Bluetooth Low Energy (BLE) has become the primary transmission media due to its extremely low energy consumption, good network scope, and data transfer speed for the Internet of Things (IoT) and smart wearable devices. With the exponential boom of the Internet of Things (IoT) and the Bluetooth Low Energy (BLE) connection protocol, a requirement to discover defensive techniques to protect it with practical security analysis. Unfortunately, IoT-BLE is at risk of spoofing assaults where an attacker can pose as a gadget and provide its users a harmful information. Furthermore, due to the simplified strategy of this protocol, there were many security and privacy vulnerabilities. Justifying this quantitative security analysis with STRIDE Methodology change to create a framework to deal with protection issues for the IoT-BLE sensors. Therefore, providing probable attack scenarios for various exposures in this analysis, and offer mitigating strategies. In light of this authors performed STRIDE threat modeling to understand the attack surface for smart wearable devices supporting BLE. The study evaluates different exploitation scenarios Denial of Service (DoS), Elevation of privilege, Information disclosure, spoofing, Tampering, and repudiation on MI Band, One plus Band, Boat Storm smartwatch, and Fire Bolt Invincible.
翻译:蓝牙低功耗(BLE)凭借其极低的能耗、良好的网络覆盖范围和数传速率,已成为物联网(IoT)及智能可穿戴设备的主要传输媒介。随着物联网和BLE连接协议的指数级增长,需要探索防御技术并结合实际安全分析进行保护。遗憾的是,IoT-BLE面临欺骗攻击的风险——攻击者可伪装成设备并向用户传播有害信息。此外,由于该协议的简化设计策略,存在诸多安全与隐私漏洞。本研究通过采用STRIDE方法论进行定量安全分析,构建处理IoT-BLE传感器保护问题的框架。据此提出针对各类暴露面的可能攻击场景,并提供缓解策略。基于此,作者对支持BLE的智能可穿戴设备进行STRIDE威胁建模,以理解攻击面。研究评估了MI Band、One Plus Band、Boat Storm智能手表和Fire Bolt Invincible设备上的不同利用场景:拒绝服务(DoS)、权限提升、信息泄露、欺骗、篡改及抵赖。