Abstract
Internet-of-Things (IoT) devices, ranging from smart home assistants to health devices, are pervasive: Forecasts estimate their number to reach 29 billion by 2030. Understanding the security of their machine-to-machine communication is crucial. Prior work focused on identifying devices’ vulnerabilities or proposed protocol-specific solutions. Instead, we investigate the security of backends speaking IoT protocols, that is, the backbone of the IoT ecosystem. We focus on three real-world protocols for our large-scale analysis: MQTT, CoAP, and XMPP. We gather a dataset of over 337,000 backends, augment it with geographical and provider data, and perform non-invasive active measurements to investigate three major security threats: information leakage, weak authentication, and denial of service. Our results provide quantitative evidence of a problematic immaturity in the IoT ecosystem. Among other issues, we find that 9.44% backends expose information, 30.38% CoAP-speaking backends are vulnerable to denial of service attacks, and 99.84% of MQTT- and XMPP-speaking backends use insecure transport protocols (only 0.16% adopt TLS, of which 70.93% adopt a vulnerable version).
| Original language | English |
|---|---|
| Title of host publication | Proceedings of 27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024 |
| Publisher | Association for Computing Machinery |
| Pages | 561-578 |
| Number of pages | 18 |
| ISBN (Electronic) | 9798400709593 |
| DOIs | |
| Publication status | Published - 30 Sept 2024 |
| Event | 27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024 - Padua, Italy Duration: 30 Sept 2024 → 2 Oct 2024 Conference number: 27 |
Conference
| Conference | 27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024 |
|---|---|
| Abbreviated title | RAID 2024 |
| Country/Territory | Italy |
| City | Padua |
| Period | 30/09/24 → 2/10/24 |
Keywords
- backends
- CoAP
- Internet of Things (IoT)
- MQTT
- XMPP
Fingerprint
Dive into the research topics of 'Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols'. Together they form a unique fingerprint.Research output
- 13 Citations
- 1 Preprint
-
Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols
Tagliaro, C., Komsic, M., Continella, A., Borgolte, K. & Lindorfer, M., 15 May 2024.Research output: Working paper › Preprint › Academic
Open AccessFile18 Downloads (Pure)
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver