Access Control Attacks Against IoT Smart Devices: A Case Study
Sumesh J. Philip, Fnu Amisha, Fnu Kamesh · 2024
The Internet of Things (IoT) paradigm refers to a system of billions of Internet-enabled smart devices interconnected with each other. This study attempts to evaluate access control restrictions in smart devices through a penetration test of a lightweight IoT device such as a smartbulb. Very often, lightweight firmware for such devices become the foundation for other products in the market, and requires careful scrutiny for security weaknesses. Past research has discovered several vulnerabilities in a variety of products linked to the vendor of our study. Hence, this study is also interested in the status quo of security updates to newer products given the knowledge of past vulnerabilities. Based on our 3-stage penetration testing approach, we have discovered several access control violations where an attacker can gain network credentials, cloud service credentials of the operator and create availability issues via denial-of-service attacks. Consumers need to be aware of such vulnerabilities that could lead to the compromise of their or-ganizational security countermeasures since weak access control checks on these devices could make them the weak links in the cyber defense chain. Stricter regulations should also be mandated by all stakeholders to ensure that the IoT ecosystem flourishes and benefits society without compromising the security aspect of networked technology systems.