All Your Bulbs Are Belong to Us: Investigating the Current State of Security in Connected Lighting Systems
نویسندگان
چکیده
ZigBee Light Link (ZLL) is the low-power mesh network standard used by connected lighting systems, such as Philips Hue, Osram Lightify, and GE Link. These lighting systems are intended for residential use but also deployed in hotels, restaurants, and industrial buildings. In this paper, we investigate the current state of security in ZLL-based connected lighting systems. We extend the scope of known attacks by describing novel attack procedures to show that the ZLL standard is insecure by design. Using our penetration testing framework, we are able to take full control over all three systems mentioned above. Besides novel attack procedures, we also extend the intended wireless range of max. 2 meters for configuring a ZLL device to over 30 meters, thus making ZLLbased systems susceptible to war driving. We conclude with a discussion about the security needs of connected lighting systems and derive several lessons for Internet of Things security that can be learned from the insecure design of ZLLbased connected lighting systems.
منابع مشابه
Computer security in the future
Until recently, computer security was an obscure discipline that seemed to have little relevance to everyday life. With the rapid growth of the Internet, e-commerce, and the widespread use of computers, computer security touches almost all aspects of daily life and all parts of society. Even those who do not use computers have information about them stored on computers. This paper reviews some ...
متن کاملExploring the Roles of Agricultural Extension in Promoting Food Security in Kwazulu-Natal Province, South Africa
Household food security remains a challenge in South Africa. The national government instituted the Integrated Food Security Strategy (IFSS) programme which identifies household agricultural production as an important element of improving household-level food security. Agricultural extension is well positioned to help achieve this aim, but its current contribution is unknown. This study identif...
متن کاملPerformance Improvement of Single-Phase Transformerless Grid-Connected PV Inverters Regarding Common-Mode Voltage (CMV) and LVRT
The single-phase transformerless grid-connected photovoltaic (PV) systems, mainly the low-power single-phase systems, require high efficiency, small size, lightweight, and low-cost grid-connected inverters. However, problems such as leakage current, the DC current injection and safety issues are incorporated with transformerless grid-connected PV inverters. Besides, the new standards such as Lo...
متن کاملA Grid Connected Transformerless Inverter and its Model Predictive Control Strategy with Leakage Current Elimination Capability
This paper proposes a new single phase transformerless Photovoltaic (PV) inverter for grid connected systems. It consists of six power switches, two diodes, one capacitor and filter at the output stage. The neutral of the grid is directly connected to the negative terminal of the source. This results in constant common mode voltage and zero leakage current. Model Predictive Controller (MPC) tec...
متن کاملA survey on RPL attacks and their countermeasures
RPL (Routing Protocol for Low Power and Lossy Networks) has been designed for low power networks with high packet loss. Generally, devices with low processing power and limited memory are used in this type of network. IoT (Internet of Things) is a typical example of low power lossy networks. In this technology, objects are interconnected through a network consisted of low-power circuits. Exampl...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1608.03732 شماره
صفحات -
تاریخ انتشار 2016