论文标题

让您的东西无人看管不是开玩笑!内存总线窥探和开放调试接口漏洞

Leaving Your Things Unattended is No Joke! Memory Bus Snooping and Open Debug Interface Exploits

论文作者

Su, Yang, Ranasinghe, Damith C.

论文摘要

物联网设备被普通人群广泛采用。今天的人们比以往任何时候都更加联系。这些设备在竞争激烈的市场中的广泛使用和低成本驱动的构建使与互联网连接的设备成为恶意演员更容易且有吸引力的目标。本文在两个案例研究中以教程样式的格式进行了针对物联网设备的无创物理攻击。该研究的重点是证明:i)对调试界面的开发,通常是在制造后打开的; ii)剥削裸露的内存总线。我们说明一个人可以使用入门级知识,廉价设备和有限时间(在8到25分钟内)进行此类攻击。

Internet of Things devices are widely adopted by the general population. People today are more connected than ever before. The widespread use and low-cost driven construction of these devices in a competitive marketplace render Internet-connected devices an easier and attractive target for malicious actors. This paper demonstrates non-invasive physical attacks against IoT devices in two case studies in a tutorial style format. The study focuses on demonstrating the: i)exploitation of debug interfaces, often left open after manufacture; and ii)the exploitation of exposed memory buses. We illustrate a person could commit such attacks with entry-level knowledge, inexpensive equipment, and limited time (in 8 to 25 minutes).

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源