iTieProbe: Is Your IoT Setup Secure against (Modern) Evil Twin?
Anand Agrawal, Rajib Ranjan Maiti

TL;DR
This paper presents iTieProbe, a system for ethical hacking that tests the security of IoT devices during Wi-Fi setup, revealing vulnerabilities like credential leaks and fake device creation, especially against evil twin attacks.
Contribution
The paper introduces iTieProbe, a novel system for discovering security vulnerabilities in IoT device setup processes using Wi-Fi, focusing on evil twin attack scenarios.
Findings
Several IoT devices leak Wi-Fi credentials during setup.
iTieProbe successfully detects vulnerabilities in 9 tested IoT devices.
Some devices are susceptible to fake IoT device creation during setup.
Abstract
Evil twin attack on Wi-Fi network has been a challenging security problem and several solutions have been proposed to this problem. In general, evil twin attack aims to exfiltrate data, like Wi-Fi and service credentials, from the client devices and considered as a serious threat at MAC layer. IoT devices with its companion apps provides different pairing methods for provisioning. The "SmartConfig Mode", the one proposed by Texas Instrument (TI) and the "Access Point pairing mode (AP mode)" are the most common pairing modes provided by the application developer and vendor of the IoT devices. Especially, AP mode use Wi-Fi connectivity to setup IoT devices where a device activates an access point to which the mobile device running the corresponding mobile application is required to connect. In this paper, we have used evil twin attack as a weapon to test the security posture of IoT…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Opportunistic and Delay-Tolerant Networks · Network Security and Intrusion Detection
