A Payload of Lies: False Data Injection Attacks on MQTT-based IIoT Systems

Wael Alsabbagh, Chaerin Kim, Peter Langendörfer · 2024

In the ever-evolving landscape of Industrial Internet of Things (IIoT), security emerges as a critical concern. This paper delves into the realm of False Data Injection Attacks (FDIAs) within MQTT-based IIoT systems, specifically targeting the publisher-subscriber model. Our exploration unveils two distinct attack scenarios that exploit the vulnerabilities inherent in the communication fabric. In the first scenario, we demonstrate the potential chaos wrought by sending false data to subscribers, manipulating their perception and inducing actions that align with the attacker’s whims. The second scenario ventures into the heart of the publisher, where the attacker injects false data – deceptive status updates from other publishers e.g., Programmable Logic Controllers (PLCs). The repercussions ripple through the entire industrial process, impacting operations based on fraudulent information. This showcases the cascading effects of FDIAs, illustrating the profound threat they pose to the reliability and integrity of IIoT systems. For real-world attack scenarios, Our attacks were conducted on a small MQTT-based IIoT system, using the Fischertechnik Lernfabrik 4.0 9V factory. Finally, we proposes mitigation solutions to safeguard IIoT systems from the far-reaching consequences of false data manipulation. Our attack codes as well as a proof-of-concept are publicly available for further research.

Read the paper · More papers on PaperTik