Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols

Carlotta Tagliaro, Martina Komsic, Andrea Continella, Kevin Borgolte, Martina Lindorfer

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

1 Citation (Scopus)
121 Downloads (Pure)

Abstract

Internet-of-Things (IoT) devices, ranging from smart home assistants to health devices, are pervasive: Forecasts estimate their number to reach 29 billion by 2030. Understanding the security of their machine-to-machine communication is crucial. Prior work focused on identifying devices’ vulnerabilities or proposed protocol-specific solutions. Instead, we investigate the security of backends speaking IoT protocols, that is, the backbone of the IoT ecosystem. We focus on three real-world protocols for our large-scale analysis: MQTT, CoAP, and XMPP. We gather a dataset of over 337,000 backends, augment it with geographical and provider data, and perform non-invasive active measurements to investigate three major security threats: information leakage, weak authentication, and denial of service. Our results provide quantitative evidence of a problematic immaturity in the IoT ecosystem. Among other issues, we find that 9.44% backends expose information, 30.38% CoAP-speaking backends are vulnerable to denial of service attacks, and 99.84% of MQTT- and XMPP-speaking backends use insecure transport protocols (only 0.16% adopt TLS, of which 70.93% adopt a vulnerable version).

Original languageEnglish
Title of host publicationProceedings of 27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024
PublisherAssociation for Computing Machinery
Pages561-578
Number of pages18
ISBN (Electronic)9798400709593
DOIs
Publication statusPublished - 30 Sept 2024
Event27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024 - Padua, Italy
Duration: 30 Sept 20242 Oct 2024
Conference number: 27

Conference

Conference27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024
Abbreviated titleRAID 2024
Country/TerritoryItaly
CityPadua
Period30/09/242/10/24

Keywords

  • backends
  • CoAP
  • Internet of Things (IoT)
  • MQTT
  • XMPP

Fingerprint

Dive into the research topics of 'Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols'. Together they form a unique fingerprint.

Cite this