Suppr超能文献

SlowITe,一种影响 MQTT 的新型拒绝服务攻击。

SlowITe, a Novel Denial of Service Attack Affecting MQTT.

机构信息

Consiglio Nazionale delle Ricerche (CNR), IEIIT Institute, 16149 Genoa, Italy.

Department of Informatics, Bioengineering, Robotics and System Engineering (DIBRIS), University of Genoa, 16145 Genoa, Italy.

出版信息

Sensors (Basel). 2020 May 21;20(10):2932. doi: 10.3390/s20102932.

Abstract

Security of the Internet of Things is a crucial topic, due to the criticality of the networks and the sensitivity of exchanged data. In this paper, we target the Message Queue Telemetry Transport (MQTT) protocol used in IoT environments for communication between IoT devices. We exploit a specific weakness of MQTT which was identified during our research, allowing the client to configure the behavior of the server. In order to validate the possibility to exploit such vulnerability, we propose SlowITe, a novel low-rate denial of service attack aimed to target MQTT through low-rate techniques. We validate SlowITe against real MQTT services, considering both plain text and encrypted communications and comparing the effects of the threat when targeting different daemons. Results show that the attack is successful and it is able to exploit the identified vulnerability to lead a DoS on the victim with limited attack resources.

摘要

物联网的安全性是一个至关重要的话题,这是由于网络的关键性和所交换数据的敏感性所决定的。在本文中,我们针对物联网环境中用于物联网设备之间通信的消息队列遥测传输(MQTT)协议。我们利用了在研究过程中发现的 MQTT 的一个特定弱点,该弱点允许客户端配置服务器的行为。为了验证利用这种漏洞的可能性,我们提出了 SlowITe,这是一种针对 MQTT 的新型低速率拒绝服务攻击,旨在通过低速率技术来实现。我们针对真实的 MQTT 服务来验证 SlowITe,同时考虑到明文和加密通信,并比较了当针对不同守护进程时威胁的影响。结果表明,该攻击是成功的,并且它能够利用已识别的漏洞,以有限的攻击资源对受害者发起 DoS。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/47e4/7285273/679155715452/sensors-20-02932-g001.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验