Attack simulation on commercial IoT systems

Authors

  • Kristjan Brataševec Univerza v Ljubljani, Fakulteta za računalništvo in informatiko
  • Matevž Pesek Univerza v Ljubljani, Fakulteta za računalništvo in informatiko

DOI:

https://doi.org/10.31449/upinf.252

Keywords:

attack defence, DoS attacks, IoT, poor authentication attacks, reply attacks

Abstract

Internet of Things (IoT) defines smart devices with sensors and software that connect to other devices and systems for data analysis, control and automation purposes. Examples of such devices include smart lights, smart washers, dryers, dishwashers, thermostats, home security cameras, and others, most of which can be easily controlled via mobile applications. Due to the affordability and increasing prevalence of these devices, problems related to incomplete data sets and the absence of automated updates are also becoming more common, which is a key security and functional factor for devices that are constantly connected to the Internet. Attackers can exploit such security flaws to unlawfully collect personal data, disable devices, or misuse their computing power to build larger networks of infected devices (botnets).
The article discusses critical device problems through various attacks and their scope, as well as strategies for managing and preventing IoT attacks. It also analyzes major past attacks, and using widely available devices such as smart light bulbs and ventilation systems to demonstrate the ease of attack implementation. The paper also critically evaluates the current trend of replacing simple devices with "smart" versions, which, due to increased complexity and inadequate security design, is becoming an increasingly challenging and difficult-to-manage security issue in the modern digital environment.

Author Biographies

Kristjan Brataševec, Univerza v Ljubljani, Fakulteta za računalništvo in informatiko

Kristjan Brataševec je študent na Fakulteti za računalništvo in informatiko Univerze v Ljubljani. Zanima se za področje kibernetske varnosti in razvoja programske opreme, še posebej za vsakodnevno uporabo. Posveča se ustvarjanju varnih celovitih aplikacijskih sistemov, tako z vidika programske kode, kot s sistemskega in omrežnega vidika.

Matevž Pesek, Univerza v Ljubljani, Fakulteta za računalništvo in informatiko

Matevž Pesek je izredni profesor in raziskovalec na Fakulteti za računalništvo in informatiko Univerze v Ljubljani, kjer je diplomiral (2012) in doktoriral (2018). Od leta 2009 je član Laboratorija za računalniško grafiko in multimedije. Od leta 2024 izvaja predmeta Varnost programov in Varnost sistemov, kjer se raziskovalno ukvarja s poučevanjem konceptov in organizacijo dogodkov s področja računalniške varnosti.

Published

2025-09-25

How to Cite

[1]
Brataševec, K. and Pesek, M. 2025. Attack simulation on commercial IoT systems. Applied Informatics. (Sep. 2025). DOI:https://doi.org/10.31449/upinf.252.

Issue

Section

Scientific articles

Most read articles by the same author(s)