CQUniversity
Browse

Insider attacks on Zigbee based IoT networks by exploiting AT commands

conference contribution
posted on 2020-01-29, 00:00 authored by WA Piracha, M Chowdhury, Biplob RayBiplob Ray, S Rajasegarar, R Doss
This paper has presented three insiders attacks on Zigbee protocol – a protocol used for wireless communication for the Internet of Thing (IoT) devices. The end- user’s communication in IoT networks are sensor oriented as the user objects in IoT networks are embedded with sensors and actuators. Most of the sensors communicate with wireless medium among which many of them use Zigbee protocol. Security is an important element of IoT objects to protect user’s privacy and counter malicious attacks but difficult to guarantee due to its limited capabilities, wireless communication and unpredicted users’ actions. In this paper, we have evaluated Zigbee protocol stack for security vulnerabilities which revealed security weakness of remote AT commands. By using remote AT commands in an IoT network, we have devised three successful insider attacks to make unauthorized change of the destination address of a packet, change of node ID, and the change of PAN ID. These attacks detail will be very useful for IoT researches and practitioners in the security domain to design appropriate countermeasures for Zigbee IoT networks.

Funding

Category 2 - Other Public Sector Grants Category

History

Editor

Shankar Sriram VS; Subramaniyaswamy V; Sasikaladevi N; Zhang L; Batten L; Li G

Volume

1116 CCIS

Start Page

77

End Page

91

Number of Pages

25

Start Date

2019-11-22

Finish Date

2019-11-24

eISSN

1865-0937

ISSN

1865-0929

ISBN-13

9789811508707

Location

Thanjavur, India

Publisher

Springer

Place of Publication

Singapore

Peer Reviewed

  • Yes

Open Access

  • No

External Author Affiliations

Deakin University

Author Research Institute

  • Centre for Intelligent Systems

Era Eligible

  • Yes

Name of Conference

10th Applications and Techniques in Information Security (ATIS 2019)

Usage metrics

    CQUniversity

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC