Detecting Spoofing Attacks in Zigbee using Device Fingerprinting

Grace Hanusha Talakala, Jyotsna L. Bapat · 2021

Zigbee is lenient in a few security policies as a result, there are certain security vulnerabilities in Zigbee, as identified by current research. This paper addresses problem of identifying and detecting attacks on the Zigbee network, especially using spoofed devices. Various parameters of the Zigbee (802.15.4) stack are analysed and from the analysis, most effective parameters for identifying and detecting the attack by spoofed devices are understood. Identified parameters are used to form a unique fingerprint of devices. The idea is to fingerprint the devices that are in the network and also devices that were previously in the network and form a database of white-listed devices. If a newly joining device does not adhere to these fingerprints it can be prevented from joining the network until further authentication or manual intervention.

Read the paper · More papers on PaperTik