A First Empirical Look on Internet-scale Exploitations of IoT Devices

被引:6
|
作者
Galluscio, Mario [1 ]
Neshenko, Nataliia [1 ]
Bou-Harb, Elias [1 ]
Huang, Yongliang [1 ]
Ghani, Nasir [2 ,3 ]
Crichigno, Jorge [4 ]
Kaddoum, Georges [5 ]
机构
[1] Florida Atlantic Univ, Cyber Threat Intelligence Lab, Boca Raton, FL 33431 USA
[2] Florida Ctr Cybersecur, Tampa, FL USA
[3] Univ S Florida, Tampa, FL 33620 USA
[4] Univ South Carolina, Columbia, SC 29208 USA
[5] Univ Quebec, ETS, Montreal, PQ, Canada
关键词
D O I
10.1109/PIMRC.2017.8292628
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Technological advances and innovative business models led to the modernization of the cyber-physical concept with the realization of the Internet of Things (IoT). While IoT envisions a plethora of high impact benefits in both, the consumer as well as the control automation markets, unfortunately, security concerns continue to be an afterthought. Several technical challenges impede addressing such security requirements, including, lack of empirical data related to various IoT devices in addition to the shortage of actionable attack signatures. In this paper, we present what we believe is a first attempt ever to comprehend the severity of IoT maliciousness by empirically characterizing the magnitude of Internet-scale IoT exploitations. We draw upon unique and extensive darknet (passive) data and develop an algorithm to infer unsolicited IoT devices which have been compromised and are attempting to exploit other Internet hosts. We further perform correlations by leveraging active Internet-wide scanning to identify and report on such IoT devices and their hosting environments. The generated results indicate a staggering 11 thousand exploited IoT devices that are currently in the wild. Moreover, the outcome pinpoints that IoT devices embedded deep in operational Cyber-Physical Systems (CPS) such as manufacturing plants and power utilities are the most compromised. We concur that such results highlight the wide-spread insecurities of the IoT paradigm, while the actionable generated inferences are postulated to be leveraged for prompt mitigation as well as to facilitate IoT forensic investigations using real empirical data.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] Demystifying IoT Security: An Exhaustive Survey on IoT Vulnerabilities and a First Empirical Look on Internet-Scale IoT Exploitations
    Neshenko, Nataliia
    Bou-Harb, Elias
    Crichigno, Jorge
    Kaddoum, Georges
    Ghani, Nasir
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2019, 21 (03): : 2702 - 2733
  • [2] Helium-based IoT Devices: Threat Analysis and Internet-scale Exploitations
    Rammouz, Veronica
    Khoury, Joseph
    Klisura, Dorde
    Pour, Morteza Safaei
    Pour, Mostafa Safaei
    Fachkha, Claude
    Bou-Harb, Elias
    [J]. 2023 19TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS, WIMOB, 2023, : 206 - 211
  • [3] Data-Driven Intelligence for Characterizing Internet-scale IoT Exploitations
    Neshenko, Nataliia
    Husak, Martin
    Bou-Harb, Elias
    Celeda, Pavel
    Al-Mulla, Sameera
    Fachkha, Claude
    [J]. 2018 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2018,
  • [4] Internet-Scale Fingerprinting the Reusing and Rebranding IoT Devices in the Cyberspace
    Yan, Zhaoteng
    Li, Zhi
    Li, Hong
    Yang, Shouguo
    Zhu, Hongsong
    Sun, Limin
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 3890 - 3909
  • [5] Detecting Internet-Scale NATs for IoT Devices Based on Tri-Net
    Yan, Zhaoteng
    Yu, Nan
    Wen, Hui
    Li, Zhi
    Zhu, Hongsong
    Sun, Limin
    [J]. WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, PT I, 2020, 12384 : 602 - 614
  • [6] Internet of Malicious Things: Correlating Active and Passive Measurements for Inferring and Characterizing Internet-Scale Unsolicited IoT Devices
    Shaikh, Farooq
    Bou-Harb, Elias
    Neshenko, Nataliia
    Wright, Andrea P.
    Ghani, Nasir
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2018, 56 (09) : 170 - 177
  • [7] Internet-scale Insecurity of Consumer Internet of Things: An Empirical Measurements Perspective
    Mangino, Antonio
    Pour, Morteza Safaei
    Bou-Harb, Elias
    [J]. ACM TRANSACTIONS ON MANAGEMENT INFORMATION SYSTEMS, 2020, 11 (04)
  • [8] Internet-scale sensing
    Diamond, D
    [J]. ANALYTICAL CHEMISTRY, 2004, 76 (15) : 278A - 286A
  • [9] Detecting Internet-Scale Surveillance Devices Using RTSP Recessive Features
    Yan, Zhaoteng
    Li, Zhi
    Bai, Wenping
    Yu, Nan
    Zhu, Hongsong
    Sun, Limin
    [J]. SCIENCE OF CYBER SECURITY, SCISEC 2021, 2021, 13005 : 21 - 35
  • [10] Internet-Scale Code Search
    Gallardo-Valencia, Rosalva E.
    Sim, Susan Elliott
    [J]. 2009 ICSE WORKSHOP ON SEARCH-DRIVEN DEVELOPMENT-USERS, INFRASTRUCTURE, TOOLS AND EVALUATION, 2009, : 49 - 52