首页> 外文会议>IEEE Conference on Communications and Network Security >Inducing data loss in Zigbee networks via join/association handshake spoofing
【24h】

Inducing data loss in Zigbee networks via join/association handshake spoofing

机译:通过联接/关联握手欺骗在Zigbee网络中导致数据丢失

获取原文

摘要

Zigbee is an IEEE 802.15.4-based specification for low-power wireless mesh networks. Being a protocol with several known vulnerabilities, it continues to attract extensive research interest due to its potential applications in the Internet-of-Things (IoT). One of Zigbee's weak points lies in the network coordinator's initial handshake with a joining device, which is unencrypted. Our paper proposes a denial-of-service attack which exploits this fact to convince an end device to send its data to a rogue device on a different channel rather than the actual coordinator. Because the resource limitations of Zigbee devices generally preclude permanent storage, this is likely to result in loss of the transmitted data. We successfully demonstrate our attack and propose a solution that uses challenge-response based authentication to mitigate the attack.
机译:Zigbee是用于低功率无线网状网络的基于IEEE 802.15.4的规范。作为具有多个已知漏洞的协议,由于其在物联网(IoT)中的潜在应用,它继续吸引了广泛的研究兴趣。 Zigbee的弱点之一在于网络协调器与未加密的连接设备的初始握手。我们的论文提出了一种拒绝服务攻击,利用此事实说服终端设备将其数据发送到另一个通道上的恶意设备,而不是实际的协调器。由于Zigbee设备的资源限制通常会阻止永久存储,因此很可能导致传输数据的丢失。我们成功演示了攻击,并提出了一种解决方案,该解决方案使用基于质询-响应的身份验证来减轻攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号