An Innovative 0?Day Attack against ZigBee: Exploitation and Protection System Analysis

Vaccari, Ivan and Aiello, Maurizio and Cambiaso, Enrico (2021) An Innovative 0?Day Attack against ZigBee: Exploitation and Protection System Analysis. In: Theory and Practice of Mathematics and Computer Science Vol. 8. B P International, pp. 146-166. ISBN 978-93-90768-08-0

Full text not available from this repository.

Abstract

Internet of Things networks represent an emerging phenomenon bringing connectivity to common sensors. Due to the limited capabilities and to the sensitive nature of the devices, security assumes a crucial and primary role. In this paper, we report an innovative and extremely dangerous threat targeting networks. The attack is based on Remote AT Commands exploitation, providing a malicious user the possibility to reconfigure or disconnect sensors from the network. We present the proposed attack and evaluate its efficiency by executing tests on a real network. Results demonstrate how the threat can be successfully executed and how it is able to focus on the targeted nodes, without affecting other nodes of the network. Moreover, we developed an innovative protection system able to detect and protect the devices from this innovative threat. Also, the protection system and the attack tool implemented are tested and validated on a real network by using XBee mod? ule, a wireless module adopted to implement and instantiate ZigBee network. The proposed protection system aims to verify if devices are able to communicate on the network when the attack is running. In this case, just before the sensor is ready to communicate on the network, an internal check is accomplished directly by the device: if needed, an additional reconfiguration is accomplished, in order to restore connectivity of the node in order to mitigate the threat. The results of this work are very interesting since, if executed against a real network, the Remote AT Command attack could create huge damage to companies and networks.

Item Type: Book Section
Subjects: Archive Digital > Computer Science
Depositing User: Unnamed user with email support@archivedigit.com
Date Deposited: 01 Nov 2023 11:55
Last Modified: 01 Nov 2023 11:55
URI: http://eprints.ditdo.in/id/eprint/1539

Actions (login required)

View Item
View Item