TY - GEN
T1 - Penetration testing IoT devices to discover critical vulnerabilities
AU - Chakraborty, Abhigyan
AU - Akshay, K. C.
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024
Y1 - 2024
N2 - The proliferation of Internet of Things (IoT) devices has introduced numerous benefits across various domains but also raises significant security concerns. This paper presents a penetration testing study on a Wi-Fi smart bulb to identify critical vulnerabilities. The testing revealed severe susceptibilities to Denial of Service (DoS) attacks, including ICMP flooding, TCP SYN flooding, and UDP flooding, which disrupted the device's functionality. Additionally, a man-in-the-middle attack using ARP spoofing exposed weak encryption practices, specifically the use of TLSv1.2 with a pre-shared key cipher suite lacking Perfect Forward Secrecy (PFS). These findings highlight the urgent need for improved security protocols in IoT devices to ensure their safe and reliable operation.
AB - The proliferation of Internet of Things (IoT) devices has introduced numerous benefits across various domains but also raises significant security concerns. This paper presents a penetration testing study on a Wi-Fi smart bulb to identify critical vulnerabilities. The testing revealed severe susceptibilities to Denial of Service (DoS) attacks, including ICMP flooding, TCP SYN flooding, and UDP flooding, which disrupted the device's functionality. Additionally, a man-in-the-middle attack using ARP spoofing exposed weak encryption practices, specifically the use of TLSv1.2 with a pre-shared key cipher suite lacking Perfect Forward Secrecy (PFS). These findings highlight the urgent need for improved security protocols in IoT devices to ensure their safe and reliable operation.
UR - https://www.scopus.com/pages/publications/85216772314
UR - https://www.scopus.com/inward/citedby.url?scp=85216772314&partnerID=8YFLogxK
U2 - 10.1109/ICRAIS62903.2024.10811719
DO - 10.1109/ICRAIS62903.2024.10811719
M3 - Conference contribution
AN - SCOPUS:85216772314
T3 - 2nd IEEE International Conference on Recent Advances in Information Technology for Sustainable Development, ICRAIS 2024 - Proceedings
SP - 54
EP - 59
BT - 2nd IEEE International Conference on Recent Advances in Information Technology for Sustainable Development, ICRAIS 2024 - Proceedings
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2nd IEEE International Conference on Recent Advances in Information Technology for Sustainable Development, ICRAIS 2024
Y2 - 6 November 2024 through 7 November 2024
ER -