S0-No-More: A Z-Wave NonceGet Denial of Service Attack utilizing included but offline NodeIDs

05/02/2022
by   Du Cheng, et al.
0

In this paper a vulnerability in the Z-Wave protocol specification, especially in the S0 Z-Wave protocol is presented. Devices supporting this standard can be blocked (denial of service) through continuous S0 NonceGet requests. This way a whole network can be blocked if the attacked devices are Z-Wave network controller. This also effects S2 network controller as long as they support S0 NonceGet requests. As only a minimal amount of nonce requests (1 per  2 seconds) is required to conduct the attack it cannot be prevented by standard countermeasures against jamming.

READ FULL TEXT

page 4

page 8

page 10

page 11

page 12

page 14

page 15

page 16

research
01/23/2020

Crushing the Wave – new Z-Wave vulnerabilities exposed

This paper describes two denial of service attacks against the Z-Wave pr...
research
07/27/2021

Poisoning of Online Learning Filters: DDoS Attacks and Countermeasures

The recent advancements in machine learning have led to a wave of intere...
research
04/06/2019

Quantum Key Distribution System Immune to Polarization-Induced Signal Fading with Quarter-Wave Plate Reflector-Michelson Interferometers

Improvement of QKD performance, particularly on system stability, has be...
research
03/22/2019

Joint Switch Upgrade and Controller Deployment in Hybrid Software-Defined Networks

To improve traffic management ability, Internet Service Providers (ISPs)...
research
10/04/2022

Optimizing Vehicle-to-Edge Mapping with Load Balancing for Attack-Resilience in IoV

Attack-resilience is essential to maintain continuous service availabili...
research
03/06/2020

Me Love (SYN-)Cookies: SYN Flood Mitigation in Programmable Data Planes

The SYN flood attack is a common attack strategy on the Internet, which ...
research
07/28/2020

Cognitive Honeypots against Lateral Movement for Mitigation of Long-Term Vulnerability

Lateral movement of advanced persistent threats (APTs) has posed a sever...

Please sign up or login with your details

Forgot password? Click here to reset