首页> 外文期刊>IEEE transactions on information forensics and security >A Data Exfiltration and Remote Exploitation Attack on Consumer 3D Printers
【24h】

A Data Exfiltration and Remote Exploitation Attack on Consumer 3D Printers

机译:消费类3D打印机的数据泄露和远程利用攻击

获取原文
获取原文并翻译 | 示例
           

摘要

With the increased popularity of 3D printers in homes, and industry sectors, such as biomedical and manufacturing, the potential for cybersecurity risks must be carefully considered. Risks may arise from factors such as printer manufacturers not having the requisite levels of security awareness, and not fully understanding the need for security measures to protect intellectual property, and other sensitive data that are stored, accessed, and transmitted from such devices. This paper examines the security features of two different models of MakerBot Industries’ consumer-oriented 3D printers and proposes an attack technique that is able to, not only, exfiltrate sensitive data, but also allow for remote manipulation of these devices. The attack steps are discretely modeled using a threat model to enable formal representation of the attack. Specifically, we found that the printers stored the previously printed and currently printing objects on an unauthenticated web server. We also ascertain that the transport layer security implementation on these devices was flawed, which severely affected the security of these devices and allowed for remote exploitation. Countermeasures to the attack that are implementable by both the manufacturer and the user of the printer are presented.
机译:随着3D打印机在家庭和工业部门(例如生物医学和制造业)中的日益普及,必须谨慎考虑潜在的网络安全风险。可能会由于以下因素而产生风险,例如打印机制造商不具备必要的安全意识级别,并且不完全了解保护知识产权的安全措施以及从此类设备存储,访问和传输的其他敏感数据的必要性。本文研究了MakerBot Industries的两种不同型号的面向消费者的3D打印机的安全功能,并提出了一种攻击技术,该技术不仅可以泄露敏感数据,还可以对这些设备进行远程操作。使用威胁模型对攻击步骤进行离散建模,以实现攻击的形式表示。具体来说,我们发现打印机将未经打印的Web服务器上存储了先前打印的和当前正在打印的对象。我们还确定这些设备上的传输层安全性实现存在缺陷,从而严重影响了这些设备的安全性并允许进行远程利用。提出了可以由打印机的制造商和用户实施的攻击对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号