Securing Commercial WiFi-Based UAVs From Common Security Attacks

被引:0
|
作者
Hooper, Michael [1 ]
Tian, Yifan [1 ]
Zhou, Runxuan [1 ]
Cao, Bin [1 ]
Lauf, Adrian P. [2 ]
Watkins, Lanier [1 ]
Robinson, William H. [3 ]
Alexis, Wlajimir [1 ]
机构
[1] Johns Hopkins Univ, Informat Secur Inst, Baltimore, MD 21218 USA
[2] Univ Louisville, Comp Engn & Comp Sci Dept, Louisville, KY 40292 USA
[3] Vanderbilt Univ, Secur & Fault Tolerance SAF T Res Grp, Nashville, TN 37235 USA
关键词
UAV; ARDiscovery; network security; hobby; flight;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
We posit that commercial Wi-Fi-based unmanned aerial vehicles (UAV) are vulnerable to common and basic security attacks, capable by beginner to intermediate hackers. We do this by demonstrating that the standard ARDiscovery Connection process and the Wi-Fi access point used in the Parrot Bebop UAV are exploitable such that the UAV's ability to fly can be disrupted mid-flight by a remote attacker. We believe that these vulnerabilities are systemic in Wi-Fi-based Parrot UAVs. Our approach observed the normal operation (i.e., ARDiscovery Connection process over Wi-Fi) of the Parrot Bebop UAV. We then used a fuzzing technique to discover that the Parrot Bebop UAV is vulnerable to basic denial of service (DoS) and buffer-overflow attacks during its ARDiscovery Connection process. The exploitation of these vulnerabilities could result in catastrophic and immediate disabling of the UAV's rotors mid-flight. Also, we discovered that the Parrot Bebop UAV is vulnerable to a basic ARP (Address Resolution Protocol) Cache Poisoning attack, which can disconnect the primary mobile device user and in most cases cause the UAV to land or return home. Based on the literature and our own penetration testing, we assert that Wi-Fi-based commercial UAVs require a comprehensive security framework that utilizes a defense-in-depth approach. This approach would likely mitigate security risks associated with the three zero-day vulnerabilities described in this paper as well as other vulnerabilities reported in the literature. This framework will be effective for Parrot Wi-Fi-based commercial UAVs and likely others with similar platforms.
引用
收藏
页码:1213 / 1218
页数:6
相关论文
共 28 条
  • [1] A WiFi-based Home Security System
    Zhang, Shaohu
    Venkatnarayan, Raghav H.
    Shahzad, Muhammad
    2020 IEEE 17TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2020), 2020, : 129 - 137
  • [2] Time to Think the Security of WiFi-Based Behavior Recognition Systems
    Liu, Jianwei
    He, Yinghui
    Xiao, Chaowei
    Han, Jinsong
    Ren, Kui
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (01) : 449 - 462
  • [3] FLOOR IDENTIFICATION WITH COMMERCIAL SMARTPHONES IN WIFI-BASED INDOOR LOCALIZATION SYSTEM
    Ai, H. J.
    Liu, M. Y.
    Shi, Y. M.
    Zhao, J. Q.
    XXIII ISPRS CONGRESS, COMMISSION IV, 2016, 41 (B4): : 573 - 577
  • [4] Understanding WiFi-based Connectivity from Moving Vehicles
    Mahajan, Ratul
    Zahorjan, John
    Zill, Brian
    IMC'07: PROCEEDINGS OF THE 2007 ACM SIGCOMM INTERNET MEASUREMENT CONFERENCE, 2007, : 321 - 326
  • [5] Wifi Infrastructure Security System from Vulnerable Attacks
    Thangaraj, P.
    Geethanjali, N.
    Kathiresan, K.
    Madhumathi, R.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (12): : 104 - 109
  • [6] SWIMMING: Seamless and Efficient WiFi-Based Internet Access from Moving Vehicles
    Lv, Pin
    Wang, Xudong
    Xue, Xiuhui
    Xu, Ming
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2015, 14 (05) : 1085 - 1097
  • [7] Observer based attack detection and security control for UAVs against attacks on desired trajectory
    Pan, Kunpeng
    Yang, Feisheng
    Lyu, Yang
    Tan, Zheng
    Pan, Quan
    JOURNAL OF THE FRANKLIN INSTITUTE-ENGINEERING AND APPLIED MATHEMATICS, 2024, 361 (11):
  • [8] A survey on ubiquitous WiFi-based indoor localization system for smartphone users from implementation perspectives
    Priya Roy
    Chandreyee Chowdhury
    CCF Transactions on Pervasive Computing and Interaction, 2022, 4 : 298 - 318
  • [9] Data Information Fusion From Multiple Access Points for WiFi-Based Self-localization
    Miyagusuku, Renato
    Yamashita, Atsushi
    Asama, Hajime
    IEEE ROBOTICS AND AUTOMATION LETTERS, 2019, 4 (02) : 269 - 276
  • [10] A survey on ubiquitous WiFi-based indoor localization system for smartphone users from implementation perspectives
    Roy, Priya
    Chowdhury, Chandreyee
    CCF TRANSACTIONS ON PERVASIVE COMPUTING AND INTERACTION, 2022, 4 (03) : 298 - 318