Literature DB >> 32455752

SlowITe, a Novel Denial of Service Attack Affecting MQTT.

Ivan Vaccari1,2, Maurizio Aiello1, Enrico Cambiaso1.   

Abstract

Security of the Internet of Things is a crucial topic, due to the criticality of the networks and the sensitivity of exchanged data. In this paper, we target the Message Queue Telemetry Transport (MQTT) protocol used in IoT environments for communication between IoT devices. We exploit a specific weakness of MQTT which was identified during our research, allowing the client to configure the behavior of the server. In order to validate the possibility to exploit such vulnerability, we propose SlowITe, a novel low-rate denial of service attack aimed to target MQTT through low-rate techniques. We validate SlowITe against real MQTT services, considering both plain text and encrypted communications and comparing the effects of the threat when targeting different daemons. Results show that the attack is successful and it is able to exploit the identified vulnerability to lead a DoS on the victim with limited attack resources.

Entities:  

Keywords:  cyber-security; internet of things; mqtt; network security; protocols security; slow dos attack

Year:  2020        PMID: 32455752     DOI: 10.3390/s20102932

Source DB:  PubMed          Journal:  Sensors (Basel)        ISSN: 1424-8220            Impact factor:   3.576


  1 in total

1.  MultiFuzz: A Coverage-Based Multiparty-Protocol Fuzzer for IoT Publish/Subscribe Protocols.

Authors:  Yingpei Zeng; Mingmin Lin; Shanqing Guo; Yanzhao Shen; Tingting Cui; Ting Wu; Qiuhua Zheng; Qiuhua Wang
Journal:  Sensors (Basel)       Date:  2020-09-11       Impact factor: 3.576

  1 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.