首页> 外文会议>International Conference on Advances in Computing, Communications and Informatics >Analysis of vulnerabilities in MQTT security using Shodan API and implementation of its countermeasures via authentication and ACLs
【24h】

Analysis of vulnerabilities in MQTT security using Shodan API and implementation of its countermeasures via authentication and ACLs

机译:使用Shodan API的MQTT安全漏洞分析以及通过身份验证和ACL实施对策

获取原文

摘要

Among the technologies evolved in the recent years, a remarkable one is the IoT (Internet of Things), wherein the `thing' in IoT could be smart phones, tablets, PCs and almost anything with a sensor on it like cars, people, machines in production plants, jet engines, oil drills, wearable devices and many more objects. A standardized, light-weight, session layer protocol with publish/subscribe architecture widely used for messaging and information exchange among IoT devices is the MQTT (MQ Telemetry Transport) protocol. In this paper, we identify various security loopholes in MQTT, using Shodan API and implementing an experimental setup on a Raspberry Pi as an MQTT Broker and python programs as publisher/subscriber clients. The experimental results with respect to the security issues in this protocol at packet and topic levels were studied and the corresponding security measures, consisting of authentication and authorization techniques (ACLs) were implemented. As a result, the Broker was then found to be immune to such attacks. This paper is a concise study of security inconsistencies in MQTT and its countermeasures.
机译:近年来发展起来的技术中,杰出的是IoT(物联网),其中IoT的“物”可以是智能手机,平板电脑,PC以及几乎任何带有传感器的东西,例如汽车,人,机器在生产工厂,喷气发动机,石油钻机,可穿戴设备以及更多物体中。 MQTT(MQ遥测传输)协议是一种具有发布/订阅体系结构的标准化,轻量级会话层协议,广泛用于IoT设备之间的消息传递和信息交换。在本文中,我们使用Shodan API并在Raspberry Pi上作为MQTT Broker并在python程序作为发布者/订阅者客户端上实现了实验性设置,从而确定了MQTT中的各种安全漏洞。研究了该协议在数据包和主题级别的安全性问题的实验结果,并实施了包括身份验证和授权技术(ACL)在内的相应安全性措施。结果,随后发现该经纪人不受此类攻击。本文是对MQTT中的安全性矛盾及其对策的简要研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号