Matches in SemOpenAlex for { <https://semopenalex.org/work/W2983028905> ?p ?o ?g. }
Showing items 1 to 85 of
85
with 100 items per page.
- W2983028905 abstract "Being an easy-to-deploy and cost-effective low power wireless solution, Bluetooth Low Energy (BLE) has been widely used by Internet-of-Things (IoT) devices. In a typical IoT scenario, an IoT device first needs to be connected with its companion mobile app which serves as a gateway for its Internet access. To establish a connection, a device first broadcasts advertisement packets with UUIDs to nearby smartphone apps. Leveraging these UUIDs, a companion app is able to identify the device, pairs and bonds with it, and allows further data communication. However, we show that there is a fundamental flaw in the current design and implementation of the communication protocols between a BLE device and its companion mobile app, which allows an attacker to precisely fingerprint a BLE device with static UUIDs from the apps. Meanwhile, we also discover that many BLE IoT devices adopt just works pairing, allowing attackers to actively connect with these devices if there is no app-level authentication. Even worse, this vulnerability can also be directly uncovered from mobile apps. Furthermore, we also identify that there is an alarming number of vulnerable app-level authentication apps, which means the devices connected by these apps can be directly controlled by attackers. To raise the public awareness of IoT device fingerprinting and also uncover these vulnerable BLE IoT devices before attackers, we develop an automated mobile app analysis tool BLESCOPE and evaluate it with all of the free BLE IoT apps in Google Play store. Our tool has identified 1,757 vulnerable mobile apps in total. We also performed a field test in a 1.28 square miles region, and identified 5,822 real BLE devices, among them 5,509 (94.6%) are fingerprintable by attackers, and 431 (7.4%) are vulnerable to unauthorized access. We have made responsible disclosures to the corresponding app developers, and also reported the fingerprinting issues to the Bluetooth Special Interest Group." @default.
- W2983028905 created "2019-11-22" @default.
- W2983028905 creator A5008433466 @default.
- W2983028905 creator A5026864098 @default.
- W2983028905 creator A5061642704 @default.
- W2983028905 creator A5070946957 @default.
- W2983028905 date "2019-11-06" @default.
- W2983028905 modified "2023-10-12" @default.
- W2983028905 title "Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps" @default.
- W2983028905 cites W1582456956 @default.
- W2983028905 cites W2027538101 @default.
- W2983028905 cites W2064355504 @default.
- W2983028905 cites W2115062372 @default.
- W2983028905 cites W2274307588 @default.
- W2983028905 cites W2408302068 @default.
- W2983028905 cites W2508433864 @default.
- W2983028905 cites W2540974634 @default.
- W2983028905 cites W2575029217 @default.
- W2983028905 cites W2760047100 @default.
- W2983028905 cites W2766106797 @default.
- W2983028905 cites W2774305472 @default.
- W2983028905 cites W2786031714 @default.
- W2983028905 cites W2791080348 @default.
- W2983028905 cites W2794648377 @default.
- W2983028905 cites W2794718534 @default.
- W2983028905 cites W2913256667 @default.
- W2983028905 cites W2929275958 @default.
- W2983028905 cites W4244726870 @default.
- W2983028905 doi "https://doi.org/10.1145/3319535.3354240" @default.
- W2983028905 hasPublicationYear "2019" @default.
- W2983028905 type Work @default.
- W2983028905 sameAs 2983028905 @default.
- W2983028905 citedByCount "39" @default.
- W2983028905 countsByYear W29830289052020 @default.
- W2983028905 countsByYear W29830289052021 @default.
- W2983028905 countsByYear W29830289052022 @default.
- W2983028905 countsByYear W29830289052023 @default.
- W2983028905 crossrefType "proceedings-article" @default.
- W2983028905 hasAuthorship W2983028905A5008433466 @default.
- W2983028905 hasAuthorship W2983028905A5026864098 @default.
- W2983028905 hasAuthorship W2983028905A5061642704 @default.
- W2983028905 hasAuthorship W2983028905A5070946957 @default.
- W2983028905 hasBestOaLocation W29830289051 @default.
- W2983028905 hasConcept C136764020 @default.
- W2983028905 hasConcept C148417208 @default.
- W2983028905 hasConcept C158379750 @default.
- W2983028905 hasConcept C186967261 @default.
- W2983028905 hasConcept C31258907 @default.
- W2983028905 hasConcept C38652104 @default.
- W2983028905 hasConcept C41008148 @default.
- W2983028905 hasConcept C546215728 @default.
- W2983028905 hasConcept C555944384 @default.
- W2983028905 hasConcept C76155785 @default.
- W2983028905 hasConcept C81860439 @default.
- W2983028905 hasConcept C95713431 @default.
- W2983028905 hasConceptScore W2983028905C136764020 @default.
- W2983028905 hasConceptScore W2983028905C148417208 @default.
- W2983028905 hasConceptScore W2983028905C158379750 @default.
- W2983028905 hasConceptScore W2983028905C186967261 @default.
- W2983028905 hasConceptScore W2983028905C31258907 @default.
- W2983028905 hasConceptScore W2983028905C38652104 @default.
- W2983028905 hasConceptScore W2983028905C41008148 @default.
- W2983028905 hasConceptScore W2983028905C546215728 @default.
- W2983028905 hasConceptScore W2983028905C555944384 @default.
- W2983028905 hasConceptScore W2983028905C76155785 @default.
- W2983028905 hasConceptScore W2983028905C81860439 @default.
- W2983028905 hasConceptScore W2983028905C95713431 @default.
- W2983028905 hasFunder F4320306076 @default.
- W2983028905 hasLocation W29830289051 @default.
- W2983028905 hasOpenAccess W2983028905 @default.
- W2983028905 hasPrimaryLocation W29830289051 @default.
- W2983028905 hasRelatedWork W2351967314 @default.
- W2983028905 hasRelatedWork W2362681120 @default.
- W2983028905 hasRelatedWork W2372429262 @default.
- W2983028905 hasRelatedWork W2376320007 @default.
- W2983028905 hasRelatedWork W2389079374 @default.
- W2983028905 hasRelatedWork W2903653170 @default.
- W2983028905 hasRelatedWork W2967161677 @default.
- W2983028905 hasRelatedWork W4220926637 @default.
- W2983028905 hasRelatedWork W4312465446 @default.
- W2983028905 hasRelatedWork W4376643979 @default.
- W2983028905 isParatext "false" @default.
- W2983028905 isRetracted "false" @default.
- W2983028905 magId "2983028905" @default.
- W2983028905 workType "article" @default.