability, and integrity of the data received from IoT devices. IoT devices are, in general, power, storage, and processing constrained devices due to cost, size, and power restrictions. This leads to the adoption of light weight communication protocols specifically designed for communication among devices in which advanced, computationally intensive methods of security cannot always be applied. One such a communication protocol is MQTT (Message Queueing Telemetry Transport). This paper intended to answer the question of the utility of penetration testing when designing and evaluating an MQTT network. Various attacks were catalogued, designed, and implemented in an application called IoT Penn. These attacks were carried out on a simulated MQTT network, after which the results were analyzed. It was found that it is possible to gain access to sensitive and privileged information, to spoof legitimate MQTT clients, and perform DoS (Denial of Service) attacks against the broker, using the default MQTT configuration.
引用
收藏
页码:141 / 157
页数:17
相关论文
共 50 条
  • [1] Implementation of SSL/TLS Security with MQTT Protocol in IoT Environment
    Iqbal Luqman Bin Mohd Paris
    Mohamed Hadi Habaebi
    Alhareth Mohammed Zyoud
    [J]. Wireless Personal Communications, 2023, 132 : 163 - 182
  • [2] Implementation of SSL/TLS Security with MQTT Protocol in IoT Environment
    Paris, Iqbal Luqman Bin Mohd
    Habaebi, Mohamed Hadi
    Zyoud, Alhareth Mohammed
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2023, 132 (01) : 163 - 182
  • [3] New security protocol integrating the ECC and MQTT for the security of IOT-Cloud environment
    Amrani, Ayoub
    Rafalia, Najat
    Jaafar, Abouchabaka
    [J]. EDUCATION EXCELLENCE AND INNOVATION MANAGEMENT: A 2025 VISION TO SUSTAIN ECONOMIC DEVELOPMENT DURING GLOBAL CHALLENGES, 2020, : 12261 - 12270
  • [4] Lightweight Authentication for MQTT to improve the Security of IoT Communication
    Bali, Ranbir Singh
    Jaafar, Fehmi
    Zavarasky, Pavol
    [J]. PROCEEDINGS OF 2019 THE 3RD INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP 2019) WITH WORKSHOP 2019 THE 4TH INTERNATIONAL CONFERENCE ON MULTIMEDIA AND IMAGE PROCESSING (ICMIP 2019), 2019, : 6 - 12
  • [5] An Extensible and Transparent Thing-to-Thing Security Enhancement for MQTT Protocol in IoT Environment
    Su, Wei-Tsung
    Chen, Wei-Cheng
    Chen, Chao-Chun
    [J]. 2019 GLOBAL IOT SUMMIT (GIOTS), 2019,
  • [6] Security risks in MQTT-based Industrial IoT Applications
    Boppana, Tej Kiran
    Bagade, Priyanka
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON OMNI-LAYER INTELLIGENT SYSTEMS (IEEE COINS 2022), 2022, : 348 - 352
  • [7] Lightweight security mechanism over MQTT protocol for IoT devices
    Amnalou, Sanaz
    Bakar, Khairul Azmi Abu
    [J]. International Journal of Advanced Computer Science and Applications, 2020, 11 (07): : 202 - 207
  • [8] Performance evaluation of CoAP and MQTT with security support for IoT environments
    Seoane, Victor
    Garcia-Rubio, Carlos
    Almenares, Florina
    Campo, Celeste
    [J]. COMPUTER NETWORKS, 2021, 197
  • [9] Lightweight Security Mechanism over MQTT Protocol for IoT Devices
    Amnalou, Sanaz
    Abu Bakar, Khairul Azmi
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (07) : 202 - 207
  • [10] A Raise of Security Concern in IoT Devices: Measuring IoT Security Through Penetration Testing Framework
    Jaafar, Abdul Ghafar
    Ismail, Saiful Adli
    Habir, Abdul
    Ariffin, Khairul Akram Zainol
    Yusop, Othman Mohd
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (05) : 676 - 690