CRMay 15, 2018

IoT Security: An End-to-End View and Case Study

arXiv:1805.05853v120 citations
Originality Incremental advance
AI Analysis

This work addresses security vulnerabilities in IoT systems for manufacturers and users, though it is incremental as it builds on existing exploit knowledge.

The paper tackles IoT security by presenting an end-to-end view for risk assessment and conducting a case study on the Edimax IP camera system, where they identified vulnerabilities that allow full control of cameras and demonstrated real-world attacks. It also models Mirai malware propagation to highlight risks, raising alarms for manufacturers.

In this paper, we present an end-to-end view of IoT security and privacy and a case study. Our contribution is three-fold. First, we present our end-to-end view of an IoT system and this view can guide risk assessment and design of an IoT system. We identify 10 basic IoT functionalities that are related to security and privacy. Based on this view, we systematically present security and privacy requirements in terms of IoT system, software, networking and big data analytics in the cloud. Second, using the end-to-end view of IoT security and privacy, we present a vulnerability analysis of the Edimax IP camera system. We are the first to exploit this system and have identified various attacks that can fully control all the cameras from the manufacturer. Our real-world experiments demonstrate the effectiveness of the discovered attacks and raise the alarms again for the IoT manufacturers. Third, such vulnerabilities found in the exploit of Edimax cameras and our previous exploit of Edimax smartplugs can lead to another wave of Mirai attacks, which can be either botnets or worm attacks. To systematically understand the damage of the Mirai malware, we model propagation of the Mirai and use the simulations to validate the modeling. The work in this paper raises the alarm again for the IoT device manufacturers to better secure their products in order to prevent malware attacks like Mirai.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes