错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Assessment of an Internet of Things Device

  • Daiana Alexandra Cîmpean,
  • Marius-Constantin Vochin,
  • Răzvan-Eusebiu Crăciunescu,
  • Ana-Maria-Claudia Drăgulinescu,
  • Laurențiu Boicescu

摘要

The rapid advance of Internet of Things (IoT) and its immersion in every domain brought into attention, besides many of its technical, social, and economic advantages, a panoply of security vulnerabilities and attack vectors that threaten IoT interconnected devices. IoT devices face many security issues such as weak authentication, insufficient encryption, deficient device management, insecure interfaces, inadequate physical security, lack of standardization, privacy concerns, insecure networks, resource constraints, and non-compliance with security standards. This highlights the pressing need for comprehensive security measures that currently seem insufficient to address the evolving landscape of threats in the dynamic IoT ecosystem. This paper conducts a security evaluation of a physical IoT device through the penetration testing methodology. It then focuses on a known vulnerability from the Common Vulnerabilities and Exposures (CVE) database. It presents the execution of a brute force attack to uncover credentials and the device’s buffer overflow vulnerability to cause a denial of service (DoS) on the device’s server. Employing a hands-on approach, the research emphasizes the practical execution of these exploitation scenarios providing a step-by-step guide on how they were performed. Lastly, it delves into the development of a proof of concept (PoC) application created to automate the process of firmware analysis and running the buffer overflow exploit for this particular use case.