Internet of Things security is a crucial topic, due to the characteristics of these networks and the sensitivity of exchanged data. In this paper, we focus on the execution of cyber-attacks from low-cost IoT devices. Particularly, our aim is to evaluate if the ESP8266 module is able to successfully perpetrate a denial of service attack against a widely adopted web service daemon. Results show that the performance of the IoT component is similar to conventional attacking nodes, although memory overflow issues are experienced when targeting some specific configurations of the server. Hence, by measuring the behavior of the ESP8266 for different attack instances, we found that, by targeting a server configured to serve the maximum number of clients possible, a single-node attack is able to establish 66% of the server's resources without experiencing any client-side malfunctioning. Instead, a distributed attack involving malicious IoT nodes is perpetrated correctly.

On the Use of Low-Cost IoT Devices to Perpetrate Slow DoS Attacks

Enrico Cambiaso
2023

Abstract

Internet of Things security is a crucial topic, due to the characteristics of these networks and the sensitivity of exchanged data. In this paper, we focus on the execution of cyber-attacks from low-cost IoT devices. Particularly, our aim is to evaluate if the ESP8266 module is able to successfully perpetrate a denial of service attack against a widely adopted web service daemon. Results show that the performance of the IoT component is similar to conventional attacking nodes, although memory overflow issues are experienced when targeting some specific configurations of the server. Hence, by measuring the behavior of the ESP8266 for different attack instances, we found that, by targeting a server configured to serve the maximum number of clients possible, a single-node attack is able to establish 66% of the server's resources without experiencing any client-side malfunctioning. Instead, a distributed attack involving malicious IoT nodes is perpetrated correctly.
2023
Istituto di Elettronica e di Ingegneria dell'Informazione e delle Telecomunicazioni - IEIIT
cyber-security
internet of things
denial of service
slow dos attack
esp8266
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/463480
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact