Zigbee's wireless security flaws threatens IoT devices

10 August 2015
By James Hayes
Mobile version
Share |
Cognosec's Tobias Zillner [R] and Sebastian Strobl [L], whose research uncovered the ZigBee vulnerability

Cognosec's Tobias Zillner [R] and Sebastian Strobl [L], whose research uncovered the ZigBee vulnerability

The ZigBee wireless communications specification used by many Internet of Things (IoT) devices contains critical security flaws, IT firm Cognosec has claimed.

Speaking at the Black Hat USA conference in Las Vegas recently, Cognosec senior IS auditor Tobias Zillner named the principle security risks in ZigBee implementations, revealed which devices are affected by them and demonstrated practical exploitations of actual product vulnerabilities.

Conducting real-world assessments on identified vulnerabilities, Cognosec found that it is possible to compromise ZigBee networks and thereby take control of connected devices on a network. Smart home devices such as lights, motion sensors, temperature sensors and even door locks, for example, could be compromised via such vulnerabilities, Zillner warned.

First standardised in 2003, the ZigBee specification was developed to enable secure wireless communication for a range of IoT devices; however, low per-unit-costs, interoperability and compatibility requirements, along with the application of legacy security concepts, has resulted in persistent known security risks, said Zillner.

"The key to communicating between devices on a ZigBee network is the usage of 'application profiles'. ZigBee home automation profiles permit a series of device types to exchange
control messages to form a wireless home automation application," Zillner explained in his Black Hat presentation. "These devices are designed to exchange well-known messages to effect control, such as turning a lamp on or off, sending a light sensor measurement to a lighting controller, or sending an alert message if an occupancy sensor detects movement."

Vendors wanting a device to be compatible to other certified devices from other manufacturers have to implement the standard interfaces and practices of this profile, Zillner added: "However, the use of a default link key introduces a high risk to the secrecy of the network key. As the security of ZigBee is reliant on the secrecy of the key material - and therefore on the secure initialisation and transport of the encryption keys - this default fallback mechanism has to be considered as a critical risk."

As a result the ZigBee specification "requires that an insecure initial key transport has to be supported, making it possible to compromise ZigBee networks, and take control of all connected devices on the network,” Zillner argued. The practical security analysis of devices Cognosec assessed indicated that the solutions are designed for easy set-up and usage, "but lack configuration possibilities for security, and [also] perform a vulnerable device pairing procedure that allows external parties to 'sniff' the exchanged network key... This represents a critical vulnerability, as the security of the solution is reliant on the secrecy of this network key”.

One use case Zillner highlighted was of external parties able to gain control over home automation systems, which have high privacy requirements, and as such can be a source of personalised data. Cognosec tests with light bulbs, motion and temperature sensors and door locks also showed that the vendors of the tested devices implemented the minimum of the features required to be certified; no other options to raise the level of security were implemented and available to the end-user, the company asserted.

“The shortcomings and limitations we have discovered in ZigBee have been created by [vendors wanting] to create the latest and greatest products – which these days means they are likely to be Internet-connected,” according to Cognosec's Zillner. “Simple units such as light switches have to be compatible with a host of other devices and [therefore] little consideration is made to security requirements – most likely to keep costs down.”

Cognosec has published its findings in a Zigbee security white paper.

Further information

https://www.cognosec.com

https://www.blackhat.com/us-15/

Latest Issue

E&T cover image 1607

"As the dust settles after the referendum result, we consider what happens next. We also look forward to an international summer of sport."

E&T jobs

  • Control System Engineer

    United Utilities
    • Lancaster, Lancashire
    • Up to £33415 + Comprehensive Benefits

    Provide ICA maintenance and engineering support to the Water & Wastewater Production

    • Recruiter: United Utilities

    Apply for this job

  • Signal Processing Engineer

    B&W Group
    • Steyning, West Sussex
    • Competitive Salary

    We are looking for a Signal Processing Engineer to support the R&D process on active loudspeaker products.

    • Recruiter: B&W Group

    Apply for this job

  • Principal Mechanical & Electrical Engineer

    De Montfort University
    • Leicestershire
    • Grade G: £36,672 - £46,414 per annum

    Join the Projects Team to develop and manage medium to large projects on the university estate.

    • Recruiter: De Montfort University

    Apply for this job

  • Advanced Commissioning Engineer

    National Grid
    • Nottinghamshire, Nottingham, England
    • £46000 - £57000 per year

    National Grid is at the heart of energy in the UK. The electricity we provide gets the nation to work, powers schools and lights everyone's way home. Our energy network connects the nation, so it's essential that it's continually evolving, advancing and i

    • Recruiter: National Grid

    Apply for this job

  • Electrical Design Engineer

    Oxford Instruments
    • Yatton, Bristol
    • Competitive salary plus excellent benefits

    We are looking for an electrical designer to join our engineering design team.

    • Recruiter: Oxford Instruments

    Apply for this job

  • Skilled Electrical Fitter

    MBDA
    • Bolton
    • Competitive Salary & Benefits

    What?s the opportunity?   The Electrical Fitter will carry out manufacturing and test tasks within the electrical department in accordance with product certification procedures, defined workmanship  ...

    • Recruiter: MBDA

    Apply for this job

  • Electrical Manufacturing Technician

    MBDA
    • Stevenage
    • Competitive Salary & Benefits

    What?s the opportunity?   As a qualified craftsman with experience in electrical manufacturing, the Manufacturing Technician will report to a Team Leader, receiving day to day ...

    • Recruiter: MBDA

    Apply for this job

  • Consultant Engineer (Electrical Power)

    BAE Systems
    • Cumbria, Barrow-In-Furness, England
    • Negotiable

    Consultant Engineer (Electrical Power) Would you like to play a key role in providing technical direction to the design of power systems on the Successor class submarines, which will replace the current Trident-equipped Vanguard class, currently in servic

    • Recruiter: BAE Systems

    Apply for this job

  • Supply Restoration Team Manager (HV/SAP)

    SSE
    • Oxford, Oxfordshire
    • Salary: £37,588 to £49,645 + Car (SSE8) Depending on skills and experience

    SSE is looking to recruit a Supply Restoration Team Manager to join our existing team in Oxford.

    • Recruiter: SSE

    Apply for this job

  • Electrical Technical Lead - Global Operations, Engineering & Laboratory

    Pfizer Ltd
    • Kent

    An exciting opportunity has arisen to join a dynamic team of professional engineers, supporting the development of novel drugs.

    • Recruiter: Pfizer Ltd

    Apply for this job

More jobs ▶

Subscribe

Choose the way you would like to access the latest news and developments in your field.

Subscribe to E&T