BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth Peripherals
Fenghao Xu, Wenrui Diao, Zhou Li, Jiongyi Chen, Kehuan Zhang
Abstract
Bluetooth is a widely used communication technology, especially under the scenarios of mobile computing and Internet of Things. Once paired with a host device, a Bluetooth device then can exchange commands and data, such as voice, keyboard/mouse inputs, network, blood pressure data, and so on, with the host. Due to the sensitivity of such data and commands, some security measures have already been built into the Bluetooth protocol, like authentication, encryption, authorization, etc. However, according to our studies on the Bluetooth protocol as well as its implementation on Android system, we find that there are still some design flaws which could lead to serious security consequences. For example, it is found that the authentication process on Bluetooth profiles is quite inconsistent and coarsegrained: if a paired device changes its profile, it automatically gets trust and users would not be notified. Also, there is no strict verification on the information provided by the Bluetooth device itself, so that a malicious device can deceive a user by changing its name, profile information, and icon to be displayed on the screen. To better understand the problem, we performed a systematic study over the Bluetooth profiles and presented three attacks to demonstrate the feasibility and potential damages of such Bluetooth design flaws. The attacks were implemented on a Raspberry Pi 2 device and evaluated with different Android OS versions ranging from 5.1 to the latest 8.1. The results showed adversaries could bypass existing protections of Android (e.g., permissions, isolations, etc.), launch Man-in-the-Middle attack, control the victim apps and system, steal sensitive information, etc. To mitigate such threats, a new Bluetooth validation mechanism was proposed. We implemented the prototype system based on the AOSP project and deployed it on a Google Pixel 2 phone for evaluation. The experiment showed our solution could effectively prevent the attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97550166-cf50-4e67-8528-e25cfc8bc384Cited by top-tier papers16
- LIGHTBLUE: Automatic Profile-Aware Debloating of Bluetooth StacksJianliang Wu, Ruoyu Wu, Daniele Antonioli, Mathias Payer et al.USENIX Security 2021 · 38 citations
- Formal Model-Driven Discovery of Bluetooth Protocol Design VulnerabilitiesJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2022 · 36 citations
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2024 · 22 citations
- BLESS: A BLE Application Security Scanning FrameworkYue Zhang, Jian Weng, Zhen Ling, Bryan Pearson et al.INFOCOM 2020 · 15 citations
- When Good Becomes Evil: Tracking Bluetooth Low Energy Devices via Allowlist-based Side Channel and Its CountermeasureYue Zhang, Zhiqiang LinCCS 2022 · 12 citations
Builds on8
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 126 citations
- Protecting Privacy of BLE Device UsersKassem Fawaz, Kyu-Han Kim, Kang G. ShinUSENIX Security 2016 · 111 citations
- Making USB Great Again with USBFILTERDave (Jing) Tian, Nolen Scaife, Adam Bates, Kevin R. B. Butler et al.USENIX Security 2016 · 56 citations
- SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CJing (Dave) Tian, Nolen Scaife, Deepak Kumar, Michael D. Bailey et al.S&P 2018 · 52 citations
- Defending against Malicious Peripherals with CinchSebastian Angel, Riad S. Wahby, Max Howald, Joshua B. Leners et al.USENIX Security 2016 · 44 citations
Related papers
- Blacktooth: Breaking through the Defense of Bluetooth in SilenceMingrui Ai, Kaiping Xue, Bo Luo, Lutong Chen et al.CCS 2022 · 10 citations
- BIAS: Bluetooth Impersonation AttackSDaniele Antonioli, Nils Ole Tippenhauer, Kasper RasmussenS&P 2020 · 90 citations
- Fake It till You Make It: Enhancing Security of Bluetooth Secure Connections via Deferrable AuthenticationMarc Fischlin, Olga SaninaCCS 2024 · 2 citations
- Method Confusion Attack on Bluetooth PairingMaximilian von Tschirschnitz, Ludwig Peuckert, Fabian Franzen, Jens GrossklagsS&P 2021 · 42 citations
- Rediscovering Method Confusion in Proposed Security Fixes for BluetoothMaximilian von Tschirschnitz, Ludwig Peuckert, Moritz Buhl, Jens GrossklagsNDSS 2025
