IoT-Scan: Network Reconnaissance for the Internet of Things

04/06/2022
by   Stefan Gvozdenovic, et al.
0

Network reconnaissance is a core networking and security procedure aimed at discovering devices and their properties. For IP-based networks, several network reconnaissance tools are available, such as Nmap. For the Internet of Things (IoT), there is currently no similar tool capable of discovering devices across multiple protocols. In this paper, we present IoT-Scan, a universal IoT network reconnaissance tool. IoT-Scan is based on software defined radio (SDR) technology, which allows for a flexible software-based implementation of radio protocols. We present a series of passive, active, multi-channel, and multi-protocol scanning algorithms to speed up the discovery of devices with IoT-Scan. We benchmark the passive scanning algorithms against a theoretical traffic model based on the non-uniform coupon collector problem. We implement the scanning algorithms and compare their performance for four popular IoT protocols: Zigbee, Bluetooth LE, Z-Wave, and LoRa. Through extensive experiments with dozens of IoT devices, we demonstrate that our implementation experiences minimal packet losses and achieves performance near the theoretical benchmark. Using multi-protocol scanning, we further demonstrate a reduction of 70% in the discovery times of Bluetooth and Zigbee devices in the 2.4 GHz band and of LoRa and Z-Wave devices in the 900 MHz band, compared to sequential passive scanning. We make our implementation and data available to the research community to allow independent replication of our results and facilitate further development of the tool.

READ FULL TEXT
research
10/19/2020

A Feasibility Study on SNTP and SPoT Protocols on Time Synchronization in Internet of Things

The new wave of computing allows users to explore their time in the Inte...
research
06/28/2021

Automatically Determining a Network Reconnaissance Scope Using Passive Scanning Techniques

The starting point of securing a network is having a concise overview of...
research
04/06/2021

RFQuack: A Universal Hardware-Software Toolkit for Wireless Protocol (Security) Analysis and Research

Software-defined radios (SDRs) are indispensable for signal reconnaissan...
research
09/20/2022

Deep Dive into the IoT Backend Ecosystem

Internet of Things (IoT) devices are becoming increasingly ubiquitous, e...
research
04/08/2019

Efficient Passive ICS Device Discovery and Identification by MAC Address Correlation

Owing to a growing number of attacks, the assessment of Industrial Contr...
research
09/22/2017

Correctness of the Chord Protocol

Internet of Things (IoT) can be seen as a cooperation of the various het...
research
05/21/2020

Authenticating On-Body IoT Devices: An Adversarial Learning Approach

By adding users as a new dimension to connectivity, on-body Internet-of-...

Please sign up or login with your details

Forgot password? Click here to reset