IoT devices are ubiquitous today. Many of these devices use RF based communication techniques to connect to other devices or to receive commands from remote controls in near field. Many devices like smart tube lights have dual mode operation, in which they connect over the internet for interfacing with a mobile app or via RF with a local remote. RF based communication interface introduces an all new attack surface on IoT devices.
Software Defined Radios (SDR) are a versatile piece of hardware that can change reception and transmission profiles based on software configuration. SDRs are available in half-duplex (only reception or transmission at a time) or full-duplex mode (reception and transmission simultaneously). Affordable SDRs like HackRF have given rise to the recent SDR revolution among radio enthusiasts. These SDRs can be used to analyze the signal transmitted between IoT devices and transmit rogue messages. In this article we discuss some of the common attacks that work by exploiting the signal transmission and how some new devices are mitigating those attacks.
Replay Attacks
The most common type of attacks are based on capturing a command sequence and retransmitting it later. This is fairly easy to do using an SDR. The first step is to find out the central frequency of transmission. After the central frequency is obtained, the attacker can listen on that frequency for new data whenever a command is sent by one device to another. Once the data is captured, the attacker can use open source software like Universal Radio Hacker (URH) to isolate a single command sequence. For executing the actual exploit, the attacker is required to transmit the isolated command sequence on the same frequency in the vicinity of the IoT device, which in turn replays the command on that device. URH and a few other softwares for SDR have the ability to replay captured signals without much manual intervention as well.
Cryptanalysis Attacks
This type of attack is much more sophisticated and can be used to exploit any identical device. The first step in this attack is the same – capturing a sample command signal. Once that signal is obtained, it is analyzed in URH. The noise threshold of the environment is subtracted from the signal to obtain the original signal. After that the signal is demodulated, but that requires the knowledge of the modulation scheme used in the communication system. After this step, the protocol is reverse-engineered and the actual command sequence is obtained. This can then be used to craft the messages directly and send it over to other devices of the same type. Replay attacks always do not work across multiple devices because the communication protocol often uses device identification numbers. Cryptanalysis attacks require in-depth knowledge of cryptography and communication theory, which are not required in replay attacks.
Wearable devices have been gaining prominence for both individuals who use it to monitor their health, and for insurance companies that use it to gauge what incentives they should provide. Wearable devices often use Bluetooth for near field communication. Until now these devices have been highly vulnerable (devices that use versions older than Bluetooth 4.2 still are) to both replay and cryptanalysis attacks. If a rogue SDR is installed in a public setting like a gym, these devices can be manipulated to show false health reports and harm both the users and the businesses depending on it.
Reconnaissance Attacks
This type of attack is complementary to the cryptanalysis attack. It is not feasible to guess the type of modulation scheme used or the protocol used in the captured communication sample. This information can often be obtained from the device spec sheet. All devices that make use of RF bandwidth are required to be certified by the authorities in that country (like the FCC for the USA), and they publish analysis reports about all such devices publicly. Manufacturers often try to thwart this type of analysis by the attacker by removing any identification markings from the chips. The attackers then analyze the chips using a multimeter and mark out various pins like the ground pins, which are then compared to the public schematic of other similar chips to determine the product ID.
Some steps taken by modern IoT devices to escape these attacks are described below:
Encrypt The Signals
This is the most important precaution. All systems should be engineered assuming that they will operate in a hostile environment. While the modulation scheme can be figured out by recon attacks, reverse-engineering the protocol is a much more difficult problem.
Use Rolling Commands
Using the same command every time exposes to the device to replay attacks. Modern IoT devices use commands that work on a rolling window basis, so a command once used cannot be used again. Each command is specific to a particular device too. Vulnerable implementations of this scheme use a small keyspace that can be brute-forced by an attacker with some patience.
Use Preamble and Synchronization Nibbles
Protocols that do not use preamble and synchronization nibbles for separating the commands are vulnerable to brute-force attacks using De Bruijn sequence reduction, which reduces the number of bits required to be replayed to transmit multiple command sequences by overlapping the common bits as per the algorithm.
IoT security is a game of cat and mouse. Both sides of the war are always finding ways to outsmart the other. Now that vehicles and industrial machines are also being equipped with IoT, the security aspect has never been more important. Attackers have already demonstrated hacking multiple IoT devices using affordable SDRs. Awareness among manufacturers is increasing but a lot more work still needs to be done in this area.