首页> 外文会议>Cyber Security in Networking Conference >Bluetooth Low Energy Makes “Just Works” Not Work
【24h】

Bluetooth Low Energy Makes “Just Works” Not Work

机译:低功耗蓝牙使“ Just Works”无法正常工作

获取原文

摘要

BLE (Bluetooth Low Energy) is being heavily deployed in many devices and IoT (Internet of Things) smart applications of various fields, such as medical, home automation, transportation and agriculture. It has transformed the classic Bluetooth into a technology that can be embedded into resource constrained devices running on a cell coin battery for months or years. Most BLE devices that are sold in the market use the Just Works pairing mode to establish a connection with peer devices. This mode is so lightweight that it leaves the implementation of security to application developers and device manufacturers. Unfortunately, as the market does not want to pay for security, a number of vulnerable smart devices are strolling around in the market. In this paper, we discuss how Bluetooth devices that use the Just Works pairing mode can be exploited to become nonoperational. We conduct a case study on three different Bluetooth smart devices. We show how these devices can be attacked and abused to not work properly. We also present a vulnerability that is due to the behavior of BLE smart devices and the Just Works pairing mode. This vulnerability can be exploited to generate an attack that affects BLE availability. We propose a solution to mitigate the attack.
机译:BLE(蓝牙低能耗)已广泛部署在医疗,家庭自动化,运输和农业等各个领域的许多设备和IoT(物联网)智能应用中。它已将经典的蓝牙技术转变为一种技术,该技术可以嵌入到使用单元硬币电池运行数月或数年的资源受限的设备中。市场上出售的大多数BLE设备都使用Just Works配对模式来建立与对等设备的连接。此模式非常轻巧,以至于将安全性实施留给了应用程序开发人员和设备制造商。不幸的是,由于市场不想为安全买单,因此许多易受攻击的智能设备在市场上走来走去。在本文中,我们讨论了如何利用使用Just Works配对模式的蓝牙设备使其无法使用。我们对三种不同的蓝牙智能设备进行了案例研究。我们展示了如何攻击和滥用这些设备以使其无法正常工作。我们还提出了一个漏洞,该漏洞是由于BLE智能设备的行为和Just Works配对模式引起的。可以利用此漏洞来生成影响BLE可用性的攻击。我们提出了一种缓解攻击的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号