Skip to main content
QUICK REVIEW

[Paper Review] IoT and Man-in-the-Middle Attacks

Hamidreza Fereidouni, Olga Fadeitcheva|arXiv (Cornell University)|Aug 4, 2023
IoT and Edge/Fog Computing5 citations
TL;DR

This paper investigates Man-in-the-Middle (MitM) attacks in IoT environments, proposing hybrid routing with anomaly detection via transmission time consistency to identify MitM intrusions. It highlights the limitations of current detection methods and advocates for standardized, secure-by-design IoT architectures, machine learning integration, and blockchain-based solutions for long-term resilience.

ABSTRACT

This paper provides an overview of the Internet of Things (IoT) and its significance. It discusses the concept of Man-in-the-Middle (MitM) attacks in detail, including their causes, potential solutions, and challenges in detecting and preventing such attacks. The paper also addresses the current issues related to IoT security and explores future methods and facilities for improving detection and prevention mechanisms against MitM.

Motivation & Objective

  • To analyze the growing threat of Man-in-the-Middle (MitM) attacks in heterogeneous, rapidly expanding IoT ecosystems.
  • To identify key vulnerabilities in IoT security, particularly unencrypted traffic and lack of standardized security frameworks.
  • To evaluate existing detection and prevention mechanisms for MitM attacks and highlight their limitations in real-world IoT deployments.
  • To propose scalable, network-level detection techniques such as hybrid routing with transmission time monitoring for improved anomaly detection.
  • To explore future directions, including machine learning, blockchain, and standardized security frameworks, for robust, deployable IoT security solutions.

Proposed method

  • Proposes a hybrid routing architecture in IoT networks where dedicated, capable devices are selected as routing nodes to monitor and stabilize data transmission paths.
  • Employs an inference algorithm to detect anomalies in transmission times, leveraging the fact that MitM attacks introduce inconsistent or delayed packet delivery.
  • Uses static ARP tables as a lightweight, manual mitigation technique to prevent IP-MAC address spoofing, though limited to small-scale networks.
  • Integrates machine learning and deep learning models for intrusion detection, emphasizing the need for realistic, large-scale training datasets.
  • Explores blockchain and distributed ledger technologies (DLT) as a means to create immutable logs for auditing and securing device communication.
  • Advocates for standardization of security protocols and network architectures to improve compatibility, scalability, and resilience against MitM attacks.
Figure 1: A General Schema of Man-in-the-Middle Attack
Figure 1: A General Schema of Man-in-the-Middle Attack

Experimental results

Research questions

  • RQ1How do Man-in-the-Middle attacks exploit the heterogeneity and unencrypted nature of IoT communications to compromise data confidentiality and integrity?
  • RQ2What are the key limitations of conventional Intrusion Detection Systems (IDS) in detecting MitM attacks within dynamic, resource-constrained IoT environments?
  • RQ3Can hybrid routing with transmission time monitoring effectively detect MitM attacks in large-scale, heterogeneous IoT networks?
  • RQ4How can emerging technologies like machine learning and blockchain be integrated into IoT security frameworks to improve detection and prevention of MitM attacks?
  • RQ5What role should standardization, regulation, and device-level security best practices play in mitigating MitM threats across the IoT ecosystem?

Key findings

  • Approximately 98% of all traffic among IoT devices is unencrypted, significantly increasing the risk of MitM attacks.
  • Traditional IDS solutions often fail to detect MitM attacks due to their stealthy, persistent nature and the complexity of IoT network topologies.
  • Hybrid routing with transmission time anomaly detection can effectively identify MitM attacks by detecting irregular delays caused by attacker-induced traffic rerouting.
  • Static ARP tables provide a viable but impractical defense in large networks due to the high maintenance overhead of manual updates.
  • Future detection systems should leverage deep learning models trained on realistic, large-scale IoT network data to improve detection accuracy and generalization.
  • Standardization of security protocols, integration of blockchain for auditability, and regulatory alignment are critical for long-term mitigation of MitM threats in IoT.
Figure 2: A General View of IoT Devices
Figure 2: A General View of IoT Devices

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.