Metongnon, Lionel
[UCL]
Sadre, Ramin
[UCL]
The Internet of Things (IoT) leads to the interconnectivity of a wide range of device types running an equally wide range of operating systems and applications. This heterogeneity of hardware and software poses significant challenges to security. Constrained IoT devices often do not have enough resources to carry the overhead of an intrusion protection system or complex security protocols. Furthermore, they are often not properly managed and updated. Network scans are a valuable tool to discover vulnerable devices. In the context of IoT, the initiator of the scan can be particularly interested in finding constrained devices, assuming that they are easier targets for attacks. However, in IoT networks hosting devices of various types, performing a scan with a high discovery rate can be a challenging task, since a scan working well for, eg, a WiFi network might easily overload a low-power network such as IEEE 802.15.4. In this paper, we propose an approach to increase the efficiency of network scans in heterogeneous environments by combining them with active round-trip time measurements. The measurements allow the scanner to differentiate IoT nodes by the used network technology. Using the knowledge gained from this differentiation, our approach adapts the scan strategy to reduce probe losses, and hence the speed and efficiency of the scan. We validate our approach through simulations of a mixed IoT infrastructure consisting of WiFi and multihop IEEE 802.15.4 subnetworks.
- Frahim J Pignataro C Apcar J Morrow M Securing the internet of things: A proposed framework https://www.cisco.com/c/en/us/about/security-center/secure-iot-proposed-framework.html
- Gayer O Wilder O Zeifman I Cctv botnet in our own back yard https://www.incapsula.com/blog/cctv-ddos-botnet-back-yard.html
- Constantin L Thousands of hacked cctv devices used in ddos attacks http://www.pcworld.com/article/3089346/security/thousands-of-hacked-cctv-devices-used-in-ddos-attacks.html
- Cid D Large cctv botnet leveraged in ddos attacks https://blog.sucuri.net/2016/06/large-cctv-botnet-leveraged-ddos-attacks.html
- Barnett R Irwin B Towards a taxonomy of network scanning techniques Wilderness, South Africa 2008 1 7
- Durumeric Z Wustrow E Halderman JA Zmap: Fast internet-wide scanning and its security applications. Washington, D.C. 2013 605 620
- Durumeric Z Bailey M Halderman JA An internet-wide view of internet-wide scanning San Diego, CA 2014 65 78
- Dainotti A King A Papale F Pescape A Analysis of a/0 stealth scan from a botnet Boston, MA, USA 2012 1 14
- Pa, EMU, 9, 1 (2015)
- Metongnon L Ezin CE Sadre R Efficient probing of heterogeneous iot networks 2017 1052 1058
- Sarr C., Chaudet C., Chelius G., Lassous I.G., Bandwidth Estimation for IEEE 802.11-Based Ad Hoc Networks, 10.1109/tmc.2008.41
- Ribeiro VJ Riedi RH Baraniuk RG Navratil J Cottrell L pathchirp: Efficient available bandwidth estimation for network paths 2003
- Johnsson A Melander B Björkman M Bandwidth measurement in wireless networks Springer 2006 89 98
- Farooq MO Kunz T Proactive bandwidth estimation for ieee 802.15.4-based networks Dresden, Germany 2013 1 5
- Beverly R A robust classifier for passive tcp/ip fingerprinting Springer Antibes Juan-les-Pins, France 2004 158 167
- Taleck G Ambiguity resolution via passive os fingerprinting Springer St. Lucia 2003 192 206
- Baronti Paolo, Pillai Prashant, Chook Vince W.C., Chessa Stefano, Gotta Alberto, Hu Y. Fun, Wireless sensor networks: A survey on the state of the art and the 802.15.4 and ZigBee standards, 10.1016/j.comcom.2006.12.020
- Montenegro G Kushalnagar N Hui J Culler D RFC 4944 transmission of ipv6 packets over ieee 802.15. 4 networks 2007
- Hui J Thubert P RFC 6282 compression format for ipv6 datagrams over ieee 802.15. 4-based networks 2011
- Deering SE RFC 2460 internet protocol, version 6 (ipv6) specification 1998
- Shelby, 6lowpan: The Wireless Embedded Internet (2011)
- Winter T RFC 6550 rpl: Ipv6 routing protocol for low-power and lossy networks 2012
- Gomez Carles, Paradells Josep, Wireless home automation networks: A survey of architectures and technologies, 10.1109/mcom.2010.5473869
- Adrian D Durumeric Z Singh G Halderman JA Zippier zmap: internet-wide scanning at 10 gbps San Diego, CA 2014
- Gont F Chown T RFC 7707 network reconnaissance in ipv6 networks 2016
- Bilalb, arXiv preprint arXiv:1307.4129 (2013)
Bibliographic reference |
Metongnon, Lionel ; Sadre, Ramin. Fast and efficient probing of heterogeneous IoT networks. In: International Journal of Network Management, Vol. SPECIAL ISSUE PAPER, p. e1997 (2017) |
Permanent URL |
http://hdl.handle.net/2078.1/191842 |