TY - GEN
T1 - PENTOS
T2 - 2017 IEEE Region 10 Conference, TENCON 2017
AU - Visoottiviseth, Vasaka
AU - Akarasiriwong, Phuripat
AU - Chaiyasart, Siravitch
AU - Chotivatunyu, Siravit
N1 - Publisher Copyright:
© 2017 IEEE.
PY - 2017/12/19
Y1 - 2017/12/19
N2 - The Internet of Thing (IoT) technology has been growing rapidly with many implementations. However, because of its ability to perform tasks and handle the sensitive information and also the paucity of user security awareness, IoT devices contain many potential risks and are the new target of attacks. In this paper, we develop a penetration testing system for IoT devices called PENTOS in order to increase the user security awareness. The system comes with the GUI running on Kali Linux which is specifically designed for ethical hacking. PENTOS automatically gathers the information of the target IoT device through the wireless communication, which are WiFi and Bluetooth. The system allows users to perform various kinds of penetration testing on their IoT devices such as the password attack, web attack, and wireless attack in order to gain the privilege access by multiple algorithms. Moreover, the system also provides the basic security guidance according to the OWASP's Top 10 IoT Vulnerabilities to educate users and increase the security awareness. After the penetration testing, the system then summarizes the results of all attacking modules and gives the recommendations for the secure deployment to avoid possible threats.
AB - The Internet of Thing (IoT) technology has been growing rapidly with many implementations. However, because of its ability to perform tasks and handle the sensitive information and also the paucity of user security awareness, IoT devices contain many potential risks and are the new target of attacks. In this paper, we develop a penetration testing system for IoT devices called PENTOS in order to increase the user security awareness. The system comes with the GUI running on Kali Linux which is specifically designed for ethical hacking. PENTOS automatically gathers the information of the target IoT device through the wireless communication, which are WiFi and Bluetooth. The system allows users to perform various kinds of penetration testing on their IoT devices such as the password attack, web attack, and wireless attack in order to gain the privilege access by multiple algorithms. Moreover, the system also provides the basic security guidance according to the OWASP's Top 10 IoT Vulnerabilities to educate users and increase the security awareness. After the penetration testing, the system then summarizes the results of all attacking modules and gives the recommendations for the secure deployment to avoid possible threats.
KW - Ethical hacking
KW - Internet of Things
KW - Kali linux
KW - Penetration testing
KW - Raspberry Pi
UR - https://www.scopus.com/pages/publications/85044187794
U2 - 10.1109/TENCON.2017.8228241
DO - 10.1109/TENCON.2017.8228241
M3 - Conference contribution
AN - SCOPUS:85044187794
T3 - IEEE Region 10 Annual International Conference, Proceedings/TENCON
SP - 2279
EP - 2284
BT - TENCON 2017 - 2017 IEEE Region 10 Conference
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 5 November 2017 through 8 November 2017
ER -