1/76
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
IoT
aka Internet of Everything (IoE), refers to network of devices having IP addresses and capability to sense, collect, and send data using embedded sensors, comms hardware, and processors
Sensing Technology (in things)
sensors embedded in devices including temperature, gas, location, industrial protocols, health of patient, etc.
Gateways
used to bridge gap between IoT device and end-user allowing them to connect and communicate with data collected by sensors
Cloud Server/Data Storage
after travelling through gateway the collected data arrives at the cloud where it is stored and undergoes data analysis, processed data is transferred to user
Remote Control using Mobile App
end-user uses remote controls installed with mobile app to monitor, control, retrieve data, and take specific action on IoT devices from remote location
IoT Architecture
Edge Technology Layer; all HW components including sensors, RFID tags, or other soft sensors on device
Access Gateway Layer
helps bridge gap between endpoints and takes care of initial data handling, carries out message routing, identification, and subscribing
Internet Layer
serves as main component in carrying out comms between two endpoints such as device-to-device, device-to-cloud, device-to-gateway, or backend data sharing
Middleware Layer
one of most critical layers that operates in two-way mode, sites between app and hardware layer behaving as interface, responsible for data management, device management, and other issues like data analysis and aggregation, data filtering, device info discovery, and access control
Application Layer
top of stack, responsible for delivery of services to relevant users from different sectors including building, industrial, manufacturing, automobile, security, healthcare, etc.
Technologies and Protocols
Short-Range Wireless Comms
Bluetooth Low Energy (BLE)
wireless PAN designed to be applied in various sectors like healthcare, security, entertainment, and fitness
Light-Fidelity (Li-Fi)
like Wi-Fi but mode of communication is Visible Light Comms (VLC) and data is transferred at very high speed of 224 Gbps
Near-Field Communication (NFC)
short-range comms that uses magnetic field induction, primarily used in contactless mobile payments, social networking, and identification of documents
QR Codes and Barcodes
machine-readable tags that contain info about product or item
RFID
stores data in tags that are read using electromagnetic fields
Thread
IPv6-based networking protocol for IoT, main purpose is home automation so devices can communicate with each other on local wireless networks
Wi-Fi
used in WLAN, most common is 802.11n which has max speed of 600 Mbps and 50 m range
Wi-Fi Direct
used for P2P comms without need for WAP, start comms only after deciding which device will act as AP
Z-Wave
low-power, short-range communication designed for home automation, provides simple and reliable way to wirelessly monitor and control household devices
Zig-Bee
short-range comms protocol based on IEEE 203.15.4, used in devices that transfer data infrequently at a low rate in restricted area within range of 10-100 m
Adaptive Network Technology (ANT)
multicast wireless sensor network tech used for short-range comms between devices related to sports and fitness sensors
Medium-Range Wireless Comms
HaLow
variant of Wi-Fi, provides extended range making it useful for comms in rural areas, offer low data rates so it reduces power and cost of transmission
LTE-Advanced
standard for mobile comms that enhances LTE, focuses on providing high capacity in terms of data rate, extended range, efficiency, and performance
IPv6 over Low-Power WPAN (6LoWPAN)
Internet protocol used for comms between smaller and low-power devices with limited processing capacity
Quick UDP Internet Connections (QUICs)L multiplexed connections between IoT devices over UDP, provides security equivalent to SSL/TLS
Long-Range Wireless Comms
Low Power WAN (LPWAN)
wireless network designed to provide long-range comms between two endpoints
Long Range WAN (LoRaWAN)
supports apps like mobile, machine-to-machine, and secure two-way comms for IoT devices, smart cities, and healthcare apps
Sigfox
used in devices that have short battery life and need to transfer limited amount of data
Neul
used in tiny part of TV white space spectrum to deliver high quality, power, and coverage and low cost networks
Very Small Aperture Terminal (VSAT)
comms protocols used for data transfer using small dish antennas for both broadband and narrowband data
Cellular
comms protocols used for communicating over longer distance, used to send high quality data but with drawbacks of being expensive and having high power consumption
Message Queuing Telemetry Transport (MQTT)
ISO standard lightweight protocol used to transmit messages for long-range wireless comms, helps establish connections to remote locations
Narrowband IoT (NB-IoT)
variant of LoRaWAN and Sigfox that used more enhanced physical layer tech and spectrum used for machine-to-machine comms
Wired Comms
Ethernet
most commonly used type of network protocol, type of LAN consisting of wired connection between computers
Multimedia over Coax Alliance (MoCA)
provides hi-def videos and related content to homes over existing coaxial cables
Power-Line Comms (PLC)
uses electrical wires to transmit power and data from one endpoint to another, required for apps in different areas like home automation, industrial devices, and broadband over power lines (BPL)
App Protocols
Constrained App Protocol (CoAP)
web transfer protocol used to transfer messages between constrained nodes and IoT networks, mainly for M2M apps like building automation and smart energy
Edge
