Assessing cybersecurity risks in BLE-based asset management systems

Detalhes bibliográficos
Autor(a) principal: Verde, David Luís Malhão
Data de Publicação: 2024
Tipo de documento: Dissertação
Idioma: eng
Título da fonte: Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
Texto Completo: http://hdl.handle.net/20.500.11960/3949
Resumo: In the current era of digital transformation, Asset Management (AM) systems using Bluetooth Low Energy (BLE) beacons are being applied across various domains, allowing for the detection of individuals or objects within a building. While the impact of a compromised Indoor Positioning System (IPS) may not be significant in certain domains, in others it can pose risks and potentially lead to the loss of human lives or other significant consequences. This work starts with a literature review on vulnerabilities that target BLE beacon devices. With the gathered knowledge from the review, a risk assessment of cyber-attacks targeting AM systems using BLE devices in two specific scenarios is presented: health- care and industry. The aim is to estimate the attacks that pose the greatest risk in each application area. An experimental setup was also created with a focus on testing a set of vulnerabilities, such as replay attack, device cloning, jamming, battery exhaustion at- tack and physical hijacking. Lastly, mitigation measures and a list of best practices and guidelines are proposed to help harden these systems. Results show that, risk levels vary depending on the targeted scenario. Replay, battery exhaustion, jamming, fuzzing, blue-smack, and physical hijacking attacks are the ones that pose the greatest risk levels in the considered scenarios. Additionally, the vulnerabilities exploited in the experimental setup manifest a concerning accessibility, that can lead to irreversible damages.
id RCAP_7152f653e03fd7b3ece4daa42fe2adab
oai_identifier_str oai:repositorio.ipvc.pt:20.500.11960/3949
network_acronym_str RCAP
network_name_str Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
repository_id_str 7160
spelling Assessing cybersecurity risks in BLE-based asset management systemsIndoor-location securityAsset managementBLE beaconsBluetoothCybersecurityLocalização indoor seguraGestão de recursosCibersegurançaIn the current era of digital transformation, Asset Management (AM) systems using Bluetooth Low Energy (BLE) beacons are being applied across various domains, allowing for the detection of individuals or objects within a building. While the impact of a compromised Indoor Positioning System (IPS) may not be significant in certain domains, in others it can pose risks and potentially lead to the loss of human lives or other significant consequences. This work starts with a literature review on vulnerabilities that target BLE beacon devices. With the gathered knowledge from the review, a risk assessment of cyber-attacks targeting AM systems using BLE devices in two specific scenarios is presented: health- care and industry. The aim is to estimate the attacks that pose the greatest risk in each application area. An experimental setup was also created with a focus on testing a set of vulnerabilities, such as replay attack, device cloning, jamming, battery exhaustion at- tack and physical hijacking. Lastly, mitigation measures and a list of best practices and guidelines are proposed to help harden these systems. Results show that, risk levels vary depending on the targeted scenario. Replay, battery exhaustion, jamming, fuzzing, blue-smack, and physical hijacking attacks are the ones that pose the greatest risk levels in the considered scenarios. Additionally, the vulnerabilities exploited in the experimental setup manifest a concerning accessibility, that can lead to irreversible damages.Na atual era da transformação digital, os sistemas de gestão de ativos que utilizam BLE descons estão a ser aplicados em várias áreas, permitindo a detecção de indivíduos ou objetos em ambientes interiores. Enquanto o impacto de um IPS comprometido pode não ser significativo em certos contextos, em aplicações criticas, pode apresentar riscos significativos, podendo, no limite, levar à perda de vidas humanas, entre outras consequências possíveis Este trabalho inicia com uma revisão sistemática das vulnerabilidades direcionadas aos dispositivos BLE bezcons. Com o conhecimento resultante desta revisão, é apresentada uma avaliação de riscos de ciberataques direcionados a sistemas de gestão de ativos que usam tecnologia BLE em dois domínios de aplicação específicos saúde e indústria. O objetivo é identificar os ataques que apresentam o maior risco em cada domínio de aplicação. Foi também criado um ambiente experimental desenhado para testar um conjunto de vulnerabilidades, tais como, ataques de repetição, clonagem de dispositivos, interferência, exaustão de bateria e ataque físico. Por fim, são propostas medidas de mitigação para os riscos identificados, bem como identificadas as melhores práticas e diretrizes para reforçar a segurança da utilização destes sistemas nos dois domínios de aplicação identificados Os resultados