论文标题
深入了解物联网后端生态系统
Deep Dive into the IoT Backend Ecosystem
论文作者
论文摘要
物联网(IoT)设备变得越来越无处不在,例如在家里,在企业环境中和生产线中。为了支持物联网设备的高级功能,物联网供应商以及服务和云公司运营着物联网后端 - 本文的重点。我们提出了一种方法来识别和通过(a)编译主要物联网后端提供商专门使用的域列表,然后(b)识别其服务器IP地址。我们依靠多种来源,包括物联网后端提供商文档,被动DNS数据和主动扫描。为了分析IoT流量模式,我们依靠来自欧洲主要ISP的被动网络流。 我们的分析着重于最高的物联网后端,并揭示了各种各样的操作策略 - 从经营自己的基础设施到利用公共云。我们发现,大多数顶级物联网后端提供商都位于多个地点和国家。尽管如此,少数人只位于一个国家,这可能会引起监管审查,因为客户IoT设备位于其他地区。确实,我们的分析表明,多达35%的物联网流量与位于其他大洲的物联网后端服务器交换。我们还发现,至少有六个顶级物联网后端依靠其他物联网后端提供商。我们还评估物联网后端提供商之间的级联效应是否可能在发生停电,构造错误或攻击时。
Internet of Things (IoT) devices are becoming increasingly ubiquitous, e.g., at home, in enterprise environments, and in production lines. To support the advanced functionalities of IoT devices, IoT vendors as well as service and cloud companies operate IoT backends -- the focus of this paper. We propose a methodology to identify and locate them by (a) compiling a list of domains used exclusively by major IoT backend providers and (b) then identifying their server IP addresses. We rely on multiple sources, including IoT backend provider documentation, passive DNS data, and active scanning. For analyzing IoT traffic patterns, we rely on passive network flows from a major European ISP. Our analysis focuses on the top IoT backends and unveils diverse operational strategies -- from operating their own infrastructure to utilizing the public cloud. We find that the majority of the top IoT backend providers are located in multiple locations and countries. Still, a handful are located only in one country, which could raise regulatory scrutiny as the client IoT devices are located in other regions. Indeed, our analysis shows that up to 35% of IoT traffic is exchanged with IoT backend servers located in other continents. We also find that at least six of the top IoT backends rely on other IoT backend providers. We also evaluate if cascading effects among the IoT backend providers are possible in the event of an outage, a misconfiguration, or an attack.