Blacktooth: Breaking through the Defense of Bluetooth in Silence
Mingrui Ai, Kaiping Xue, Bo Luo, Lutong Chen, Nenghai Yu, Qibin Sun, Feng Wu
摘要
Bluetooth is a short-range wireless communication technology widely used by billions of personal computing, IoT, peripheral, and wearable devices. Bluetooth devices exchange commands and data, such as keyboard/mouse inputs, audio, and files, through a secure communication channel that is established through a pairing process. Due to the sensitivity of those commands and data, security mechanisms, such as encryption, authentication, and authorization, have been developed and adopted in the standards. Nevertheless, vulnerabilities continue to be discovered. In the literature, few successful attacks against the Bluetooth connection establishment stage have been reported. Many attacks simply assume that connections are already established or use a compromised agent, e.g, a malicious app or a careless user, to initialize the connection. We argue that such assumptions are strong and impractical. A stealthily established connection is a critical starting point for any practical attack against Bluetooth devices. In this paper, we demonstrate that the Bluetooth Specification contains a series of vulnerabilities that will enable an attacker to impersonate a Bluetooth device and successfully establish a connection with a victim device. The entire process does not require any involvement of the device owner/user or any malicious app on the victim device. The attacker could further escalate permissions by switching Bluetooth profiles to retrieve sensitive information from the victim device and inject arbitrary commands. We name our new attack as the Blacktooth Attack. To demonstrate the effectiveness and practicality of the Blacktooth attack, we evaluate it against 21 different Bluetooth devices with diverse manufacturers and operating
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian 等S&P 2024 · 被引用 22 次
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks and DefensesDaniele AntonioliCCS 2023 · 被引用 7 次
- BBC: Enabling BLE to Support Bluetooth ClassicHsun-Wei Cho, Kang G. ShinNSDI 2026
- OneTouch: Effortless 2FA Scheme to Secure Fingerprint Authentication with Wearable OTP TokenYihui Yan, Zhice YangUSENIX Security 2025
它引用的顶会 Paper8
- BIAS: Bluetooth Impersonation AttackSDaniele Antonioli, Nils Ole Tippenhauer, Kasper RasmussenS&P 2020 · 被引用 90 次
- The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDRDaniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne RasmussenUSENIX Security 2019 · 被引用 89 次
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 被引用 77 次
- BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth PeripheralsFenghao Xu, Wenrui Diao, Zhou Li, Jiongyi Chen 等NDSS 2019 · 被引用 51 次
- Method Confusion Attack on Bluetooth PairingMaximilian von Tschirschnitz, Ludwig Peuckert, Fabian Franzen, Jens GrossklagsS&P 2021 · 被引用 42 次
相关 Paper
- BLERP: BLE Re-Pairing Attacks and DefensesTommaso Sacchetti, Daniele AntonioliNDSS 2026 · 被引用 2 次
- Fake It till You Make It: Enhancing Security of Bluetooth Secure Connections via Deferrable AuthenticationMarc Fischlin, Olga SaninaCCS 2024 · 被引用 2 次
- Formal Model-Driven Discovery of Bluetooth Protocol Design VulnerabilitiesJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian 等S&P 2022 · 被引用 36 次
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyXijia Che, Yi He, Xuewei Feng, Kun Sun 等CCS 2024 · 被引用 10 次
- SweynTooth: Unleashing Mayhem over Bluetooth Low EnergyMatheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun 等USENIX ATC 2020 · 被引用 83 次
