MQTTactic: Security Analysis and Verification for Logic Flaws in MQTT Implementations
Bin Yuan, Zhanxiang Song, Yan Jia, Zhenyu Lu, Deqing Zou, Hai Jin, Luyi Xing
Abstract
IoT messaging protocols are critical to connecting users and IoT devices. Among all the protocols, the Message Queuing and Telemetry Transport (MQTT) is arguably the most widely used. Mainstream IoT platforms leverage MQTT brokers, server side implementation of MQTT, to enable and mediate user-device communication (e.g., the transmission of control commands). There are over 70 open-source MQTT brokers, which have been widely adopted in production. Any security defects in those open-source MQTT brokers easily get into many vendors’ IoT deployments with amplified impacts, inevitably endangering the security of IoT applications and millions of users. We report the first systematic security analysis of open-source MQTT brokers in the wild. To enable the analysis, we designed and developed MQTTactic, a semi-automatic tool that can formally verify MQTT broker implementations based on generated security properties. MQTTactic is based on static code analysis, formal modeling, and automated model checking (with off-the-shelf model checker Spin). In designing MQTTactic, we characterize and address key technical challenges. MQTTactic currently focuses on authorization-related properties, and discovered 7 novel, zero-day flaws practically enabling serious, unauthorized access. We reported all flaws to related parties, who acknowledged the issues and have been taking actions to fix them. Our thorough evaluation shows that MQTTactic is effective and practical.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8b5cef53-55e0-4cc4-b3ce-5f3a1d53ec1fCited by top-tier papers3
- Untangling the Knot: Breaking Access Control in Home Wireless Mesh NetworksXin'an Zhou, Qing Deng, Juefei Pu, Keyu Man et al.CCS 2024 · 2 citations
- Hidden and Lost Control: on Security Design Risks in IoT User-Facing Matter ControllerHaoqiang Wang, Yiwei Fang, Yichen Liu, Ze Jin et al.NDSS 2025
- MBFuzzer: A Multi-Party Protocol Fuzzer for MQTT BrokersXiangpu Song, Jianliang Wu, Yingpei Zeng, Hao Pan et al.USENIX Security 2025
Related papers
- MPInspector: A Systematic and Automatic Approach for Evaluating the Security of IoT Messaging ProtocolsQinying Wang, Shouling Ji, Yuan Tian, Xuhong Zhang et al.USENIX Security 2021 · 45 citations
- FUME: Fuzzing Message Queuing Telemetry Transport BrokersBryan Pearson, Yue Zhang, Cliff C. Zou, Xinwen FuINFOCOM 2022 · 16 citations
- Burglars' IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsYan Jia, Luyi Xing, Yuhang Mao, Dongfang Zhao et al.S&P 2020 · 64 citations
- ProFactory: Improving IoT Security via Formalized Protocol CustomizationFei Wang, Jianliang Wu, Yuhong Nan, Yousra Aafer et al.USENIX Security 2022
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
