Identifying the BLE Misconfigurations of IoT Devices through Companion Mobile Apps

2022 19th Annual IEEE International Conference on Sensing, Communication, and Networking (SECON)(2022)

引用 0|浏览5
暂无评分
摘要
Bluetooth Low Energy (BLE) is widely deployed and has become the de-facto communication standard in the IoT ecosystem. Naturally, the security of BLE received much attention from both researchers and attackers. In another aspect, the BLE specifications provide the security guidelines for BLE deployments. Due to various reasons, the developers do not follow the guidelines in the implementation process, which introduces the misconfiguration issue. However, identifying these BLE mis-configurations in IoT device firmware is quite challenging. In this work, we do not handle the BLE-enabled devices directly. Instead, we focus on the security misconfiguration issues in their companion mobile apps, which can reflect the deployment conditions of the corresponding devices. Further, we designed an analysis tool - BSC-Checker to detect the misconfigurations based on pre-defined checking strategies. With BSC-Checker, we conducted large-scale experiments on 4,589 apps from multiple app markets. The result shows that the BLE configurations of most BLE apps disobey at least one security rule, and the current BLE deployment status is not optimistic.
更多
查看译文
关键词
BLE specifications,security guidelines,BLE deployments,misconfiguration issue,BLE mis-configurations,IoT device firmware,BLE-enabled devices,security misconfiguration issues,companion mobile apps,deployment conditions,corresponding devices,analysis tool - BSC-Checker,multiple app markets,BLE configurations,BLE apps disobey at least one security rule,current BLE deployment status,BLE misconfigurations,IoT devices,Bluetooth Low Energy,de-facto communication standard,IoT ecosystem
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要