mostram que os níveis de risco variam dependendo do domínio de aplicação e do tipo de ataque. Os ataques de repetição, exaustão de bateria, interferência, confusão, blue-smack e ataque físico representam os maiores níveis de risco nos cenários considerados. Além disso, as vulnerabilidades exploradas no ambiente experimental evidenciam uma acessibilidade preocupante, que pode levar a danos irreversíveis.2024-03-13T15:05:18Z2024-01-08T00:00:00Z2024-01-08info:eu-repo/semantics/publishedVersioninfo:eu-repo/semantics/masterThesisapplication/pdfhttp://hdl.handle.net/20.500.11960/3949TID:203551729engVerde, David Luís Malhãoinfo:eu-repo/semantics/openAccessreponame:Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)instname:Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informaçãoinstacron:RCAAP2024-04-11T08:11:55Zoai:repositorio.ipvc.pt:20.500.11960/3949Portal AgregadorONGhttps://www.rcaap.pt/oai/openairemluisa.alvim@gmail.comopendoar:71602024-04-11T08:11:55Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos) - Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informaçãofalse
dc.title.none.fl_str_mv Assessing cybersecurity risks in BLE-based asset management systems
title Assessing cybersecurity risks in BLE-based asset management systems
spellingShingle Assessing cybersecurity risks in BLE-based asset management systems
Verde, David Luís Malhão
Indoor-location security
Asset management
BLE beacons
Bluetooth
Cybersecurity
Localização indoor segura
Gestão de recursos
Cibersegurança
title_short Assessing cybersecurity risks in BLE-based asset management systems
title_full Assessing cybersecurity risks in BLE-based asset management systems
title_fullStr Assessing cybersecurity risks in BLE-based asset management systems
title_full_unstemmed Assessing cybersecurity risks in BLE-based asset management systems
title_sort Assessing cybersecurity risks in BLE-based asset management systems
author Verde, David Luís Malhão
author_facet Verde, David Luís Malhão
author_role author
dc.contributor.author.fl_str_mv Verde, David Luís Malhão
dc.subject.por.fl_str_mv Indoor-location security
Asset management
BLE beacons
Bluetooth
Cybersecurity
Localização indoor segura
Gestão de recursos
Cibersegurança
topic Indoor-location security
Asset management
BLE beacons
Bluetooth
Cybersecurity
Localização indoor segura
Gestão de recursos
Cibersegurança
description In the current era of digital transformation, Asset Management (AM) systems using Bluetooth Low Energy (BLE) beacons are being applied across various domains, allowing for the detection of individuals or objects within a building. While the impact of a compromised Indoor Positioning System (IPS) may not be significant in certain domains, in others it can pose risks and potentially lead to the loss of human lives or other significant consequences. This work starts with a literature review on vulnerabilities that target BLE beacon devices. With the gathered knowledge from the review, a risk assessment of cyber-attacks targeting AM systems using BLE devices in two specific scenarios is presented: health- care and industry. The aim is to estimate the attacks that pose the greatest risk in each application area. An experimental setup was also created with a focus on testing a set of vulnerabilities, such as replay attack, device cloning, jamming, battery exhaustion at- tack and physical hijacking. Lastly, mitigation measures and a list of best practices and guidelines are proposed to help harden these systems. Results show that, risk levels vary depending on the targeted scenario. Replay, battery exhaustion, jamming, fuzzing, blue-smack, and physical hijacking attacks are the ones that pose the greatest risk levels in the considered scenarios. Additionally, the vulnerabilities exploited in the experimental setup manifest a concerning accessibility, that can lead to irreversible damages.
publishDate 2024
dc.date.none.fl_str_mv 2024-03-13T15:05:18Z
2024-01-08T00:00:00Z
2024-01-08
dc.type.status.fl_str_mv info:eu-repo/semantics/publishedVersion
dc.type.driver.fl_str_mv info:eu-repo/semantics/masterThesis
format masterThesis
status_str publishedVersion
dc.identifier.uri.fl_str_mv http://hdl.handle.net/20.500.11960/3949
TID:203551729
url http://hdl.handle.net/20.500.11960/3949
identifier_str_mv TID:203551729
dc.language.iso.fl_str_mv eng
language eng
dc.rights.driver.fl_str_mv info:eu-repo/semantics/openAccess
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
dc.source.none.fl_str_mv reponame:Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
instname:Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informação
instacron:RCAAP
instname_str Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informação
instacron_str RCAAP
institution RCAAP
reponame_str Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
collection Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
repository.name.fl_str_mv Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos) - Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informação
repository.mail.fl_str_mv mluisa.alvim@gmail.com
_version_ 1817543268251992064