{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T02:27:04Z","timestamp":1784082424717,"version":"3.55.0"},"reference-count":38,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T00:00:00Z","timestamp":1641945600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The advancement in the domain of IoT accelerated the development of new communication technologies such as the Message Queuing Telemetry Transport (MQTT) protocol. Although MQTT servers\/brokers are considered the main component of all MQTT-based IoT applications, their openness makes them vulnerable to potential cyber-attacks such as DoS, DDoS, or buffer overflow. As a result of this, an efficient intrusion detection system for MQTT-based applications is still a missing piece of the IoT security context. Unfortunately, existing IDSs do not provide IoT communication protocol support such as MQTT or CoAP to validate crafted or malformed packets for protecting the protocol implementation vulnerabilities of IoT devices. In this paper, we have designed and developed an MQTT parsing engine that can be integrated with network-based IDS as an initial layer for extensive checking against IoT protocol vulnerabilities and improper usage through a rigorous validation of packet fields during the packet-parsing stage. In addition, we evaluate the performance of the proposed solution across different reported vulnerabilities. The experimental results demonstrate the effectiveness of the proposed solution for detecting and preventing the exploitation of vulnerabilities on IoT protocols.<\/jats:p>","DOI":"10.3390\/s22020567","type":"journal-article","created":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T09:10:36Z","timestamp":1641978636000},"page":"567","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":64,"title":["Preventing MQTT Vulnerabilities Using IoT-Enabled Intrusion Detection System"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3253-0140","authenticated-orcid":false,"given":"Muhammad","family":"Husnain","sequence":"first","affiliation":[{"name":"Al-Khwarizmi Institute of Computer Science (KICS), University of Engineering and Technology (UET), Lahore 39161, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2620-109X","authenticated-orcid":false,"given":"Khizar","family":"Hayat","sequence":"additional","affiliation":[{"name":"Al-Khwarizmi Institute of Computer Science (KICS), University of Engineering and Technology (UET), Lahore 39161, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6932-1975","authenticated-orcid":false,"given":"Enrico","family":"Cambiaso","sequence":"additional","affiliation":[{"name":"Consiglio Nazionale delle Ricerche (CNR), IEIIT Institute, 16149 Genoa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7833-6127","authenticated-orcid":false,"given":"Ubaid U.","family":"Fayyaz","sequence":"additional","affiliation":[{"name":"Al-Khwarizmi Institute of Computer Science (KICS), University of Engineering and Technology (UET), Lahore 39161, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6201-6225","authenticated-orcid":false,"given":"Maurizio","family":"Mongelli","sequence":"additional","affiliation":[{"name":"Consiglio Nazionale delle Ricerche (CNR), IEIIT Institute, 16149 Genoa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3305-215X","authenticated-orcid":false,"given":"Habiba","family":"Akram","sequence":"additional","affiliation":[{"name":"Al-Khwarizmi Institute of Computer Science (KICS), University of Engineering and Technology (UET), Lahore 39161, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1835-5531","authenticated-orcid":false,"given":"Syed","family":"Ghazanfar Abbas","sequence":"additional","affiliation":[{"name":"Al-Khwarizmi Institute of Computer Science (KICS), University of Engineering and Technology (UET), Lahore 39161, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1841-5979","authenticated-orcid":false,"given":"Ghalib A.","family":"Shah","sequence":"additional","affiliation":[{"name":"Al-Khwarizmi Institute of Computer Science (KICS), University of Engineering and Technology (UET), Lahore 39161, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,1,12]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Hussain, F., Abbas, S.G., Shah, G.A., Pires, I.M., Fayyaz, U.U., Shahzad, F., Garcia, N.M., and Zdravevski, E. (2021). A Framework for Malicious Traffic Detection in IoT Healthcare Environment. Sensors, 21.","DOI":"10.3390\/s21093025"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Deogirikar, J., and Vidhate, A. (2017, January 10\u201311). Security attacks in IoT: A survey. Proceedings of the 2017 International Conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud) (I-SMAC), Palladam, India.","DOI":"10.1109\/I-SMAC.2017.8058363"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Ronen, E., and Shamir, A. (2016, January 21\u201324). Extended functionality attacks on IoT devices: The case of smart lights. Proceedings of the 2016 IEEE European Symposium on Security and Privacy (EuroS&P), Saarbruecken, Germany.","DOI":"10.1109\/EuroSP.2016.13"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1109\/MC.2017.201","article-title":"DDoS in the IoT: Mirai and other botnets","volume":"50","author":"Kolias","year":"2017","journal-title":"Computer"},{"key":"ref_5","unstructured":"Harat, S., Malczewski, M., Szczotka, A., and Anderson, E.M. (2020). Discovery of IoT Devices. (15\/706,832), U.S. Patent."