Consumer Internet of Things (IoT) devices often leverage the local network to communicate with the corresponding companion app or other devices. This has benefits in terms of efficiency since it offloads the cloud. ENISA and NIST security guidelines underscore the importance of enabling default local communication for safety and reliability. Indeed, an IoT device should continue to function in case the cloud connection is not available. While the security of cloud-device connections is typically strengthened through the usage of standard protocols, local connectivity security is frequently overlooked. Neglecting the security of local communication opens doors to various threats, including replay attacks. In this paper, we investigate this class of attacks by designing a systematic methodology for automatically testing IoT devices vulnerability to replay attacks. Specifically, we propose a tool, named REPLIOT, able to test whether a replay attack is successful or not, without prior knowledge of the target devices. We perform thousands of automated experiments using popular commercial devices spanning various vendors and categories. Notably, our study reveals that among these devices, 51% of them do not support local connectivity, thus they are not compliant with the reliability and safety requirements of the ENISA/NIST guidelines. We find that 75% of the remaining devices are vulnerable to replay attacks with REPLIOT having a detection accuracy of 0.98-1. Finally, we investigate the possible causes of this vulnerability, discussing possible mitigation strategies.
翻译:消费物联网设备常通过本地网络与配套应用程序或其他设备通信。这种设计通过减轻云端负载提升了效率。ENISA和NIST安全指南强调了启用默认本地通信对安全性与可靠性的重要性——物联网设备应在无法连接云端时仍能正常运行。尽管云-设备连接的安全性通常通过标准协议进行强化,但本地连接的安全性却常被忽视。忽视本地通信安全会为包括重放攻击在内的多种威胁敞开大门。本文通过设计一套系统化方法来自动检测物联网设备的重放攻击漏洞,系统性地研究了此类攻击。具体而言,我们提出名为REPLIOT的工具,可在无需预先了解目标设备的情况下测试重放攻击是否成功。我们使用涵盖多个厂商和品类的热门商用设备开展了数千次自动化实验。值得注意的是,研究发现其中51%的设备不支持本地连接,因此不符合ENISA/NIST指南对可靠性与安全性的要求。在剩余设备中,75%易受重放攻击,而REPLIOT的检测准确率达到0.98-1。最后,我们探索了该漏洞的可能成因,并讨论了潜在的缓解策略。