...
首页> 外文期刊>Wireless communications & mobile computing >MQTT Security: A Novel Fuzzing Approach
【24h】

MQTT Security: A Novel Fuzzing Approach

机译:MQTT安全性:一种新颖的模糊处理方法

获取原文
           

摘要

The Internet of Things is a concept that is increasingly present in our lives. The emergence of intelligent devices has led to a paradigm shift in the way technology interacts with the environment, leading society to a smarter planet. Consequently, new advanced telemetry approaches appear to connect all kinds of devices with each other, with companies, or with other networks, such as the Internet. On the road to an increasingly interconnected world, where critical devices rely on communication networks to provide an essential service, there arises the need to ensure the security and reliability of these protocols and applications. In this paper, we discuss a security-based approach for MQTT (Message Queue Telemetry Transport), which stands out as a very lightweight and widely used messaging and information exchange protocol for IoT (Internet of Things) devices throughout the world. To that end, we propose the creation of a framework that allows for performing a novel, template-based fuzzing technique on the MQTT protocol. The first experimental results showed that performance of the fuzzing technique presented here makes it a good candidate for use in network architectures with low processing power sensors, such as Smart Cities. In addition, the use of this fuzzer in widely used applications that implement MQTT has led to the discovery of several new security flaws not hitherto reported, demonstrating its usefulness as a tool for finding security vulnerabilities.
机译:物联网是我们生活中越来越多的概念。智能设备的出现导致技术与环境互动的方式发生了范式转变,从而将社会带入了一个更智能的星球。因此,新的先进遥测方法似乎可以将各种设备彼此,与公司或与其他网络(例如Internet)连接。在通向日益互连的世界的道路上,关键设备依赖于通信网络来提供基本服务,因此需要确保这些协议和应用程序的安全性和可靠性。在本文中,我们讨论了MQTT(消息队列遥测传输)的基于安全性的方法,该方法作为一种轻量级且广泛用于IoT(物联网)设备的消息传递和信息交换协议而脱颖而出。为此,我们建议创建一个框架,该框架允许对MQTT协议执行新颖的,基于模板的模糊测试技术。最初的实验结果表明,此处介绍的模糊技术的性能使其成为具有低处理能力传感器的网络体系结构(如智能城市)中的良好候选者。此外,在实现MQTT的广泛使用的应用程序中使用此模糊器已经导致发现了一些迄今未报告的新安全漏洞,证明了其作为查找安全漏洞工具的有用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号