Return
Zigbee Network Communication Analysis and Security Vulnerability Evaluation
DOI:10.1109/tr.2026.3723186.png)
Abstract
En 中文
Zigbee, characterized by its low-power consumption and flexible network topology, is regarded as an essential wireless communication technology. Large companies are developing Zigbee-related applications and Zigbee-enabled devices. As a paramount concern in Zigbee systems, it is essential to study and analyze the security vulnerabilities. To address the remaining limitations of prior research, such as stringent requirements and limited flexibility, we investigate methods for analyzing Zigbee security vulnerabilities with low requirements and flexible configuration. We develop three test scenarios focusing on Zigbee devices, packets, and communication. Key information extraction or new device injection is not required. To evaluate these scenarios, we design an analysis framework. We use an analyzer device as an external source, generate protocol-compliant packets with semantic-aware content, and test network communication during different operational phases. To evaluate our framework and assess security vulnerabilities across diverse systems, we test eight device systems, encompassing various functions and application environments of Zigbee products. Experimental results demonstrate that victim devices experience failures during the commissioning or suffer connection disruptions, rendering the systems incapable of fulfilling their intended functions. Vulnerabilities, including malfunctions requiring the manual resets to restore functionality and instances of key leakage, are observed in the test. We delve into the root causes of the identified vulnerabilities and provide mitigation strategies.
Keywords:
Cause effect analysis
security
sensors
testing
Zigbee
Journal
IF:
5.7
Papers:
2.7K
Citations:
8.5K

