IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in...

27
IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT Swarun Kumar Assistant Professor, ECE, CMU http://swarunkumar.com 1

Transcript of IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in...

Page 1: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT

Swarun KumarAssistant Professor, ECE, CMU

http://swarunkumar.com

1

Page 2: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Lab”All things Wireless”

2

Page 3: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Lab

3

5-G & IoT Battery-Free Sensing New Frontiers

”All things Wireless”

Page 4: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Wireless Security & Privacy

4

Traditional View: Add security & privacy features to wireless

Our View: Use wireless features to improve security & privacy

Page 5: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Thank you Cylab!

• Detection and Mitigation of Fake News(with PI Osman Yagan), 2018

• Wireless Security for Low-Power IoT (2019)

• Lightweight Security for IoT Fog Networks(with PI Osman Yagan), 2020

• Detecting Unauthorized I-IoT Traffic (2020)

5

Akshay Gadre2020 Cylab PhD Fellow

(PS: Check out his poster!)

Page 6: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Thank you Cylab!

• Detection and Mitigation of Fake News(with PI Osman Yagan), 2018

• Wireless Security for Low-Power IoT (2019)

• Lightweight Security for IoT Fog Networks(with PI Osman Yagan), 2020

• Detecting Unauthorized I-IoT Traffic (2020)

Page 7: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Thank you Cylab!

• Detection and Mitigation of Fake News(with PI Osman Yagan), 2018

• Wireless Security for Low-Power IoT (2019)

• Lightweight Security for IoT Fog Networks(with PI Osman Yagan), 2020

• Detecting Unauthorized I-IoT Traffic (2020)

Page 8: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Can we detect radio adversaries?

8

Low Power, Cheap Less Capable

Page 9: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Idea: Use Hardware Imperfections!

9

Cheap Unique filters, Frequency shifts, etc.

Can’t predict / emulate!

Use Wireless “Physically Unclonable Functions” to Achieve Security Goals

Page 10: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Impact

• IPSN 2020 Best Paper, Paper at ICC

• Seeded new awards: NSF CPS (~ $1.5 million), ARL

• Exploring new industry collaborations

10

Page 11: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Thank you Cylab!

• Detection and Mitigation of Fake News(with PI Osman Yagan), 2018

• Wireless Security for Low-Power IoT (2019)

• Lightweight Security for IoT Fog Networks(with PI Osman Yagan), 2020

• Detecting Unauthorized I-IoT Traffic (2020)

Page 12: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Industrial IoT is increasingly wireless

12

Page 13: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

I-IoT Wireless is Fragmented

.. Partly because they provide different range, data rates and infrastructure needs.

13

Page 14: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Implication: Many Security Holes

• Passive Attacks: Monitoring Traffic Flows

• Active Attacks: Mimicking/taking over operations

Oh, I know the Robotic arm is active now

Hey arm, smash some equipment

Our Focus

14

Page 15: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Solution: IoTSnifferInstrument the environment with software radios that bothdetect and locate unauthorized traffic.

Software Radios

15

Page 16: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Our Secret Sauce

• An Efficient Decoding Pipeline: Handle diverse I-IoT technologies

• Learning & Tracking Sender Behavior: Using wireless channels

• Device Tracking: Even for non-cooperating sender devices!

16

Page 17: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Prior Work: LTE Sniffing (LTEye)

Logger

Per-User Analytics(Anonymized)

LTEyeSniffer

LTEyeDatabase

DataAnalyzer

17

Page 18: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Overview of LTEye

User ID Qlty12345678

Link Quality (bits/RE) 182 3 4 5

Page 19: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

User ID Qlty12345678

Temporal Analytics

012

9:00 AM 11:00 AM 1:00 PM 3:00 PM 5:00 PM

Link Quality (bits/RE)2 3 4 5 19

Overview of LTEye

Page 20: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

User ID Qlty12345678

Temporal Analytics

012

9:00 AM 11:00 AM 1:00 PM 3:00 PM 5:00 PM

2 3 4 5 Link Quality (bits/RE) 20

Overview of LTEye

Page 21: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

User ID Qlty12345678

2 3 4 5

Where are these users in the floorspace?

Link Quality (bits/RE) 21

Overview of LTEye

Page 22: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

User ID Qlty12345678

Spatial Analytics

2 3 4 5 Link Quality (bits/RE) 22

Overview of LTEye

Page 23: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Open Challenges in I-IoT context

• Heterogeneous Technologies

• Frequency hopping, active evasion from the sniffers

• Efficient Spectrum sensing

23

Page 24: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

A few updates so far

• Complete: Inexpensive Multi-Technology SDR Sniffer (~ $20)• Support for LoRa, Xbee, Zwave and SIGFOX

24

Page 25: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

A few updates so far• In Progress: Location-Tracking Experiments

25

Page 26: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Next Steps: Mill-19 Testbed

26

Page 27: IoTSniffer: Detecting Unauthorized Traffic in Industrial IoT · 2 days ago · Traffic in Industrial IoT Swarun Kumar ... • Lightweight Security for IoT Fog Networks (with PI Osman

Summary: We do wireless!

New solutions that leverage wireless to address securityand privacy problems

Learn more about my lab’s work at:www.witechlab.com

Hey arm, smash some equipment

Us

27