Securing Commercial WiFi-Based UAVs From Common Security Attacks

被引:0
|
作者
Hooper, Michael [1 ]
Tian, Yifan [1 ]
Zhou, Runxuan [1 ]
Cao, Bin [1 ]
Lauf, Adrian P. [2 ]
Watkins, Lanier [1 ]
Robinson, William H. [3 ]
Alexis, Wlajimir [1 ]
机构
[1] Johns Hopkins Univ, Informat Secur Inst, Baltimore, MD 21218 USA
[2] Univ Louisville, Comp Engn & Comp Sci Dept, Louisville, KY 40292 USA
[3] Vanderbilt Univ, Secur & Fault Tolerance SAF T Res Grp, Nashville, TN 37235 USA
关键词
UAV; ARDiscovery; network security; hobby; flight;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
We posit that commercial Wi-Fi-based unmanned aerial vehicles (UAV) are vulnerable to common and basic security attacks, capable by beginner to intermediate hackers. We do this by demonstrating that the standard ARDiscovery Connection process and the Wi-Fi access point used in the Parrot Bebop UAV are exploitable such that the UAV's ability to fly can be disrupted mid-flight by a remote attacker. We believe that these vulnerabilities are systemic in Wi-Fi-based Parrot UAVs. Our approach observed the normal operation (i.e., ARDiscovery Connection process over Wi-Fi) of the Parrot Bebop UAV. We then used a fuzzing technique to discover that the Parrot Bebop UAV is vulnerable to basic denial of service (DoS) and buffer-overflow attacks during its ARDiscovery Connection process. The exploitation of these vulnerabilities could result in catastrophic and immediate disabling of the UAV's rotors mid-flight. Also, we discovered that the Parrot Bebop UAV is vulnerable to a basic ARP (Address Resolution Protocol) Cache Poisoning attack, which can disconnect the primary mobile device user and in most cases cause the UAV to land or return home. Based on the literature and our own penetration testing, we assert that Wi-Fi-based commercial UAVs require a comprehensive security framework that utilizes a defense-in-depth approach. This approach would likely mitigate security risks associated with the three zero-day vulnerabilities described in this paper as well as other vulnerabilities reported in the literature. This framework will be effective for Parrot Wi-Fi-based commercial UAVs and likely others with similar platforms.
引用
收藏
页码:1213 / 1218
页数:6
相关论文
共 28 条
  • [21] Combinatorial Analysis for Securing IoT-Assisted Industry 4.0 Applications From Vulnerability-Based Attacks
    George, Gemini
    Thampi, Sabu M.
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (01) : 3 - 15
  • [22] Protecting Legitimate SEI Security Approaches From Phase-based Obfuscation Attacks
    Tyler, Joshua H.
    Reising, Donald R.
    Fadul, Mohamed K. M.
    Sartipi, Mina
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 1425 - 1431
  • [23] Securing hybrid wired/mobile IP networks from TCP-flooding based Denial-of-Service attacks
    Taleb, T
    Nishiyama, H
    Kato, N
    Nemoto, Y
    GLOBECOM '05: IEEE Global Telecommunications Conference, Vols 1-6: DISCOVERY PAST AND FUTURE, 2005, : 2907 - 2911
  • [24] Smart Green Communication Protocols Based on Several-Fold Messages Extracted from Common Sequential Patterns in UAVs
    Garcia-Magarino, Ivan
    Gray, Geraldine
    Lacuesta, Raquel
    Lloret, Jaime
    IEEE NETWORK, 2020, 34 (03): : 249 - 255
  • [25] Securing Data From Side-Channel Attacks: A Graph Neural Network-Based Approach for Smartphone-Based Side Channel Attack Detection
    Abbas, Sidra
    Ojo, Stephen
    Bouazzi, Imen
    Avelino Sampedro, Gabriel
    Al Hejaili, Abdullah
    Almadhor, Ahmad S.
    Kulhanek, Rastislav
    IEEE ACCESS, 2024, 12 : 138904 - 138920
  • [26] Insights from Evidence-Based Medicine Method for Building Security Systems Against Terrorist Attacks in Hospitals
    Chen, Guochen
    Jin, Gaofeng
    JOURNAL OF MULTIDISCIPLINARY HEALTHCARE, 2023, 16 : 4133 - 4137
  • [27] An Intelligent Big Data Security Framework Based on AEFS-KENN Algorithms for the Detection of Cyber-Attacks from Smart Grid Systems
    Muthubalaji, Sankaramoorthy
    Muniyaraj, Naresh Kumar
    Rao, Sarvade Pedda Venkata Subba
    Thandapani, Kavitha
    Mohan, Pasupuleti Rama
    Somasundaram, Thangam
    Farhaoui, Yousef
    BIG DATA MINING AND ANALYTICS, 2024, 7 (02): : 399 - 418
  • [28] Population-based prevalence study of common congenital malformations of the alimentary tract and abdominal wall in Thailand: a study using data from the National Health Security Office
    Sirichamratsakul, Kulpreeya
    Laochareonsuk, Wison
    Surachat, Komwit
    Sangkhathat, Surasak
    WORLD JOURNAL OF PEDIATRIC SURGERY, 2023, 6 (03)