A diverse set of Internet of Things (IoT) devices are becoming an integrated part of daily lives, and playing an increasingly vital role in various industry, enterprise and agricultural settings. The current IoT ecosystem relies on several IoT management platforms to manage and operate a large number of IoT devices, their data, and their connectivity. Considering their key role, these platforms must be properly secured against cyber attacks. In this work, we first explore the core operations/features of leading platforms to design a framework to perform a systematic security evaluation of these platforms. Subsequently, we use our framework to analyze a representative set of 52 IoT management platforms, including 42 web-hosted and 10 locally-deployable platforms. We discover a number of high severity unauthorized access vulnerabilities in 9/52 evaluated IoT management platforms, which could be abused to perform attacks such as remote IoT SIM deactivation, IoT SIM overcharging and IoT device data forgery. More seriously, we also uncover instances of broken authentication in 13/52 platforms, including complete account takeover on 8/52 platforms along with remote code execution on 2/52 platforms. In effect, 17/52 platforms were affected by vulnerabilities that could lead to platform-wide attacks. Overall, vulnerabilities were uncovered in 33 platforms, out of which 28 platforms responded to our responsible disclosure. We were also assigned 11 CVEs and awarded bounty for our findings.
翻译:各类物联网设备正日益融入日常生活,并在工业、企业和农业等多个领域发挥愈发关键的作用。当前的物联网生态系统依赖数个物联网管理平台来管理和运营大量物联网设备及其数据和连接。鉴于其关键作用,这些平台必须得到充分的网络安全防护。在本研究中,我们首先探索领先平台的核心操作与功能,设计了一个框架来对这些平台进行系统性安全评估。随后,我们利用该框架分析了具有代表性的52个物联网管理平台,包括42个基于Web的平台和10个本地可部署平台。我们在评估的52个平台中的9个平台上发现了多个高危未授权访问漏洞,这些漏洞可能被利用来实施远程物联网SIM卡停用、物联网SIM卡超额计费以及物联网设备数据伪造等攻击。更为严重的是,我们还在52个平台中的13个平台上发现了认证机制受损的实例,其中包括52个平台中的8个平台存在完全账户接管漏洞,以及52个平台中的2个平台存在远程代码执行漏洞。实际上,52个平台中的17个平台受到可能导致平台级攻击的漏洞影响。总体而言,在33个平台中发现了漏洞,其中28个平台对我们的负责任的披露作出了回应。我们还因此获得了11个CVE编号和漏洞赏金。