@inproceedings{ebd94ff86afe4a21a1d0f334c0bd5e0d,
title = "Opening Pandora{\textquoteright}s box: Effective techniques for reverse engineering IoT devices",
abstract = "With the growth of the Internet of Things, many insecure embedded devices are entering into our homes and businesses. Some of these web-connected devices lack even basic security protections such as secure password authentication. As a result, thousands of IoT devices have already been infected with malware and enlisted into malicious botnets and many more are left vulnerable to exploitation. In this paper we analyze the practical security level of 16 popular IoT devices from high-end and low-end manufacturers. We present several low-cost black-box techniques for reverse engineering these devices, including software and fault injection based techniques for bypassing password protection. We use these techniques to recover device firmware and passwords. We also discover several common design flaws which lead to previously unknown vulnerabilities. We demonstrate the effectiveness of our approach by modifying a laboratory version of the Mirai botnet to automatically include these devices. We also discuss how to improve the security of IoT devices without significantly increasing their cost.",
author = "Omer Shwartz and Yael Mathov and Michael Bohadana and Yuval Elovici and Yossi Oren",
note = "Publisher Copyright: {\textcopyright} Springer International Publishing AG, part of Springer Nature 2018.; 16th International Conference on Smart Card Research and Advanced Applications, CARDIS 2017 ; Conference date: 13-11-2017 Through 15-11-2017",
year = "2018",
month = jan,
day = "1",
doi = "10.1007/978-3-319-75208-2\_1",
language = "American English",
isbn = "9783319752075",
series = "Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)",
publisher = "Springer Verlag",
pages = "1--21",
editor = "Thomas Eisenbarth and Yannick Teglia",
booktitle = "Smart Card Research and Advanced Applications - 16th International Conference, CARDIS 2017,Revised Selected Papers",
address = "Germany",
}