Improving the resiliency of IoT systems

Moosa Yahyazadeh, Octav Chipara, Rishab Nithyanand, Omar Chowdhury, Kasturi Varadarajan, Alberto M. Segre · 2021

Internet of Things (IoT), as a new emerging technology, has gained a foothold in many different domains such as smart home, health care, and industrial manufacturing for its customization capability to meet varying application domain needs. Such customization is mostly realized through programmable IoT platforms, where seamless automation tasks are performed using various IoT apps to increase the productivity of the systems. Prior work has shown that there are several vulnerabilities associated with the misbehavior in these IoT apps which expose such IoT platforms to a variety of security, privacy, and safety threats. In an attempt to identify/prevent such misbehavior, however, those solutions suggested so far still suffer from one or more of the following limitations: (a) requiring a significant amount of human intervention; (b) only designed for analyzing IoT apps in isolation and thus not suitable for mitigating misbehavior involving multiple apps in concert; (c) lacking more precise analysis (i.e., they tend to have higher false positives); (d) only addressing a limited number of misbehavior classes; and (e) using a restricted form of ground truth (representing the misbehavior) make them not expressive enough to capture the complexities of misbehaviors.In this study, we first propose two techniques, called EXPAT and PATRIoT, addressing those limitations in the prior solutions and demonstrate some empirical evaluation of our techniques indicating that they can effectively mitigate the misbehavior in the programmable IoT systems while incurring only a moderate overhead. We then investigate a class of vulnerabilities in the implementations of a security mechanism — RSA PKCS#1-v1.5 signature verification — that underlies many security guarantees in the loT systems. These vulnerabilities are variants of Bleichenbacher-style low public exponent RSA signature forgery, which occurs when a signature verification implementation leaves a significant area of the signature’s encoded message unchecked, while the signer’s public key uses a low public exponent. To detect such vulnerabilities, our proposed approach, called MORPHEUS, features a formally verified implementation of RSA PKCS#1-v1.5 signature verification, acting as the oracle to detect bugs in implementation under test. MORPHEUS works in a black box fashion and thus is a programming language agnostic framework to target various implementations. We have used MORPHEUS to test against 45 PKCS#1-v1.5 signature verification implementations and dis- covered 6 implementations are susceptible to the variants of the Bleichenbacher-style low public exponent RSA signature forgery, 1 implementation with buffer overflow attack, 33 implementations with incompatibility issue, and 8 implementations with minor leniencies. All our findings have been responsibly disclosed to the affected vendors and 12 new CVEs have been assigned to the immediately exploitable ones.

Read the paper · More papers on PaperTik