helps IoT environments move computational processing to the edge of the network allowing smart devices and gateways to perform tasks and services from cloud end, improves content caching, delivery, storage, and management of IoT
Lightweight Machine to Machine (LWM2M)
app-layer comms protocol used for app-level comms between IoT devices, used for device management
Physical Web
tech used to enable faster and seamless interaction with nearby IoT devices, reveals list of URLs being broadcast by nearby devices with BLE beacons
eXtensible Messaging and Presence Protocol (XMPP)
used for real-time comms in IoT devices, used for developing interoperable devices, apps, and services for the IoT environment
Mihini/M3DA
SW used for comms between M2M server and apps running on embedded gateway, allows IoT apps to exchange data and commands with M2M server
Comms Protocols
Device-to-Device (D2D)
interconnected devices interact with each other through Internet predominantly using Zigbee, Z-Wave, or Bluetooth, most commonly used in smart homes devices that transfer small packets to each other at low data rate, popular in comms between wearable devices (e.g., EKG device paired with user's smartphone)
Device-to-Cloud (D2C)
devices communicate with cloud directly, uses Wi-Fi, Ethernet, or Cellular (e.g., CCTV camera accessed by smartphone remotely)
Device-to-Gateway (D2G)
device communicates with intermediate device (gateway) which communicates with cloud service, gateway could be smartphone or hub which provides security features or protocol translation, usually over Zigbee or Z-Wave (e.g., smart TV that connects to cloud through mobile phone app)
Backend Data-Sharing
extends D2C such that data from IoT device can be accessed by authorized third parties, devices upload data to cloud which is later accessed by third party (e.g., analyzer of monthly energy consumption at a company)
Rolling Code Attack
attacker jams and sniffs the signal to obtain the code transferred to a vehicle's receiver; the attacker then uses it to unlock and steal the vehicle
BlueBorne Attack
attackers connect to nearby devices and exploit the vulnerabilities of the Bluetooth protocol to compromise the device, compatible with all BT versions and does not require user interaction, precondition, or config expect for BT being active
Remote Access using Telnet
Attackers exploit an open telnet port to obtain information that is shared between the connected devices, including their software and hardware models
Software-defined Radio (SDR) Attacks
attacker uses SDR to examine comms signals in IoT network and sends spam content to interconnected devices which can change transmission or reception of signals between devices depending on SW implementations via half or full duplex transmission modes
Replay Attack
attackers intercept legitimate messages from valid communication and continuously send the intercepted message to the target device to perform a denial-of-service attack or crash the target device
Cryptanalysis Attack
same procedure as replay attack, but attack must be skilled in cryptography, comms theory, and modulation scheme to remove noises from signal
Recon Attack
attacker obtains info from device's specs as all IoT devices run through RF signals that are certified by their country's authority and disclose analysis report of the device, attacker uses multimeters to investigate chipset and mark out identifications to discover product ID and compare it with published report
RTL-SDR
HW available in form of USB dongle used to capture active radio signals in vicinity, can capture frequencies from 500 kHz up to 1.75 GHz, attackers can receive and decode GPS signals, analyze spectrum, listen to DAB broadcast radio, listen to and decode HD radio, sniff GSM signals, listening to VHF amateur radio, scan trunked radio conversations, and scan for cordless phones
GNU Radio
uses external RF HW to generate SDR and offers framework and required tools to generate SW radio signals, attackers can perform various SDR-based attacks, offers framework and required tools to generate SW radio signals
Fault Injection Attack
occurs when an attacker tries to introduce fault behavior in an IoT device with the goal of exploiting these faults to compromise the security of that device, can be invasive or non-invasive
Optical, Electro Magnetic Fault Injection (EMFI), Body Bias Injection
attacker injects faults into device using projecting lasers and electromagnetic pulses
Frequency/Voltage Tampering
attacker tampers with operating conditions, modifies level of power supply, or alters cloth frequency of chip
Power/Clock/Reset Glitching
attack injects faults or glitches into power supply and clock network of chip
Temperature Attacks
attacker alters temp for operating the chip affecting the whole environment
Sybil Attack
attacker uses multiple forged identities to create a strong illusion of traffic congestion, affecting communication between neighboring nodes and networks
Firmware Update (FOTA) Attack
attacker intercepts and manipulates the firmware update process to inject malicious code
Control Hijacking Attack
changing normal flow control of IoT device FW by injecting code
Rube Goldberg Attack
chained attack designed to exploit industrial IoT device weaknesses
Skill Squatting Attack
exploiting voice-based commands in digital assistants
Formjacking Attack
stealing credit card details and PII from payment forms
Zigbee End-Device (ZED) Sabotage
damages ZED by sending signal periodically to wake up object to drain its battery
Ohigashi-Morii Attack
attacks WPA-TKIP by reducing injection time of malicious packet
NAND Glitching
process of gaining root access while booting a device which can be performed by making a ground connection to the serial I/O pin of a flash memory chip by exploiting a backup process loaded in the local flash memory chip to grant privileged single-user access during a booting failure