vix.ing · top · new · best · stats · spec

PoisonIvy: (In)secure Practices of Enterprise IoT Systems in Smart\n Buildings

2020/10/12 by Luis Puche Rondon, Rondon, Luis Puche, Leonardo Babun +7 · 1 citation
Computer Science · Engineering · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Network Security and Intrusion Detection #Security and Verification in Computing #Smart Grid Security and Resilience

paper · pdf · doi:10.48550/arxiv.2010.05658

openalex publication_date 2020/10/12 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

The rise of IoT devices has led to the proliferation of smart buildings,\noffices, and homes worldwide. Although commodity IoT devices are employed by\nordinary end-users, complex environments such as smart buildings, smart\noffices, conference rooms, or hospitality require customized and highly\nreliable solutions. Those systems called Enterprise Internet of Things (EIoT)\nconnect such environments to the Internet and are professionally managed\nsolutions usually offered by dedicated vendors. As EIoT systems require\nspecialized training, software, and equipment to deploy, this has led to very\nlittle research investigating the security of EIoT systems and their\ncomponents. In effect, EIoT systems in smart settings such as smart buildings\npresent an unprecedented and unexplored threat vector for an attacker. In this\nwork, we explore EIoT system vulnerabilities and insecure development\npractices. Specifically, focus on the usage of drivers as an attack mechanism,\nand introduce PoisonIvy, a number of novel attacks that demonstrate an attacker\ncan easily compromise EIoT system controllers using malicious drivers.\nSpecifically, we show how drivers used to integrate third-party devices to EIoT\nsystems can be misused in a systematic fashion. To demonstrate the capabilities\nof attackers, we implement and evaluate PoisonIvy using a testbed of real EIoT\ndevices. We show that an attacker can perform DoS attacks, gain remote control,\nand maliciously abuse system resources of EIoT systems. To the best of our\nknowledge, this is the first work to analyze the (in)securities of EIoT\ndeployment practices and demonstrate the associated vulnerabilities in this\necosystem. With this work, we raise awareness on the (in)secure development\npractices used for EIoT systems, the consequences of which can largely impact\nthe security, privacy, reliability, and performance of millions of EIoT systems\nworldwide.\n

Cited by

Related