ThingPot: an interactive Internet-of-Things honeypot

07/11/2018
by   Meng Wang, et al.
0

The Mirai Distributed Denial-of-Service (DDoS) attack exploited security vulnerabilities of Internet-of-Things (IoT) devices and thereby clearly signalled that attackers have IoT on their radar. Securing IoT is therefore imperative, but in order to do so it is crucial to understand the strategies of such attackers. For that purpose, in this paper, a novel IoT honeypot called ThingPot is proposed and deployed. Honeypot technology mimics devices that might be exploited by attackers and logs their behavior to detect and analyze the used attack vectors. ThingPot is the first of its kind, since it focuses not only on the IoT application protocols themselves, but on the whole IoT platform. A Proof-of-Concept is implemented with XMPP and a REST API, to mimic a Philips Hue smart lighting system. ThingPot has been deployed for 1.5 months and through the captured data we have found five types of attacks and attack vectors against smart devices. The ThingPot source code is made available as open source.

READ FULL TEXT
research
03/22/2023

AIIPot: Adaptive Intelligent-Interaction Honeypot for IoT Devices

The proliferation of the Internet of Things (IoT) has raised concerns ab...
research
12/05/2019

Leveraging Operational Technology and the Internet of Things to Attack Smart Buildings

In recent years, the buildings where we spend most part of our life are ...
research
11/28/2017

A Novel Approach for Security Situational Awareness in the Internet of Things

Internet of Things (IoT) is characterized by various of heterogeneous de...
research
02/24/2019

Expect More from the Networking: DDoS Mitigation by FITT in Named Data Networking

Distributed Denial of Service (DDoS) attacks have plagued the Internet f...
research
12/18/2019

Harzer Roller: Linker-Based Instrumentation for Enhanced Embedded Security Testing

Due to the rise of the Internet of Things, there are many new chips and ...
research
06/29/2020

Towards Learning-automation IoT Attack Detection through Reinforcement Learning

As a massive number of the Internet of Things (IoT) devices are deployed...
research
07/24/2021

BIoTA Control-Aware Attack Analytics for Building Internet of Things

Modern building control systems adopt demand control heating, ventilatio...

Please sign up or login with your details

Forgot password? Click here to reset