Ethical hacking of Danalock V3: A cyber security analysis of a consumer IoT device
2021 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesis
Abstract [sv]
IoT-enheter blir alltmer populära. IoT-produkter tillåter användare att fjärrstyraenheten med hjälp av en mobilapplikation eller en webbapplikation. För dettaändamål används en mängd av kommunikationsprotokoll som Bluetooth och Wi-Fi.Denna sammankoppling av enheter och användningen av olika tekniker kan leda tillsäkerhetsproblem. Det är viktigt att säkra dessa enheter för att förhindra obehörigaanvändare från att komma åt känslig information eller ta kontroll över produkten. Ett exempel på en IoT-enhet är Danalock V3, som är ett smart lås som kanimplementeras på en dörr. Syftet med denna rapport är att genomföra ensäkerhetsbedömning av Danalock V3 genom penetrationstestning. Med en svarthatt-metod samlar vi in information om enheten för att förstå dess funktionalitetoch de funktioner som tillhandahålls för användarna. Därefter skapar vi enhotmodell baserad på vår analys av enheten och dess relaterade komponenter. Vianvänder den samlade informationen vid kartläggning av ytattacker för att skapaett arkitekturdiagram som visar komponenterna och den miljö där enhetenfungerar. Diagrammet används för att identifiera de tillgångar och ingångspunktersom kan användas för att hacka smartlåset. Vi använder också STRIDE-metodenför att identifiera möjliga sårbarheter som kan äventyra säkerheten för låset. I denna säkerhetsbedömning genomför vi sju penetrationstester för att utvärderanågra av säkerhetsfunktionerna i Danalock V3. Dessa tester är Reverse engineeringof mobile application, mobile application storage analysis, GPS spoofing, Networktraffic decryption, Bluetooth traffic decryption, Tampering with data sent to themobile application, och Tampering with data sent to the lock. Resultaten av denna undersökning visar att själva enheten är säkrad i vissutsträckning menatt det finns utrymme för ytterligare förbättringar. Vi märker attDanalock V3 använder olika krypteringsprotokoll för att skydda den överfördainformationen. Användaren är dock ansvarig för att skydda mobiltelefonen för attförhindra åtkomst till de lagrade referenserna I denna rapport diskuterar vi också de erhållna resultaten och konsekvenserna avdessa attacker. Vi tillhandahåller en analys av testerna och hur de påverkaranvändarna. Vi använder DREAD-klassificeringssystemet för att utvärdera deupptäckta sårbarheterna och riskerna.
Abstract [en]
IoT devices are becoming increasingly popular. IoT products allow the users to remotely control the device using a mobile application or a web application. For this purpose, a variety of communication protocols are used such as Bluetooth and WiFi. This interconnection of devices and the use of various technologies could lead tosecurity issues. It is important to secure these devices to prevent unauthorized users from accessing the sensitive information or taking control of product. An example of an IoT device is Danalock V3, which is a smart lock that can be implemented on a door. The aim of this report is to conduct a security assessment of Danalock V3 through penetration testing. Using a black hat approach, we gather information about the device to understand its functionality and the provided features for the users. Next, we create a threat model based on our analysis of the device and its related components. We use the gathered information in surface attack mapping to create an architectural diagram displaying the components andthe environment in which the device operates in. This diagram is used to identify the assets and entry points that could be used to hack the smart lock. We also use the STRIDE method to identify the possible vulnerabilities that could compromise the security of the lock. In this security assessment we conduct 7 penetration tests to evaluate some of the security features of Danalock V3. These tests are Reverse engineering of mobile application, Mobile application storage analysis, GPS spoofing, Network traffic decryption, Bluetooth traffic decryption, tampering with data sent to the mobile application, and Tampering with data sent to the lock. The results of this investigation show that the device itself is secured to some extent and that there is room for further improvement. We notice that Danalock V3uses different encryption protocols to protect the transmitted data. However, the user is responsible to protecting the mobile phone to prevent access to the stored credentials. This means that the user should connect to secure networks when downloading the digital key and when logging in to the account. In this report we also discuss the obtained results and the implications of these attacks. We provide an analysis of these tests and how they affect the users. We use the DREAD rating system to evaluate the discovered vulnerabilities and the risksinvolved.
Place, publisher, year, edition, pages
2021. , p. 53
Series
TRITA-EECS-EX ; 2021:27
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:kth:diva-291207OAI: oai:DiVA.org:kth-291207DiVA, id: diva2:1534124
Supervisors
Examiners
2021-03-082021-03-042022-06-25Bibliographically approved