Penetration testing IoT devices to discover critical vulnerabilities

Abhigyan Chakraborty, K. C. Akshay

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    Abstract

    The proliferation of Internet of Things (IoT) devices has introduced numerous benefits across various domains but also raises significant security concerns. This paper presents a penetration testing study on a Wi-Fi smart bulb to identify critical vulnerabilities. The testing revealed severe susceptibilities to Denial of Service (DoS) attacks, including ICMP flooding, TCP SYN flooding, and UDP flooding, which disrupted the device's functionality. Additionally, a man-in-the-middle attack using ARP spoofing exposed weak encryption practices, specifically the use of TLSv1.2 with a pre-shared key cipher suite lacking Perfect Forward Secrecy (PFS). These findings highlight the urgent need for improved security protocols in IoT devices to ensure their safe and reliable operation.

    Original languageEnglish
    Title of host publication2nd IEEE International Conference on Recent Advances in Information Technology for Sustainable Development, ICRAIS 2024 - Proceedings
    PublisherInstitute of Electrical and Electronics Engineers Inc.
    Pages54-59
    Number of pages6
    ISBN (Electronic)9798350354461
    DOIs
    Publication statusPublished - 2024
    Event2nd IEEE International Conference on Recent Advances in Information Technology for Sustainable Development, ICRAIS 2024 - Manipal, India
    Duration: 06-11-202407-11-2024

    Publication series

    Name2nd IEEE International Conference on Recent Advances in Information Technology for Sustainable Development, ICRAIS 2024 - Proceedings

    Conference

    Conference2nd IEEE International Conference on Recent Advances in Information Technology for Sustainable Development, ICRAIS 2024
    Country/TerritoryIndia
    CityManipal
    Period06-11-2407-11-24

    All Science Journal Classification (ASJC) codes

    • Computer Vision and Pattern Recognition
    • Information Systems
    • Signal Processing
    • Information Systems and Management
    • Renewable Energy, Sustainability and the Environment
    • Media Technology
    • Health Informatics

    Fingerprint

    Dive into the research topics of 'Penetration testing IoT devices to discover critical vulnerabilities'. Together they form a unique fingerprint.

    Cite this