Source-linked AI summary
Survey of Security and Privacy Issues of Internet of Things
Tuhin Borgohain, Uday Kumar, Sugata Sanyal
TL;DR
IoT’s internet-based automatic information exchange creates security flaws and privacy concerns for end users. This paper surveys vulnerabilities in the communication technologies underlying IoT, including WSNs, RFID, and health-monitoring systems, and reports concrete attack and exposure mechanisms. It concludes by advocating stronger security measures before further IoT development.
Problem
IoT communication infrastructure and its information-exchange technologies have security flaws that expose end users to privacy concerns.
Method
The paper conducts a general survey of IoT security issues and end-user privacy issues across its communication technologies.
Results
The survey identifies attacks and vulnerabilities across WSNs, RFID, and socially connected health-monitoring devices, including privacy exposure risks.
Takeaways & Limitations
The paper recommends adopting sound security measures, intrusion detection, cryptographic and steganographic measures, and efficient communication methods for a more secure IoT infrastructure.
Abstract
from arXiv · showhide
This paper is a general survey of all the security issues existing in the Internet of Things (IoT) along with an analysis of the privacy issues that an end-user may face as a consequence of the spread of IoT. The majority of the survey is focused on the security loopholes arising out of the information exchange technologies used in Internet of Things. No countermeasure to the security drawbacks has been analyzed in the paper.
1. INTRODUCTION Building upon the concept of Device to Device (D2D)
IoT enables free information flow among embedded computing devices through the internet, but its internet-based exchange creates security and privacy concerns that should be addressed early.
- IoT connects embedded computing devices through the internet for information exchange.
- The paper identifies IoT as vulnerable to security issues and end-user privacy concerns.
- The authors argue that security should be addressed before further IoT development to support effective and widely accepted adoption.
2. OVERVIEW
The paper surveys IoT connectivity technologies, security and privacy issues, and proposed steps for addressing those issues.
- Section 3 discusses communication technologies that exchange information through internet infrastructure.
- Section 4 surveys IoT security issues and privacy concerns faced by end users of technologies using its information-sharing architecture.
- Section 5 concludes with a proposal for steps to address IoT security issues.
3. CONNECTIVITY TECHNOLOGIES AND INTERACTION AMONGST VARIOUS INTERNET OF THINGS (IoT) DEVICES
IoT devices exchange information automatically through connectivity technologies including wireless sensor networks and RFID. These technologies rely on distributed sensing, wireless links, and tag-reader interactions.
- Automatic information exchange between systems or devices is the main objective of IoT.
- Wireless sensor networks: Wireless sensor networks use independent nodes, limited wireless frequency and bandwidth, and multi-hop relay toward a base station.
- Wireless sensor networks: WSN nodes include sensors, microcontrollers, memory, radio transceivers, and batteries, with collaborative sensing and dynamic wireless communication.
- RFID: RFID tags automatically exchange information through radio-frequency waves without line-of-sight alignment or physical contact.
- RFID: An RFID tag stores a unique Electronic Product Code in memory, which identifies the tag to a reader.
- RFID tags: Active RFID tags use internal batteries, whereas passive tags obtain energy from a reader’s electromagnetic signal through inductive coupling.
4. SECURITY ISSUES AND PRIVACY CONCERNS
IoT communication technologies introduce security and privacy vulnerabilities across wireless sensor networks, RFID, and socially connected health-monitoring devices. The survey organizes attacks by network layer and security property, while describing concrete threats to availability, authenticity, integrity, confidentiality, and user privacy.
- Security problems in IoT arise prominently from the technologies used to relay information between devices.
- Wireless sensor networks: WSN security issues include attacks on secrecy and authentication, service integrity, and network availability.
- WSN physical layer: Physical-layer DoS attacks include jamming, which blocks node communication, and node tampering, which extracts sensitive information physically.
- WSN link layer: Link-layer DoS attacks include collisions, repeated collision-based unfairness, and battery exhaustion caused by unusually high channel traffic.
- WSN network layer: Network-layer threats include spoofing, replaying, misdirection, hello floods, homing, selective forwarding, and acknowledgement flooding.
- WSN transport and application layers: Transport- and application-layer attacks use unnecessary or fake messages to congest channels, trigger retransmissions, or stimulate traffic toward a base station.
- RFID: RFID vulnerabilities include unauthorized tag disabling, cloning, reverse engineering, power analysis, eavesdropping, man-in-the-middle attacks, spoofing, viruses, tracking, and tag killing.
- Health-related IoT technologies: Health-monitoring devices may store login passwords in clear text and expose account functions through unprotected HTTP instructions.
5. CONCLUSION
The paper surveys IoT security flaws and argues that securing existing infrastructure should precede further expansion of IoT implementations.
- The survey covers security flaws across the Internet of Things that may hinder its development and implementation.
- Adopting sound security measures, intrusion detection systems, cryptographic and stenographic measures, and efficient communication methods could strengthen IoT infrastructure.
- The authors recommend developing security measures for existing IoT infrastructure before introducing additional implementation methods in daily life.
Biographies and Photographs
The biographies identify the authors’ academic and professional backgrounds, spanning engineering education, software-system delivery, and research advising.
- Tuhin Borgohain is a third-year Instrumentation Engineering student pursuing a Bachelor of Engineering degree at Assam Engineering College.
- Uday Kumar works as a Delivery Manager at Tech Mahindra and has experience engineering complex software systems and leading projects across multiple domains.
- Sugata Sanyal serves as a Research Advisor at Tata Consultancy Services and has published research on network security and intrusion detection systems.