IoT Goes Nuclear: Creating a ZigBee Chain Reaction
Eyal Ronen, Adi Shamir, Achi-Or Weingarten, Colin O'Flynn
摘要
Within the next few years, billions of IoT devices will densely populate our cities. In this paper we describe a new type of threat in which adjacent IoT devices will infect each other with a worm that will spread explosively over large areas in a kind of nuclear chain reaction, provided that the density of compatible IoT devices exceeds a certain critical mass. In particular, we developed and verified such an infection using the popular Philips Hue smart lamps as a platform. The worm spreads by jumping directly from one lamp to its neighbors, using only their built-in ZigBee wireless connectivity and their physical proximity. The attack can start by plugging in a single infected bulb anywhere in the city, and then catastrophically spread everywhere within minutes, enabling the attacker to turn all the city lights on or off, permanently brick them, or exploit them in a massive DDOS attack. To demonstrate the risks involved, we use results from percolation theory to estimate the critical mass of installed devices for a typical city such as Paris whose area is about 105 square kilometers: The chain reaction will fizzle if there are fewer than about 15,000 randomly located smart lights in the whole city, but will spread everywhere when the number exceeds this critical mass (which had almost certainly been surpassed already).
To make such an attack possible, we had to find a way to remotely yank already installed lamps from their current networks, and to perform over-the-air firmware updates. We overcame the first problem by discovering and exploiting a major bug in the implementation of the Touchlink part of the ZigBee Light Link protocol, which is supposed to stop such attempts with a proximity test. To solve the second problem, we developed a new version of a side channel attack to extract the global AES-CCM key (for each device type) that Philips uses to encrypt and authenticate new firmware. We used only readily available equipment costing a few hundred dollars, and managed to find this key without seeing any actual updates. This demonstrates once again how difficult it is to get security right even for a large company that uses standard cryptographic techniques to protect a major product.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper23
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 被引用 411 次
- BlackIoT: IoT Botnet of High Wattage Devices Can Disrupt the Power GridSaleh Soltan, Prateek Mittal, H. Vincent PoorUSENIX Security 2018 · 被引用 348 次
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu 等USENIX Security 2018 · 被引用 236 次
- Understanding and Improving Security and Privacy in Multi-User Smart Homes: A Design Exploration and In-Home User StudyEric Zeng, Franziska RoesnerUSENIX Security 2019 · 被引用 190 次
- All Things Considered: An Analysis of IoT Devices on Home NetworksDeepak Kumar, Kelly Shen, Benton Case, Deepali Garg 等USENIX Security 2019 · 被引用 189 次
相关 Paper
- LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic InterferenceFengchen Yang, Wenze Cui, Xinfeng Li, Chen Yan 等NDSS 2025
- Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access DelegationBin Yuan, Yan Jia, Luyi Xing, Dongfang Zhao 等USENIX Security 2020
- Examining Mirai's Battle over the Internet of ThingsHarm Griffioen, Christian DoerrCCS 2020 · 被引用 81 次
- How to BREAK MU-MIMO Precoding in IEEE 802.11 Wi-Fi NetworksFrancesca Meneghello, Francesco Gringoli, Marco Cominelli, Michele Rossi 等INFOCOM 2025 · 被引用 4 次
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
