Source-linked AI summary

Consumer, Commercial and Industrial IoT (In)Security: Attack Taxonomy and Case Studies

Christos Xenofontos, Ioannis Zografopoulos, Charalambos Konstantinou, Alireza Jolfaei, Muhammad Khurram Khan, Kim-Kwang Raymond Choo

arXiv:2105.06612v1cs.CR

TL;DR

IoT systems span heterogeneous devices and sectors, creating vulnerabilities that can affect both devices and their operational environments. The paper proposes a four-category attack taxonomy and applies it to nine real-world incidents, documenting attack paths, impacts, and mitigation strategies. Its taxonomy supports systematic investigation of attack clusters across consumer, commercial, and industrial IoT deployments.

  • Problem

    IoT architectures, technologies, and security objectives are diverse, while related taxonomies do not consistently categorize and justify real-world attack incidents across IoT layers.

  • Method

    The paper proposes a taxonomy with Device, Infrastructure, Communication, and Service categories and analyzes nine incidents across consumer, commercial, and industrial IoT sectors.

  • Results

    The taxonomy maps real-world incidents to attack categories while the case studies identify vulnerabilities, attack paths, impacts, and potential mitigation strategies.

  • Takeaways & Limitations

    Systematic investigation of attack clusters can reduce the need to classify every newly encountered attack individually and support secure, resilient IoT systems.

Abstract

from arXiv · show

Internet of Things (IoT) devices are becoming ubiquitous in our lives, with applications spanning from the consumer domain to commercial and industrial systems. The steep growth and vast adoption of IoT devices reinforce the importance of sound and robust cybersecurity practices during the device development life-cycles. IoT-related vulnerabilities, if successfully exploited can affect, not only the device itself, but also the application field in which the IoT device operates. Evidently, identifying and addressing every single vulnerability is an arduous, if not impossible, task. Attack taxonomies can assist in classifying attacks and their corresponding vulnerabilities. Security countermeasures and best practices can then be leveraged to mitigate threats and vulnerabilities before they emerge into catastrophic attacks and ensure overall secure IoT operation. Therefore, in this paper, we provide an attack taxonomy which takes into consideration the different layers of IoT stack, i.e., device, infrastructure, communication, and service, and each layer's designated characteristics which can be exploited by adversaries. Furthermore, using nine real-world cybersecurity incidents, that had targeted IoT devices deployed in the consumer, commercial, and industrial sectors, we describe the IoT-related vulnerabilities, exploitation procedures, attacks, impacts, and potential mitigation mechanisms and protection strategies. These (and many other) incidents highlight the underlying security concerns of IoT systems and demonstrate the potential attack impacts of such connected ecosystems, while the proposed taxonomy provides a systematic procedure to categorize attacks based on the affected layer and corresponding impact.

I. INTRODUCTION

IoT adoption is expanding across consumer, commercial, and industrial settings, while heterogeneous architectures and sector-specific objectives create vulnerabilities whose impacts can extend beyond individual devices.

  • BLE vulnerabilities can expose transmitted user data and weaken authentication after paired devices reconnect, affecting wearable and industrial IoT ecosystems.
  • IoT environments span personal and home devices, connected medical systems, smart cities, transportation, manufacturing, and critical infrastructure.
  • IoT security objectives differ by deployment: availability is central in cities, while industrial systems prioritize sensed-data integrity and resource availability because failures can cause uneconomical or catastrophic operations.
  • The paper proposes a layered attack taxonomy and examines nine incidents across consumer, commercial, and industrial IoT sectors, including attack vectors, impacts, and mitigations.

II. IOT ATTACK TAXONOMY

Prior IoT taxonomies classify attacks by layers, attacker behavior, security goals, technologies, or application domains, but related work does not consistently map realistic incidents to justified attack categories.

  • A. Related Work: Existing IoT taxonomies use diverse criteria, including attack layers, attacker behavior, security goals, exploitation paths, device properties, access levels, and application domains.
  • A. Related Work: Some prior classifications discuss vulnerabilities and countermeasures or real-world examples, but they often focus on selected technologies, sectors, or attack types.
  • A. Related Work: Attack methods discussed in the literature include jamming, eavesdropping, packet injection, routing, spoofing, packet redirection, packet dropping, and application-layer exploitation.
  • A. Related Work: Prior taxonomies include cyber-physical, middleware, and application categories linked to violated goals such as availability, authenticity, integrity, confidentiality, and access control.
  • A. Related Work: Related work does not consistently provide meticulous incident categorization, category justification, or realistic examples across all attack classes.

B. Proposed Taxonomy

The proposed taxonomy groups IoT attacks into Device, Infrastructure, Communication, and Service categories and applies these categories to real-world incidents across three IoT domains.

  • B. Proposed Taxonomy: The paper uses the taxonomy to classify incidents from consumer, commercial, and industrial sectors while describing vulnerabilities, attack paths, impacts, and countermeasures.
  • B. Proposed Taxonomy: The taxonomy classifies attacks into Device, Infrastructure, Communication, and Service categories, allowing attacks to belong to multiple categories when appropriate.
  • B. Proposed Taxonomy: Device attacks damage or tamper with IoT hardware or software, including sensors, actuators, edge devices, ports, firmware, and malicious code execution paths.
  • B. Proposed Taxonomy: Infrastructure attacks target back-end data access, storage, processing, databases, cloud systems, and edge-computing operations.
  • B. Proposed Taxonomy: Communication attacks target protocols, standards, technologies, channels, routing, switching, network exchange, and protocol translations between IoT devices.
  • B. Proposed Taxonomy: Service attacks target user-facing functionality and orchestration software, including reports, control commands, phishing, social engineering, hijacking, malicious scripts, and buffer overflows.

III. ATTACKS USE CASES TARGETING IOT DEPLOYMENTS

The case-study section analyzes real-world attacks across consumer, commercial, and industrial IoT deployments, connecting adversarial procedures and vulnerabilities with impacts and countermeasures.

  • The case studies cover consumer, commercial, and industrial IoT incidents and classify the attacks according to the proposed taxonomy.
  • Each analysis describes exploited vulnerabilities, adversarial attack procedures, operational impacts, and security countermeasures.

A. Incidents Targeting Consumer IoT Devices

Consumer IoT incidents show how vulnerabilities in voice assistants and related applications can compromise device operation and user privacy. The paper examines attack procedures, impacts, and mitigation considerations across consumer devices.

  • Consumer IoT attacks span individual privacy compromises, including voice-assistant abuse, and broader attacks against connected-device ecosystems.
  • 1) Case Study 1 – Voice Assistant :: Voice-assistant attackers exploited implementation bugs in application features to eavesdrop on users, steal credentials, and enable phishing or account-hijacking attacks.The attack framework manipulated application behavior and welcome messages to evade security mechanisms and deceive users.
  • 1) Case Study 1 – Voice Assistant :: Reviewing application features after every update and handling silent messages, unpronounceable characters, and keywords carefully are proposed countermeasures.

2) Case Study 2 – Baby Monitoring Cameras:

The baby-monitoring-camera case exposes multiple device, service, and access weaknesses that can compromise video privacy and connected home networks. Default credentials and insecure streaming substantially expand the attack surface.

  • Baby-monitoring-camera vulnerabilities included unauthenticated local-network access, unencrypted peer-to-peer cloud video streaming, default passwords, and administrator-access UART interfaces.These weaknesses allowed attackers to target the camera across device and service categories.
  • Attackers could scan for valid device IDs with default credentials, connect to the camera through its peer-to-peer service, and spy on users.
  • Changing default credentials, disabling unused features, applying firmware updates, and enabling encrypted traffic can reduce potential attack entry points.The paper notes that these measures cannot deter determined adversaries completely.
  • The Mirai botnet illustrates how consumer IoT compromise can scale from individual device privacy risks to disruptive attacks affecting many devices.

3) Case Study 3 – The Mirai Botnet:

The Mirai botnet used network scanning and credential attacks to compromise consumer IoT devices, while the broader paper connects IoT incidents to layered vulnerabilities across commercial and industrial systems. The cases motivate mitigations spanning credentials, software, hardware, and network architecture.

