Securing MQTT: unveiling vulnerabilities and innovating cyber range solutions

Yendoubé KOMBATE, Pélagie HOUNGUE, Samuel Ouya · Procedia Computer Science · 2024

The Message Queuing Telemetry Transport (MQTT) protocol, widely used in various industries for Machine-to-Machine (M2M) communication, plays a central role in the IoT architecture. However, despite its widespread adoption, an analysis conducted on the shodan search engine revealed up to 540531 vulnerabilities worldwide as of April 2024, underscoring the security challenges facing this protocol. How can an innovative cyber range system be designed to assess and improve the security of MQTT protocols, focusing on in-depth vulnerability analysis, authentication strategy development, and targeted countermeasures against specific attacks? The study includes an analysis of relevant articles, followed by classification into five different categories. Furthermore, the presentation of a cyber range that exposes various attacks, such as replay attacks, Man-In-The-Middle (MITM), Denial of Service (DoS)/Distributed DoS(DDoS), and cam-hackers, enhances the understanding of MQTT protocol vulnerabilities, emphasizes the critical importance of strengthening security, and serves as a reference for new researchers in the field.

Read the paper · More papers on PaperTik