Resetting Your Password Is Vulnerable: A Security Study of Common SMS-Based Authentication in IoT Device

المؤلفون المشاركون

Niu, Weina
Zhang, Xiaosong
Wang, Dong
Chen, Ting
Ming, Jiang
Wang, Chao

المصدر

Wireless Communications and Mobile Computing

العدد

المجلد 2018، العدد 2018 (31 ديسمبر/كانون الأول 2018)، ص ص. 1-15، 15ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2018-07-04

دولة النشر

مصر

عدد الصفحات

15

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Firmware vulnerability is an important target for IoT attacks, but it is challenging, because firmware may be publicly unavailable or encrypted with an unknown key.

We present in this paper an attack on Short Message Service (SMS for short) authentication code which aims at gaining the control of IoT devices without firmware analysis.

The key idea is based on the observation that IoT device usually has an official application (app for short) used to control itself.

Customer needs to register an account before using this app, phone numbers are usually suggested to be the account name, and most of these apps have a common feature, called Reset Your Password, that uses an SMS authentication code sent to customer phone to authenticate the customer when he forgot his password.

We found that an attacker can perform brute-force attack on this SMS authentication code automatically by overcoming several challenges, then he can steal the account to gain the control of IoT devices.

In our research, we have implemented a prototype tool, called SACIntruder, to enable performing such brute-force attack test on IoT devices automatically.

We evaluated it and successfully found 12 zero-day vulnerabilities including smart lock, sharing car, smart watch, smart router, etc.

We also discussed how to prevent this attack.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Wang, Dong& Zhang, Xiaosong& Ming, Jiang& Chen, Ting& Wang, Chao& Niu, Weina. 2018. Resetting Your Password Is Vulnerable: A Security Study of Common SMS-Based Authentication in IoT Device. Wireless Communications and Mobile Computing،Vol. 2018, no. 2018, pp.1-15.
https://search.emarefa.net/detail/BIM-1216260

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Wang, Dong…[et al.]. Resetting Your Password Is Vulnerable: A Security Study of Common SMS-Based Authentication in IoT Device. Wireless Communications and Mobile Computing No. 2018 (2018), pp.1-15.
https://search.emarefa.net/detail/BIM-1216260

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Wang, Dong& Zhang, Xiaosong& Ming, Jiang& Chen, Ting& Wang, Chao& Niu, Weina. Resetting Your Password Is Vulnerable: A Security Study of Common SMS-Based Authentication in IoT Device. Wireless Communications and Mobile Computing. 2018. Vol. 2018, no. 2018, pp.1-15.
https://search.emarefa.net/detail/BIM-1216260

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1216260