Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

SlowTT: A Slow Denial of Service Against IoT Networks

Academic Article
Publication Date:
2020
abstract:
The security of Internet of Things environments is a critical and trending topic, due to the nature of the networks and the sensitivity of the exchanged information. In this paper, we investigate the security of the Message Queue Telemetry Transport (MQTT) protocol, widely adopted in IoT infrastructures. We exploit two specific weaknesses of MQTT, identified during our research activities, allowing the client to configure the KeepAlive parameter and MQTT packets to execute an innovative cyber threat against the MQTT broker. In order to validate the exploitation of such vulnerabilities, we propose SlowTT, a novel "Slow" denial of service attack aimed at targeting MQTT through low-rate techniques, characterized by minimum attack bandwidth and computational power requirements. We validate SlowTT against real MQTT services, by considering both plaintext and encrypted communications and by comparing the effects of the attack when targeting different application daemons and protocol versions. Results show that SlowTT is extremely successful, and it can exploit the identified vulnerability to execute a denial of service against the IoT network by keeping the connection alive for a long time.
Iris type:
01.01 Articolo in rivista
Keywords:
Internet of Things; protocols security; cyber security; network security; slow DoS attack; MQTT
List of contributors:
Vaccari, Ivan; Aiello, Maurizio; Cambiaso, Enrico
Authors of the University:
AIELLO MAURIZIO
CAMBIASO ENRICO
Handle:
https://iris.cnr.it/handle/20.500.14243/377499
Published in:
INFORMATION
Journal
  • Overview

Overview

URL

https://www.mdpi.com/2078-2489/11/9/452
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)