  • 3) Case Study 3 – The Mirai Botnet:: Mirai scanned IPv4 addresses, tried Telnet or SSH credentials, infected successful victims with device-specific malware, and remotely coordinated them for DDoS attacks.The infected devices simultaneously continued scanning for additional vulnerable systems.
  • 3) Case Study 3 – The Mirai Botnet:: Mirai mainly targeted IP cameras, DVRs, printers, and routers, with estimated consumer device costs of $13.50 per device and network-overflow costs of $4,207.03 per hour.
  • 3) Case Study 3 – The Mirai Botnet:: Randomized passwords, non-default network configurations, ASLR, secure automatic updates, and suspicious-traffic alerts are proposed defenses against botnet attacks.

2) Case Study 5 – Heavy-Duty Vehicles:

Heavy-duty vehicle attacks exploited communication interfaces and physical diagnostic access to control vehicle functions. The resulting compromises could override driver input and create severe safety hazards.

  • Researchers compromised truck and school-bus CAN networks through the OBD port, controlling throttle, engine brakes, and dashboard indicators.The attacks used captured packets and packet-injection tools against the J1939 vehicle network.
  • The case demonstrates that added vehicle connectivity and communication interfaces also increase potential entry points for adversaries.
  • Attackers could override driver input, remove torque regulation, disable engine braking below 30 mph, and alter brake-pressure indicators.
  • These vehicle attacks could threaten passengers and surroundings by impairing braking, torque control, and the driver’s ability to assess brake pressure.

3) Case Study 6 – Healthcare Medical Devices:

Healthcare IoT attacks exposed outdated, Internet-connected medical systems and demonstrated consequences ranging from data compromise to disrupted patient care. The case study documents exploitation activity and recommends upgrading legacy systems and strengthening cybersecurity practices.

  • More than 80% of 1.2 million IoT devices in U.S. healthcare organizations reportedly used outdated operating systems without security updates.
  • A German hospital ransomware incident caused system-access unavailability, preventing admission of a critically ill patient who was transferred to another hospital.
  • Shodan exposed Internet-connected medical systems, including anesthesia, cardiology, infusion, MRI, PACS, nuclear-medicine, and pacemaker systems, with weaknesses such as default credentials and Telnet-root access.
  • Healthcare honeypots recorded 55,416 successful logins, 24 successful exploitations, 299 malware samples, and eight HoneyCreds logins over six months.
  • Recommended protections include checking default credentials, reporting vulnerabilities to manufacturers, adopting cybersecurity practices, and upgrading or replacing unsupported systems.

C. Incidents Targeting Industrial IoT Devices

Industrial IoT connectivity links IT, OT, and industrial control systems, but also expands pathways for ransomware to propagate across facilities. WannaCry incidents show that unpatched Windows dependencies can produce substantial operational and financial consequences.

  • 1) Case Study 7 - Ransomware – WannaCry: Approximately $170 million in cost followed WannaCry-related operational downtime at TSMC’s IC fabrication facilities.
  • C. Incidents Targeting Industrial IoT Devices: IIoT integration broadened the vulnerability surface because industrial systems depended on unpatched Windows machines and enterprise-network connectivity.
  • 1) Case Study 7 - Ransomware – WannaCry: WannaCry exploited Windows MS17-010 through EternalBlue, installed the DoublePulsar backdoor, and injected malicious code via SMBv1.
  • 1) Case Study 7 - Ransomware – WannaCry: During installation, WannaCry queried a hardcoded domain as a kill-switch and scanned connected networks for vulnerable devices through open port 445.
  • 1) Case Study 7 - Ransomware – WannaCry: The ransomware encrypted files, deleted unencrypted data, and used a TOR-based command-and-control stage for ransom communication.

2) Case Study 8 – Water Treatment Facilities – Kemuri:

The Kemuri Water Company incident shows how weaknesses in remote access and legacy IT systems can carry attacks into operational technology. Such cross-layer compromise can affect utility operations and create risks to public safety and health.

  • 2) Case Study 8 – Water Treatment Facilities – Kemuri: The KWC investigation identified vulnerabilities in remote user login applications and exposed traffic associated with state-sponsored hacktivists.
  • 2) Case Study 8 – Water Treatment Facilities – Kemuri: Attackers entered the KWC environment through a payment portal using SQL injection and phishing, then leveraged plaintext administrator credentials to access the AS400 system.
  • 2) Case Study 8 – Water Treatment Facilities – Kemuri: KWC remediation included terminating the account-management front end, blocking AS400 outbound connectivity, replacing or patching legacy systems, and network segregation.
  • 2) Case Study 8 – Water Treatment Facilities – Kemuri: Attackers penetrated through IT infrastructure, delivered payloads to OT endpoints, and tampered with facility management and water quality.
  • 2) Case Study 8 – Water Treatment Facilities – Kemuri: A compromise of critical water infrastructure could jeopardize people’s safety and health if customers received contaminated water.

