Piping Botnet - Turning Green Technology into a Water Disaster

by   Ben Nassi, et al.

The current generation of IoT devices is being used by clients and consumers to regulate resources (such as water and electricity) obtained from critical infrastructure (such as urban water services and smart grids), creating a new attack vector against critical infrastructure. In this research we show that smart irrigation systems, a new type of green technology and IoT device aimed at saving water and money, can be used by attackers as a means of attacking urban water services. We present a distributed attack model that can be used by an attacker to attack urban water services using a botnet of commercial smart irrigation systems. Then, we show how a bot running on a compromised device in a LAN can:(1) detect a connected commercial smart irrigation system (RainMachine, BlueSpray, and GreenIQ) within 15 minutes by analyzing LAN's behavior using a dedicated classification model, and (2) launch watering via a commercial smart irrigation system according to an attacker's wishes using spoofing and replay attacks. In addition, we model the damage that can be caused by performing such an attack and show that a standard water tower can be emptied in an hour using a botnet of 1,355 sprinklers and a flood water reservoir can be emptied overnight using a botnet of 23,866 sprinklers. Finally, we discuss countermeasure methods and hypothesize whether the next generation of plumbers will use Kali Linux instead of a monkey wrench.


page 5

page 8

page 10

page 12


The Dark (and Bright) Side of IoT: Attacks and Countermeasures to Identification of Smart Home Devices and Services

We present a new machine learning-based attack that exploits network pat...

iTieProbe: Is Your IoT Setup Secure against (Modern) Evil Twin?

Evil twin attack on Wi-Fi network has been a challenging security proble...

A Tutorial on Resilience in Smart Grids

A key quality of any kind of system is its ability to deliver its respec...

Assessing the Effectiveness of Attack Detection at a Hackfest on Industrial Control Systems

A hackfest named SWaT Security Showdown (S3) has been organized consecut...

Smart IoT-Biofloc water management system using Decision regression tree

The conventional fishing industry has several difficulties: water contam...

Development and analysis of a Bayesian water balance model for large lake systems

Water balance models are often employed to improve understanding of driv...

Design of Economical Fuzzy Logic Controller for Washing Machine

Things are becoming more advanced as technology advances, and machines n...

Please sign up or login with your details

Forgot password? Click here to reset