2020 · 19 citations · 10 references
EngineeringInformation SecuritySecurity IssuesSoftware AnalysisVulnerability Assessment (Computing)Trusted Execution EnvironmentInternet Of ThingsFuzzingTestbedVirtualization SecurityComputer EngineeringComputer ScienceSecurity Testing MethodData SecurityProgram AnalysisFuzzing TechniqueSoftware TestingCloud ComputingVulnerability DiscoveryDocker Lighter
This paper deals with the security issues of IoT networks and particularly with vulnerabilities of Message Queuing Telemetry Transport (MQTT) protocol. We proposed Fuzzing attack techniques to detect new security breaches in MQTT. Fuzz involves the random data generation and transmission to the input of MQTT brokers or clients in order to identify breaches by analyzing their responses. We focus on the development of a containerized test architecture as well as on the generation of scenarios using the Fuzzing. We chose Docker as a container of applications based on a single virtual machine. Through our empirical tests, we found Docker lighter and better efficient than traditional Virtual Machines. We demonstrated that the implementation of a fuzzing technique on Docker within small-scale is efficient to detect a number of MQTT security flaws.
10
IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao et al. · 2018 · 321 citations · Full text