Matches in SemOpenAlex for { <https://semopenalex.org/work/W2686848947> ?p ?o ?g. }
Showing items 1 to 72 of
72
with 100 items per page.
- W2686848947 abstract "Within the next few years, billions of IoT devices will densely populate our cities. In this paper we describe a new type of threat in which adjacent IoT devices will infect each other with a worm that will rapidly spread over large areas, provided that the density of compatible IoT devices exceeds a certain critical mass. In particular, we developed and verified such an infection using the popular Philips Hue smart lamps as a platform. The worm spreads by jumping directly from one lamp to its neighbors, using only their built-in ZigBee wireless connectivity and their physical proximity. The attack can start by plugging in a single infected bulb anywhere in the city, and then catastrophically spread everywhere within minutes. It enables the attacker to turn all the city lights on or off, to permanently brick them, or to exploit them in a massive DDOS attack. To demonstrate the risks involved, we use results from percolation theory to estimate the critical mass of installed devices for a typical city such as Paris whose area is about 105 square kilometers: The chain reaction will fizzle if there are fewer than about 15,000 randomly located smart lamps in the whole city, but will spread everywhere when the number exceeds this critical mass (which had almost certainly been surpassed already). To make such an attack possible, we had to find a way to remotely yank already installed lamps from their current networks, and to perform over-the-air firmware updates. We overcame the first problem by discovering and exploiting a major bug in the implementation of the Touchlink part of the ZigBee Light Link protocol, which is supposed to stop such attempts with a proximity test. To solve the second problem, we developed a new version of a side channel attack to extract the global AES-CCM key (for each device type) that Philips uses to encrypt and authenticate new firmware. We used only readily available equipment costing a few hundred dollars, and managed to find this key without seeing any actual updates. This demonstrates once again how difficult it is to get security right even for a large company that uses standard cryptographic techniques to protect a major product." @default.
- W2686848947 created "2017-06-30" @default.
- W2686848947 creator A5000713291 @default.
- W2686848947 creator A5009126679 @default.
- W2686848947 creator A5079779835 @default.
- W2686848947 creator A5086540426 @default.
- W2686848947 date "2017-05-01" @default.
- W2686848947 modified "2023-10-18" @default.
- W2686848947 title "IoT Goes Nuclear: Creating a ZigBee Chain Reaction" @default.
- W2686848947 cites W1527529076 @default.
- W2686848947 cites W2040582337 @default.
- W2686848947 cites W2070432943 @default.
- W2686848947 cites W2095240753 @default.
- W2686848947 cites W2123097583 @default.
- W2686848947 cites W2135698166 @default.
- W2686848947 cites W2154909745 @default.
- W2686848947 cites W2354520588 @default.
- W2686848947 cites W29626722 @default.
- W2686848947 doi "https://doi.org/10.1109/sp.2017.14" @default.
- W2686848947 hasPublicationYear "2017" @default.
- W2686848947 type Work @default.
- W2686848947 sameAs 2686848947 @default.
- W2686848947 citedByCount "299" @default.
- W2686848947 countsByYear W26868489472017 @default.
- W2686848947 countsByYear W26868489472018 @default.
- W2686848947 countsByYear W26868489472019 @default.
- W2686848947 countsByYear W26868489472020 @default.
- W2686848947 countsByYear W26868489472021 @default.
- W2686848947 countsByYear W26868489472022 @default.
- W2686848947 countsByYear W26868489472023 @default.
- W2686848947 crossrefType "proceedings-article" @default.
- W2686848947 hasAuthorship W2686848947A5000713291 @default.
- W2686848947 hasAuthorship W2686848947A5009126679 @default.
- W2686848947 hasAuthorship W2686848947A5079779835 @default.
- W2686848947 hasAuthorship W2686848947A5086540426 @default.
- W2686848947 hasConcept C165696696 @default.
- W2686848947 hasConcept C29852176 @default.
- W2686848947 hasConcept C31258907 @default.
- W2686848947 hasConcept C38652104 @default.
- W2686848947 hasConcept C41008148 @default.
- W2686848947 hasConcept C555944384 @default.
- W2686848947 hasConcept C67212190 @default.
- W2686848947 hasConcept C76155785 @default.
- W2686848947 hasConcept C81860439 @default.
- W2686848947 hasConcept C9390403 @default.
- W2686848947 hasConceptScore W2686848947C165696696 @default.
- W2686848947 hasConceptScore W2686848947C29852176 @default.
- W2686848947 hasConceptScore W2686848947C31258907 @default.
- W2686848947 hasConceptScore W2686848947C38652104 @default.
- W2686848947 hasConceptScore W2686848947C41008148 @default.
- W2686848947 hasConceptScore W2686848947C555944384 @default.
- W2686848947 hasConceptScore W2686848947C67212190 @default.
- W2686848947 hasConceptScore W2686848947C76155785 @default.
- W2686848947 hasConceptScore W2686848947C81860439 @default.
- W2686848947 hasConceptScore W2686848947C9390403 @default.
- W2686848947 hasLocation W26868489471 @default.
- W2686848947 hasOpenAccess W2686848947 @default.
- W2686848947 hasPrimaryLocation W26868489471 @default.
- W2686848947 hasRelatedWork W1657049324 @default.
- W2686848947 hasRelatedWork W1864298798 @default.
- W2686848947 hasRelatedWork W2766830182 @default.
- W2686848947 hasRelatedWork W2768437505 @default.
- W2686848947 hasRelatedWork W2779961139 @default.
- W2686848947 hasRelatedWork W3080383462 @default.
- W2686848947 hasRelatedWork W3165483060 @default.
- W2686848947 hasRelatedWork W3188635106 @default.
- W2686848947 hasRelatedWork W3204768908 @default.
- W2686848947 hasRelatedWork W4207085300 @default.
- W2686848947 isParatext "false" @default.
- W2686848947 isRetracted "false" @default.
- W2686848947 magId "2686848947" @default.
- W2686848947 workType "article" @default.