Demystifying the Security Implications in IoT Device Rental Services
Yi He, Yunchao Guan, Ruoyu Lun, Shangru Song, Zhihao Guo, Jianwei Zhuge, Jianjun Chen, Qiang Wei, Zehui Wu, Miao Yu, Hetian Shi, Qi Li
摘要
Nowadays, unattended device rental services with cellular IoT controllers, such as e-scooters and EV chargers, are widely deployed in public areas around the world, offering convenient access to users via mobile apps. While differing from traditional smart homes in functionality and implementation, the security of these devices remains largely unexplored. In this work, we conduct a systematic study to uncover security implications in IoT device rental services. By investigating 17 physical devices and 92 IoT apps, we identify multiple design and implementation flaws across a wide range of products, which can lead to severe security consequences, such as forcing all devices offline, remotely controlling all devices, or hijacking all users' accounts of the vendors. The root cause is that rentable IoT devices adopt weak resource identifiers (IDs), and attackers can infer these IDs at scale and exploit access control flaws to manipulate these resources. For instance, rentable IoT products allow authenticated users to find and use any device from the rentable IoT apps via a device serial number, which can be easily inferred by attackers and combined with other vulnerabilities to exploit remote devices on a large scale. To identify these risks, we propose a tool, called IDScope, to automatically detect the weak IDs in apps and assess if these IDs can be abused to scale the exploitation scope of existing access control vulnerabilities. Finally, we identify 57 vulnerabilities in 28 products which can lead to various large-scale exploitation in 24 products and affect millions of users and devices by exploiting three types of weak IDs. The vendors have confirmed our findings and most issues have been mitigated with our assistance.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper37
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- A variegated look at 5G in the wild: performance, power, and QoE implicationsArvind Narayanan, Xumiao Zhang, Ruiyang Zhu, Ahmad Hassan 等SIGCOMM 2021 · 被引用 259 次
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 被引用 254 次
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu 等USENIX Security 2018 · 被引用 236 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
相关 Paper
- Plug-N-Pwned: Comprehensive Vulnerability Analysis of OBD-II Dongles as A New Over-the-Air Attack Surface in Automotive IoTHaohuang Wen, Qi Alfred Chen, Zhiqiang LinUSENIX Security 2020
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 被引用 77 次
- Looking from the Mirror: Evaluating IoT Device Security through Mobile Companion AppsXueqiang Wang, Yuqiong Sun, Susanta Nanda, XiaoFeng WangUSENIX Security 2019 · 被引用 65 次
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 被引用 59 次
- Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasuresSihan Wang, Guan-Hua Tu, Xinyu Lei, Tian Xie 等MobiCom 2021 · 被引用 12 次
