Securing Shared Subscriptions in MQTTv5 for IoT Networks: Vulnerability Analysis and Mitigation

Graziano Rizzo, Mattia Giovanni Spina, Floriano De Rango · 2024

Massive IoT (M-IoT) is a network paradigm introduced in the fifth-generation (5G) of networks to cope with a huge number of interconnected IoT devices that handle high volumes of data while providing fast and reliable IoT applications. Focusing on the constrained nature of sensors, the Message Queuing Telemetry Transport (MQTT) protocol introduces, with the MQTTv5 specification, a pivotal technology for enhancing resource utilization and connectivity efficiency in M-IoT scenarios: the shared subscription mechanism. However, due to the huge amount of interconnected IoT devices characterizing modern networks, security vulnerabilities are further exacerbated potentially leading to high-scale damage. Based on these considerations, the objective of this work is to provide a security-oriented examination of the shared subscription feature proving how malicious users can exploit it to induce an indefinite starvation status among the legacy subscribers of the IoT Wireless Sensor Network (WSN) deployment. We highlighted the extent of the damage of the shared subscription attack proposing a countermeasure that takes into account both the light nature of MQTT and the impact that it could have in future M-IoT deployment testing it under real IoT traffic patterns.

Read the paper · More papers on PaperTik