Security assessment of common open source MQTT brokers and clients

09/07/2023
by   Edoardo Di Paolo, et al.
0

Security and dependability of devices are paramount for the IoT ecosystem. Message Queuing Telemetry Transport protocol (MQTT) is the de facto standard and the most common alternative for those limited devices that cannot leverage HTTP. However, the MQTT protocol was designed with no security concern since initially designed for private networks of the oil and gas industry. Since MQTT is widely used for real applications, it is under the lens of the security community, also considering the widespread attacks targeting IoT devices. Following this direction research, in this paper we present an empirical security evaluation of several widespread implementations of MQTT system components, namely five broker libraries and three client libraries. While the results of our research do not capture very critical flaws, there are several scenarios where some libraries do not fully adhere to the standard and leave some margins that could be maliciously exploited and potentially cause system inconsistencies.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/20/2019

Memory Forensic Analysis of MQTT Devices

Internet of Things is revolutionizing the current era with its vast usag...
research
07/18/2022

Performance Evaluation for Privacy-preserving Control of Domestic IoT Devices

Most of the existing models for deploying IoT ecosystem involves the ven...
research
06/30/2023

A Quic(k) Security Overview: A Literature Research on Implemented Security Recommendations

Built on top of UDP, the relatively new QUIC protocol serves as the base...
research
03/25/2021

The Cost of OSCORE and EDHOC for Constrained Devices

Many modern IoT applications rely on the Constrained Application Protoco...
research
04/13/2021

Practical Pitfalls for Security in OPC UA

In 2006, the OPC Foundation released the first specification for OPC Uni...
research
01/02/2022

Towards a secure API client generator for IoT devices

Given the success of IoT platforms, more developers and companies want t...
research
09/02/2021

TLS Beyond the Broker: Enforcing Fine-grained Security and Trust in Publish/Subscribe Environments for IoT

Message queuing brokers are a fundamental building block of the Internet...

Please sign up or login with your details

Forgot password? Click here to reset