Quantifying the Impact of Stealthy BLE Spam & Flooding Attacks on IoT Environments
For IoT security researchers and military system designers, this work provides the first quantitative analysis of BLE flooding attacks and a practical countermeasure, though it is incremental as it builds on known attack vectors.
This paper develops a quantitative foundation for understanding the impact of BLE flooding attacks on IoT environments, particularly in military field medical systems, and proposes a practical deterrence strategy based on agility to raise the cost of such attacks.
The energy-efficient design of the BLE protocol, emphasis on rapid, and userfriendly discovery, making it an ideal choice for IoMTs, specifically, military field medical systems, and battlefield wearable sensors. Especially in active conflict zones, when static medical facilities are vulnerable and often targeted, limiting their viability for sustained care delivery. This rapid deployment, and ease of management comes at the cost of expanded attack surface, i.e., BLE flooding attacks. During such attacks, adversaries flood advertisement channels with unauthorized connection or advertising requests to exhaust nearby device resources and disrupt legitimate communication, sometimes culminating in denial-of-service conditions. A first public proof-of-concept of such attacks, using a Raspberry Pi has since been adapted to commodity platforms (e.g., Flipper Zero, HackRF, Android), lowering the barrier to attack. In contested environments, such platforms are directly relevant to adversarial RF jamming and spoofing operations, where low-cost, portable devices can induce disproportionate disruption in dense wireless ecosystems. In this work, we develop a quantitative foundation for understanding the impact of such attacks and propose a practical deterrence strategy based on agility to raise the cost of such attacks.