An Assessment Platform of Cybersecurity Attacks against the MQTT Protocol using SIEM - IRT SystemX Accéder directement au contenu
Communication Dans Un Congrès Année : 2022

An Assessment Platform of Cybersecurity Attacks against the MQTT Protocol using SIEM

Mohamed Hadded
  • Fonction : Auteur
  • PersonId : 1080197
Gaspard Lauras
  • Fonction : Auteur
Jérôme Letailleur
  • Fonction : Auteur
Yohann Petiot
  • Fonction : Auteur
Anouk Dubois
  • Fonction : Auteur
  • PersonId : 1083493

Résumé

The industry of shared self-driving is increasingly interested in the Message Queuing Telemetry Transport (MQTT) solution to develop and evaluate their autonomous and shared mobility services. This solution would have the advantage of making data exchange easier between autonomous vehicles themselves and between vehicles and infrastructure. Nevertheless, there are a number of security threats due to the design and the use of the MQTT protocol. Some of these threats are denial of service (DoS), spoofing, information disclosure and data corruption. These security issues can be caused by external attackers as well as internal entities that are successfully authenticated. This paper analyzes the impact of these attacks on the performance of MQTT protocol with TLS in terms of CPU/RAM usage and latency. For that, we provide in this paper an in-depth overview of cybersecurity attacks that can disrupt the MQTT protocol and we also present an evaluation platform using Security Information and Event Management (SIEM) architecture that automatically collects and aggregates system events from the server to assess the impact of the cyber attacks. The results indicate that these attacks have highly negative influence on the performance of broker. These results will contribute in the future to implement new countermeasures to improve cybersecurity of MQTT protocol.
Fichier principal
Vignette du fichier
An_Analysis_of_Cybersecurity_Attacks_against_MQTT_protocol.pdf (656.42 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03809994 , version 1 (11-10-2022)

Identifiants

  • HAL Id : hal-03809994 , version 1

Citer

Mohamed Hadded, Gaspard Lauras, Jérôme Letailleur, Yohann Petiot, Anouk Dubois. An Assessment Platform of Cybersecurity Attacks against the MQTT Protocol using SIEM. 25th International Conference on Software Telecommunications and Computer Networks SOFCTOM 2022, Sep 2022, Split, Croatia. ⟨hal-03809994⟩

Collections

IRT-SYSTEMX
37 Consultations
174 Téléchargements

Partager

Gmail Facebook X LinkedIn More