3) Case Study 9 – Modify Control Logic - Triton/TRISIS/HatMan:

The TRITON/TRISIS/HatMan case targeted safety-control components in a petrochemical plant by compromising an SIS workstation and reprogramming connected controllers. The attack could have caused either an operational shutdown or continued operation under unsafe conditions.

  • 3) Case Study 9 – Modify Control Logic - Triton/TRISIS/HatMan: TRITON targeted a petrochemical plant’s Safety Instrumented System workstation and deployed malware to reprogram connected IIoT controllers.
  • 3) Case Study 9 – Modify Control Logic - Triton/TRISIS/HatMan: Attackers gained remote access to the SIS workstation, reached the process-control network, and infected the TriStation environment with trilog.exe.
  • 3) Case Study 9 – Modify Control Logic - Triton/TRISIS/HatMan: Reverse engineering of workstation-controller protocols enabled attackers to mimic legitimate workstations and perform communication-based attacks.
  • 3) Case Study 9 – Modify Control Logic - Triton/TRISIS/HatMan: A successful TRITON attack could have triggered an unexpected plant shutdown or allowed the plant to continue operating under unsafe conditions.
  • 3) Case Study 9 – Modify Control Logic - Triton/TRISIS/HatMan: Recommended protections include segregating safety, process-control, and information networks and enforcing physical controls over TriStation terminals and controller programming.
  • 3) Case Study 9 – Modify Control Logic - Triton/TRISIS/HatMan: Table III maps case studies to taxonomy categories and indicates partial or complete relevance using white-to-black circles.

IV. OPEN CHALLENGES

IoT security remains constrained by heterogeneous devices, limited resources, insecure development and maintenance practices, and the scale of collected data. Addressing these challenges requires coordinated protection across manufacturers, users, and other stakeholders.

  • Vendor and user practices: Default credentials, overlooked vulnerabilities, and negligent patching practices continue to expose IoT systems to compromise.The paper links these weaknesses to vendor practices, user behavior, and vulnerabilities in widely used TCP/IP stacks.
  • Cost and maintenance: Low-cost IoT devices often lack fundamental protections, while long-term software support and security updates impose substantial supplier costs.The paper describes cost as a trade-off between rapid deployment and adequate security, with support commonly discontinued after several years.
  • Computational and protocol constraints: Resource-constrained nodes may not support sophisticated encryption and authentication, while industrial systems may rely on legacy or poorly documented protocols.Modbus is cited as a legacy protocol lacking encryption, and TriStation as a tailor-made industrial protocol with limited public structural information.
  • Learning-based security: Learning-based IoT security methods remain vulnerable to decision-time and data-poisoning attacks, motivating robust algorithms and thorough security assessment.The paper calls for domain-aware approaches to identifying IoT faults and detecting malicious attacks.
  • Data management: The volume of IoT-generated data requires moderation, secure handling, access controls, and greater user awareness of collected information.Examples include cookies and geolocation data, whose collection should be transparent enough for users to make informed choices.

V. CONCLUDING REMARKS

The paper presents an attack taxonomy grounded in real-world incidents across consumer, commercial, and industrial IoT. It maps vulnerabilities and attack paths to operational contexts while proposing mitigation strategies and emphasizing vulnerabilities shared across sectors.

  • Taxonomy and case studies: The taxonomy classifies real-world IoT attacks and maps each case to attack classes, vulnerabilities, exploitation paths, and countermeasures.The case studies cover three incidents each from the consumer, commercial, and industrial sectors.
  • Cross-sector scope: The analysis spans consumer, commercial, and industrial domains whose differing operational objectives and constraints shape their security concerns.Examples of constraints include asset security, real-time operation, and device life-cycles.
  • Cross-cutting vulnerabilities: Default credentials and inadequate network segregation recur across IoT sectors, requiring precise remediation beyond isolated vendor, protocol, or user actions.The paper argues that unified security efforts are needed because these vulnerabilities cut across application boundaries.
Loading 2105.06612v1…