Security Vulnerabilities of Internet of Things : A Case Study of the Smart Plug System

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

175 Scopus Citations
View graph of relations

Author(s)

  • Zhen Ling
  • Junzhou Luo
  • Yiling Xu
  • Chao Gao
  • Xinwen Fu

Detail(s)

Original languageEnglish
Article number7932855
Pages (from-to)1899-1909
Journal / PublicationIEEE Internet of Things Journal
Volume4
Issue number6
Publication statusPublished - 1 Dec 2017
Externally publishedYes

Abstract

With the rapid development of the Internet of Things, more and more small devices are connected into the Internet for monitoring and control purposes. One such type of devices, smart plugs, have been extensively deployed worldwide in millions of homes for home automation. These smart plugs, however, would pose serious security problems if their vulnerabilities were not carefully investigated. Indeed, we discovered that some popular smart home plugs have severe security vulnerabilities which could be fixed but unfortunately are left open. In this paper, we case study a smart plug system of a known brand by exploiting its communication protocols and successfully launching four attacks: 1) device scanning attack; 2) brute force attack; 3) spoofing attack; and 4) firmware attack. Our real-world experimental results show that we can obtain the authentication credentials from the users by performing these attacks. We also present guidelines for securing smart plugs. © 2017 IEEE.

Research Area(s)

  • Attacks, countermeasures, Internet of Things (IoT), vulnerabilities

Bibliographic Note

Publication details (e.g. title, author(s), publication statuses and dates) are captured on an “AS IS” and “AS AVAILABLE” basis at the time of record harvesting from the data source. Suggestions for further amendments or supplementary information can be sent to [email protected].

Citation Format(s)

Security Vulnerabilities of Internet of Things: A Case Study of the Smart Plug System. / Ling, Zhen; Luo, Junzhou; Xu, Yiling et al.
In: IEEE Internet of Things Journal, Vol. 4, No. 6, 7932855, 01.12.2017, p. 1899-1909.

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review