论文标题
基于UPNP的物联网安全的概述:威胁,漏洞和潜在的解决方案
An Overview of UPnP-based IoT Security: Threats, Vulnerabilities, and Prospective Solutions
论文作者
论文摘要
从小型传感器到复杂的云基础架构以及各种网络技术和通信协议的开发和增加的智能设备的可用性,都支持了事物部署的迅速扩展。通用插头(UPNP)协议已被广泛接受并在IoT域中使用,以支持异质IoT设备之间的交互作用,部分原因是零配置实现,这使得它可用于大规模网络。 UPNP支持物联网系统的流行和普遍性需要探索与使用协议进行物联网部署相关的安全风险。在这项工作中,我们分析了基于UPNP的物联网系统的安全漏洞,并通过利用脆弱性的对手来确定攻击机会。最后,我们提出了潜在的解决方案,以从对抗操作中获得基于UPNP的物联网系统。
Advances in the development and increased availability of smart devices ranging from small sensors to complex cloud infrastructures as well as various networking technologies and communication protocols have supported the rapid expansion of Internet of Things deployments. The Universal Plug and Play (UPnP) protocol has been widely accepted and used in the IoT domain to support interactions among heterogeneous IoT devices, in part due to zero configuration implementation which makes it feasible for use in large-scale networks. The popularity and ubiquity of UPnP to support IoT systems necessitate an exploration of security risks associated with the use of the protocol for IoT deployments. In this work, we analyze security vulnerabilities of UPnP-based IoT systems and identify attack opportunities by the adversaries leveraging the vulnerabilities. Finally, we propose prospective solutions to secure UPnP-based IoT systems from adversarial operations.