Next Article in Journal
Popularity Prediction of Instagram Posts
Next Article in Special Issue
Botnet Defense System: Concept, Design, and Basic Strategy
Previous Article in Journal
Decision-Making for Project Delivery System with Related-Indicators Based on Pythagorean Fuzzy Weighted Muirhead Mean Operator
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

SlowTT: A Slow Denial of Service against IoT Networks

1
Consiglio Nazionale delle Ricerche (CNR), IEIIT Institute, 16149 Genoa, Italy
2
Department of Informatics, Bioengineering, Robotics and System Engineering (DIBRIS), University of Genoa, 16145 Genoa, Italy
*
Author to whom correspondence should be addressed.
Information 2020, 11(9), 452; https://doi.org/10.3390/info11090452
Submission received: 18 August 2020 / Revised: 11 September 2020 / Accepted: 15 September 2020 / Published: 18 September 2020
(This article belongs to the Special Issue Security and Privacy in the Internet of Things)

Abstract

The security of Internet of Things environments is a critical and trending topic, due to the nature of the networks and the sensitivity of the exchanged information. In this paper, we investigate the security of the Message Queue Telemetry Transport (MQTT) protocol, widely adopted in IoT infrastructures. We exploit two specific weaknesses of MQTT, identified during our research activities, allowing the client to configure the KeepAlive parameter and MQTT packets to execute an innovative cyber threat against the MQTT broker. In order to validate the exploitation of such vulnerabilities, we propose SlowTT, a novel “Slow” denial of service attack aimed at targeting MQTT through low-rate techniques, characterized by minimum attack bandwidth and computational power requirements. We validate SlowTT against real MQTT services, by considering both plaintext and encrypted communications and by comparing the effects of the attack when targeting different application daemons and protocol versions. Results show that SlowTT is extremely successful, and it can exploit the identified vulnerability to execute a denial of service against the IoT network by keeping the connection alive for a long time.
Keywords: Internet of Things; protocols security; cyber security; network security; slow DoS attack; MQTT Internet of Things; protocols security; cyber security; network security; slow DoS attack; MQTT

Share and Cite

MDPI and ACS Style

Vaccari, I.; Aiello, M.; Cambiaso, E. SlowTT: A Slow Denial of Service against IoT Networks. Information 2020, 11, 452. https://doi.org/10.3390/info11090452

AMA Style

Vaccari I, Aiello M, Cambiaso E. SlowTT: A Slow Denial of Service against IoT Networks. Information. 2020; 11(9):452. https://doi.org/10.3390/info11090452

Chicago/Turabian Style

Vaccari, Ivan, Maurizio Aiello, and Enrico Cambiaso. 2020. "SlowTT: A Slow Denial of Service against IoT Networks" Information 11, no. 9: 452. https://doi.org/10.3390/info11090452

APA Style

Vaccari, I., Aiello, M., & Cambiaso, E. (2020). SlowTT: A Slow Denial of Service against IoT Networks. Information, 11(9), 452. https://doi.org/10.3390/info11090452

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop