A fake timing attack against behavioural tests used in embedded IoT M2M communications
Valerio Selis, Alan Marshall · 2017
Interconnected embedded machines in the Internet of Things (IoT) play a key role for collecting and managing data from the real environment. These machines adopt Machine-to-Machine (M2M) networks in order to exchange information. Securing this information is therefore essential. However, these machines have reduced capabilities giving the opportunity to be easily compromised. IoT trust agents in embedded machines can use timing-based behavioural tests in order to trust each other. However, attackers can use powerful systems to subvert the network by launching a fake timing attack. This attack consists of mimicking the timing behaviours of real embedded machines. In this work, we present a detection algorithm for detecting this attack and also detecting forged embedded machines based on virtual and emulated systems. This will allow IoT embedded machines to create trusted M2M communications.