簡易檢索 / 詳目顯示

研究生: 吳東燊
Wu, Dong-Shen
論文名稱: 基於藍牙低功耗之高仿真蜜罐
Highly Realistic Honeypot for Bluetooth Low Energy
指導教授: 林輝堂
Lin, Hui-Tang
學位類別: 碩士
Master
系所名稱: 電機資訊學院 - 電腦與通信工程研究所
Institute of Computer & Communication Engineering
論文出版年: 2021
畢業學年度: 109
語文別: 英文
論文頁數: 49
中文關鍵詞: 高仿真性蜜罐藍牙低功耗物聯網安全
外文關鍵詞: High Realistic honeypot, Bluetooth low energy, IoT security
相關次數: 點閱:111下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 隨著物聯網的快速發展,物聯網設備受到入侵的風險也日益增加。目前最適合發現新型攻擊的方式就是誘捕系統,也稱為蜜罐。近年來,各種不同種類的蜜罐陸續被提出,目前雖然使用藍牙的設備不斷增加,卻沒有較新的文獻提出適用於藍牙的誘捕系統。因此本文提出了一種基於藍牙低功耗的高仿真性誘捕系統。其中包含利用開發板來實作的物理性蜜罐,能夠在藍牙有效距離內與攻擊者進行實際互動;以及虛假檔案系統構建成的虛擬蜜罐,透過我們假造的回應機制來欺騙攻擊者,這兩種方法的合併使用可以達到同時誘捕來自有線網路的攻擊者以及在藍牙通訊範圍內的攻擊者,而且具有高適應性可以依據需要偽裝成不同設備,也具有高安全性能保證攻擊者不會將蜜罐攻陷並占為己有。由於藍牙通訊本身受限於距離限制,因此為了證明藍牙攻擊是有可能造成嚴重的安全性問題,我們實作了一項攻擊,能夠欺騙受害者進行藍牙連線並在受害者不知情的狀況下,竊取所有受害者的通訊錄,通話紀錄,以及簡訊等資料,明確展示藍牙安全問題的嚴重性。

    With the rapid development of the Internet of Things, the risk of IoT devices being compromised is also increasing. At present, the most suitable way to detect new types of attacks is trapping systems, also known as honeypots. In recent years, various types of honeypots have been proposed. Although the number of Bluetooth devices is increasing, no newer literature proposes a trapping system suitable for Bluetooth. Therefore, this paper presents a high emulation trapping system based on Bluetooth Low Energy. These include physical honeypots implemented using development boards, which can interact with attackers within the effective range of Bluetooth, and virtual honeypots constructed by fake file systems, which deceive attackers through our simulated response mechanism. The combined use of the two methods can simultaneously trap attackers from wired networks and within the Bluetooth communication range. It is highly adaptable and can be disguised as different devices according to needs. It also has a high-security performance to ensure that attackers will not compromise the honeypot. Because Bluetooth communication itself is limited by distance, to prove that Bluetooth attacks are likely to cause serious security problems, we implemented an attack that can trick the victim into making a Bluetooth connection without the victim’s knowledge. We demonstrate how the attacker can steal all the victim’s address book, call records, and text messages to show the Bluetooth security problem’s seriousness clearly.

    摘要 I Abstract II Acknowledgements IV Contents V List of Tables VII List of Figures VIII Chapter 1 Introduction 1 1.1 Overview 1 1.2 Internet of Things 2 1.3 Bluetooth 3 1.4 Honeypot 5 1.5 Motivation 6 1.6 Objective 7 1.7 Thesis Outline 8 Chapter 2 Background and Related Works 9 2.1 Background 10 2.1.1 Honeypot 10 2.1.2 ATT&GATT Profile 11 2.1.3 Bluetooth’s Security 12 2.2 Relate Works 16 2.2.1 Ethernet-based Honeypot 16 2.2.2 Telnet based IoTPoT 17 2.2.3 Wireless Honeypot 18 2.2.4 ThingPot 19 2.2.5 Bluetooth Decoy System 20 2.2.6 SIPHON: Scalable and highly interactive physical honeypot 22 Chapter 3 System Architecture 24 3.1 Architecture 25 3.2 Physical BLE Honeypot 27 3.2.1 Physical Honeypot Overview 27 3.2.2 BLE Mesh 28 3.2.3 Physical Honeypot Design 29 3.3 Virtual Honeypot 35 3.3.1 Virtual Honeypot Overview 35 3.3.2 Virtual Honeypot Design 36 3.3.3 Shodan.io Honeypot Test 38 Chapter 4 Attack Implementation 39 4.1 Experiment Environment 40 4.2 Attack Setup 40 4.3 Attack Analysis 45 Chapter 5 Conclusion 46 Bibliography 48

