Forensic Analysis of an IoT ARP Spoofing Attack

Sabrina Friedl, Günther Pernul · 2024

The Internet of Things (IoT) creates numerous attack opportunities. Address Resolution Protocol (ARP) spoofing (or cache poisoning) attacks allow hackers to impersonate a PC and steal traffic. This attack is commonly used in spy movies and increasingly in IoT environments. To show the procedure of an IoT forensic analysis to an ARP spoofing attack, we simulate an IoT environment using Arduinos (UNO Rev2, NANO 33 IoT) and sensors (keypad module, motion sensor) acting as IoT devices in the network. This is the basis for the presented fictitious case scenario (based on an actual case), in which a former insider helps a hacking group to breach a corporate network and spy on company secrets to sell them to the competition (industrial espionage). This attack scenario increasingly used and possible by novel IoT attack paths damages customers' trust in the company and leads to the loss of secret documents, directly causing significant financial loss for the company. The case scenario shows that forensic analysis can provide valuable evidence. It demonstrates the current danger of newly implemented IoT environments within companies and the dangerous use of standard IoT devices (devices available on the market and ones developed for pen-testing) as entry points for advanced attacks.

Read the paper · More papers on PaperTik