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"102779","DOI":"10.1016\/j.jnca.2020.102779","article-title":"Security in product lifecycle of IoT devices: A survey","volume":"171","author":"Yousefnezhad","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_7","first-page":"6","article-title":"Consumer IoT: Security vulnerability case studies and solutions","volume":"9","author":"Alladi","year":"2019","journal-title":"IEEE Consum. Electron. Mag."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Wurm, J., Hoang, K., Arias, O., Sadeghi, A.R., and Jin, Y. (2016, January 25\u201328). Security analysis on consumer and industrial IoT devices. Proceedings of the 2016 21st Asia and South Pacific Design Automation Conference (ASP-DAC), Macao, China.","DOI":"10.1109\/ASPDAC.2016.7428064"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"101648","DOI":"10.1016\/j.cose.2019.101648","article-title":"Design and implementation of automated IoT security testbed","volume":"88","author":"Waraga","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"964","DOI":"10.1016\/j.future.2016.11.031","article-title":"Secure integration of IoT and cloud computing","volume":"78","author":"Stergiou","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Hussain, F., Abbas, S.G., Fayyaz, U.U., Shah, G.A., Toqeer, A., and Ali, A. (2020). Towards a Universal Features Set for IoT Botnet Attacks Detection. arXiv.","DOI":"10.21203\/rs.3.rs-114467\/v1"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Tawalbeh, L., Muheidat, F., Tawalbeh, M., and Quwaider, M. (2020). IoT Privacy and security: Challenges and solutions. Appl. Sci., 10.","DOI":"10.3390\/app10124102"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1899","DOI":"10.1109\/JIOT.2017.2707465","article-title":"Security vulnerabilities of internet of things: A case study of the smart plug system","volume":"4","author":"Ling","year":"2017","journal-title":"IEEE Internet Things J."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Williams, R., McMahon, E., Samtani, S., Patton, M., and Chen, H. (2017, January 22\u201324). Identifying vulnerabilities of consumer Internet of Things (IoT) devices: A scalable approach. Proceedings of the 2017 IEEE International Conference on Intelligence and Security Informatics (ISI), Beijing, China.","DOI":"10.1109\/ISI.2017.8004904"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Hong, D.K., Chen, Q.A., and Mao, Z.M. (2017, January 3). An initial investigation of protocol customization. Proceedings of the 2017 Workshop on Forming an Ecosystem around Software Transformation, Dallas, TX, USA.","DOI":"10.1145\/3141235.3141236"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"616","DOI":"10.1109\/COMST.2019.2953364","article-title":"Security of the Internet of Things: Vulnerabilities, attacks, and countermeasures","volume":"22","author":"Butun","year":"2019","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Makhshari, A., and Mesbah, A. (2021, January 22\u201330). IoT bugs and development challenges. Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE), Madrid, Spain.","DOI":"10.1109\/ICSE43902.2021.00051"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Newman, B., and Al-Nemrat, A. (2021). Making the Internet of Things Sustainable: An Evidence Based Practical Approach in Finding Solutions for yet to Be Discussed Challenges in the Internet of Things. Digital Forensic Investigation of Internet of Things (IoT) Devices, Springer.","DOI":"10.1007\/978-3-030-60425-7_11"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Palmieri, A., Prem, P., Ranise, S., Morelli, U., and Ahmad, T. (2019, January 8\u201313). MQTTSA: A tool for automatically assisting the secure deployments of MQTT brokers. Proceedings of the 2019 IEEE World Congress on Services (SERVICES), Milan, Italy.","DOI":"10.1109\/SERVICES.2019.00023"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Araujo Rodriguez, L.G., and Mac\u00eado Batista, D. (2020, January 18\u201322). Program-aware fuzzing for MQTT applications. Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis, Virtual Event.","DOI":"10.1145\/3395363.3402645"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Ghazanfar, S., Hussain, F., Rehman, A.U., Fayyaz, U.U., Shahzad, F., and Shah, G.A. (2020, January 26\u201327). IoT-Flock: An Open-source Framework for IoT Traffic Generation. Proceedings of the 2020 International Conference on Emerging Trends in Smart Technologies (ICETST), Karachi, Pakistan.","DOI":"10.1109\/ICETST49965.2020.9080732"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"164803","DOI":"10.1109\/ACCESS.2019.2953075","article-title":"An Intelligent Communication Warning Vulnerability Detection Algorithm Based on IoT Technology","volume":"7","author":"Yi","year":"2019","journal-title":"IEEE Access"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., and Ghorbani, A.A. (2019, January 1\u20133). Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy. Proceedings of the 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India.","DOI":"10.1109\/CCST.2019.8888419"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"107678","DOI":"10.1109\/ACCESS.2019.2932438","article-title":"Search: A collaborative and intelligent nids architecture for sdn-based cloud iot networks","volume":"7","author":"Nguyen","year":"2019","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Hussain, F., Abbas, S.G., Husnain, M., Fayyaz, U.U., Shahzad, F., and Shah, G.A. (2020). IoT DoS and DDoS Attack Detection using ResNet. arXiv.","DOI":"10.21203\/rs.3.rs-120303\/v1"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Dhakal, S., Jaafar, F., and Zavarsky, P. (2019, January 3\u20135). Private blockchain network for IoT device firmware integrity verification and update. Proceedings of the 2019 IEEE 19th International Symposium on High Assurance Systems Engineering (HASE), Hangzhou, China.","DOI":"10.1109\/HASE.2019.00033"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Shiaeles, S., Kolokotronis, N., and Bellini, E. (2019, January 8\u201313). IoT vulnerability data crawling and analysis. Proceedings of the 2019 IEEE World Congress on Services (SERVICES), Milan, Italy.","DOI":"10.1109\/SERVICES.2019.00028"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1608","DOI":"10.1109\/JPROC.2019.2918437","article-title":"Edge computing security: State of the art and challenges","volume":"107","author":"Xiao","year":"2019","journal-title":"Proc. IEEE"},{"key":"ref_29","first-page":"1","article-title":"A Survey of IIoT Protocols: A Measure of Vulnerability Risk Analysis Based on CVSS","volume":"53","author":"Arrizabalaga","year":"2020","journal-title":"ACM Comput. Surv."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Ling, Z., Liu, K., Xu, Y., Jin, Y., and Fu, X. (2017, January 4\u20138). An end-to-end view of IoT security and privacy. Proceedings of the GLOBECOM 2017\u20142017 IEEE Global Communications Conference, Singapore.","DOI":"10.1109\/GLOCOM.2017.8254011"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1109\/MDAT.2018.2863106","article-title":"Lessons learned from hacking a car","volume":"36","author":"Miller","year":"2019","journal-title":"IEEE Design Test"},{"key":"ref_32","unstructured":"Feng, X., Liao, X., Wang, X., Wang, H., Li, Q., Yang, K., Zhu, H., and Sun, L. (2019, January 14\u201316). Understanding and securing device vulnerabilities through automated bug report analysis. Proceedings of the 28th USENIX Security Symposium, Santa Clara, CA, USA."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1145\/1030194.1015489","article-title":"Shield: Vulnerability-driven network filters for preventing known vulnerability exploits","volume":"34","author":"Wang","year":"2004","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Kasinathan, P., Pastrone, C., Spirito, M.A., and Vinkovits, M. (2013, January 7\u20139). Denial-of-Service detection in 6LoWPAN based Internet of Things. Proceedings of the 2013 IEEE 9th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob), Lyon, France.","DOI":"10.1109\/WiMOB.2013.6673419"},{"key":"ref_35","unstructured":"Sheikh, N.U., Rahman, H., Vikram, S., and AlQahtani, H. (2018). A Lightweight Signature-Based IDS for IoT Environment. arXiv."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1016\/j.is.2016.05.004","article-title":"AUPS: An open source AUthenticated Publish\/Subscribe system for the Internet of Things","volume":"62","author":"Rizzardi","year":"2016","journal-title":"Inf. Syst."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Andy, S., Rahardjo, B., and Hanindhito, B. (2017, January 19\u201321). Attack scenarios and security analysis of MQTT communication protocol in IoT system. Proceedings of the 2017 4th International Conference on Electrical Engineering, Computer Science and Informatics (EECSI), Yogyakarta, Indonesia.","DOI":"10.1109\/EECSI.2017.8239179"},{"key":"ref_38","first-page":"1","article-title":"Secure-MQTT: An efficient fuzzy logic-based approach to detect DoS attack in MQTT protocol for internet of things","volume":"2019","author":"Haripriya","year":"2019","journal-title":"EURASIP J. Wirel. Commun. Netw."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/2\/567\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T14:14:47Z","timestamp":1760364887000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/2\/567"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,12]]},"references-count":38,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,1]]}},"alternative-id":["s22020567"],"URL":"https:\/\/doi.org\/10.3390\/s22020567","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,12]]}}}