    [1] I. F. Akyildiz and J. M. Jornet, "The internet of nano-things," IEEE Wireless Communications, vol. 17, no. 6, pp. 58-63, 2010.
    [2] I. Bluetooth SIG. https://www.bluetooth.com/ (accessed.
    [3] A. Brown and T. Andel, "What’s in your Honeypot?," in 11th International Conference on Cyber Warfare and Security: ICCWS2016, Boston, MA, USA, 2016, pp. 355-362.
    [4] P. Cope, J. Campbell, and T. Hayajneh, "An investigation of Bluetooth security vulnerabilities," in 2017 IEEE 7th Annual Computing and Communication Workshop and Conference (CCWC), 2017: IEEE, pp. 1-7.
    [5] K. Fawaz, K.-H. Kim, and K. G. Shin, "Protecting privacy of {BLE} device users," in 25th {USENIX} Security Symposium ({USENIX} Security 16), 2016, pp. 1205-1221.
    [6] J. D. Guarnizo et al., "Siphon: Towards scalable high-interaction physical honeypots," in Proceedings of the 3rd ACM Workshop on Cyber-Physical System Security, 2017, pp. 57-68.
    [7] W. Jansen, Guidelines on cell phone and PDA security: recommendations of the National Institute of Standards and Technology (no. 800). DIANE Publishing, 2009.
    [8] R. Kaur and G. Singh, "Analysing port scanning tools and security techniques," International Journal of Electrical Electronics & Computer Sciense Engineering (IJEECSE), vol. 1, no. 5, p. 58, 2014.
    [9] D. Lazar, H. Chen, X. Wang, and N. Zeldovich, "Why does cryptographic software fail? A case study and open problems," in Proceedings of 5th Asia-Pacific Workshop on Systems, 2014, pp. 1-7.
    [10] A. M. Lonzetta, P. Cope, J. Campbell, B. J. Mohd, and T. Hayajneh, "Security vulnerabilities in Bluetooth technology as used in IoT," Journal of Sensor and Actuator Networks, vol. 7, no. 3, p. 28, 2018.
    [11] NORDICSEMICONDUCTOR. "nRF Toolbox." https://www.nordicsemi.com/Products/Development-tools/nrf-toolbox (accessed.
    [12] Y. M. P. Pa, S. Suzuki, K. Yoshioka, T. Matsumoto, T. Kasama, and C. Rossow, "IoTPOT: Analysing the rise of IoT compromises," in 9th {USENIX} Workshop on Offensive Technologies ({WOOT} 15), 2015.
    [13] E. S. Padda, E. S. Gupta, E. Apoorva, E. Lofty, and E. A. Kaur, "Honeypot: A security tool in intrusion detection," International Journal of Advanced Engineering, Management and Science, vol. 2, no. 5, p. 239437, 2016.
    [14] A. Podhradsky, C. Casey, and P. Ceretti, "The Bluetooth honeypot project: Measuring and managing bluetooth risks in the workplace," International Journal of Interdisciplinary Telecommunications and Networking (IJITN), vol. 4, no. 3, pp. 1-22, 2012.
    [15] N. C. Rowe and J. Rrushi, Introduction to cyberdeception. Springer, 2016.
    [16] E. P. a. T. Schiller. "A Practical Guide to Honeypots." https://www.cse.wustl.edu/~jain/cse571-09/ftp/honey/ (accessed.
    [17] H. Šemić and S. Mrdovic, "IoT honeypot: A multi-component solution for handling manual and Mirai-based attacks," in 2017 25th Telecommunication Forum (TELFOR), 2017: IEEE, pp. 1-4.
    [18] J. Sen, "Security and privacy challenges in cognitive wireless sensor networks," in Cognitive radio technology applications for wireless and mobile Ad hoc networks: IGI Global, 2013, pp. 194-232.
    [19] Y. Shaked and A. Wool, "Cracking the bluetooth pin," in Proceedings of the 3rd international conference on Mobile systems, applications, and services, 2005, pp. 39-50.
    [20] J. Tosi, F. Taffoni, M. Santacatterina, R. Sannino, and D. Formica, "Performance evaluation of bluetooth low energy: A systematic review," Sensors, vol. 17, no. 12, p. 2898, 2017.
    [21] M. Wang, J. Santillan, and F. Kuipers, "ThingPot: an interactive Internet-of-Things honeypot," arXiv preprint arXiv:1807.04114, 2018.

    下載圖示
    2026-07-31公開
    QR CODE