Along with the rise of Industry 4.0 and the implementation of IoT in various fields, Bluetooth Low Energy (BLE) has emerged as a very popular communication protocol between these microcontroller-based IoT devices. BLE is characterized by its energy efficiency and its ability to run on resource-constrained microcontrollers. This rapid adoption of IoT devices utilizing BLE has left a security gap in which these devices are vulnerable to different exploits and attacks, particularly considering that BLE is designed to be low energy compared to normal Bluetooth, leaving fewer resources to be used for security. In this thesis, we first explore the architecture of BLE, its underlying mechanisms, and possible limitations to the protocol. We then move into common vulnerabilities and attacks against BLE devices. The thesis covers both passive eavesdropping or sniffing attacks and active ones, such as man-in-the-middle (MITM) attacks. Along with other forms of attacks that affect wireless communication, such as packet injection or denial of service attacks. Finally, the thesis addresses how these common attacks can be mitigated for IoT devices and embedded systems, even if they are resource-constrained. Strategies for securing BLE devices, such as common protocol level mitigations, implementation hardening, and operational security techniques, are covered.

Along with the rise of Industry 4.0 and the implementation of IoT in various fields, Bluetooth Low Energy (BLE) has emerged as a very popular communication protocol between these microcontroller-based IoT devices. BLE is characterized by its energy efficiency and its ability to run on resource-constrained microcontrollers. This rapid adoption of IoT devices utilizing BLE has left a security gap in which these devices are vulnerable to different exploits and attacks, particularly considering that BLE is designed to be low energy compared to normal Bluetooth, leaving fewer resources to be used for security. In this thesis, we first explore the architecture of BLE, its underlying mechanisms, and possible limitations to the protocol. We then move into common vulnerabilities and attacks against BLE devices. The thesis covers both passive eavesdropping or sniffing attacks and active ones, such as man-in-the-middle (MITM) attacks. Along with other forms of attacks that affect wireless communication, such as packet injection or denial of service attacks. Finally, the thesis addresses how these common attacks can be mitigated for IoT devices and embedded systems, even if they are resource-constrained. Strategies for securing BLE devices, such as common protocol level mitigations, implementation hardening, and operational security techniques, are covered.

A Survey of Security Vulnerabilities and Countermeasures in Bluetooth Low Energy (BLE) for Microcontroller-Based IoT Devices

MAHMOUD, OMAR MOHAMED MOHAMED KAMAL ALI
2025/2026

Abstract

Along with the rise of Industry 4.0 and the implementation of IoT in various fields, Bluetooth Low Energy (BLE) has emerged as a very popular communication protocol between these microcontroller-based IoT devices. BLE is characterized by its energy efficiency and its ability to run on resource-constrained microcontrollers. This rapid adoption of IoT devices utilizing BLE has left a security gap in which these devices are vulnerable to different exploits and attacks, particularly considering that BLE is designed to be low energy compared to normal Bluetooth, leaving fewer resources to be used for security. In this thesis, we first explore the architecture of BLE, its underlying mechanisms, and possible limitations to the protocol. We then move into common vulnerabilities and attacks against BLE devices. The thesis covers both passive eavesdropping or sniffing attacks and active ones, such as man-in-the-middle (MITM) attacks. Along with other forms of attacks that affect wireless communication, such as packet injection or denial of service attacks. Finally, the thesis addresses how these common attacks can be mitigated for IoT devices and embedded systems, even if they are resource-constrained. Strategies for securing BLE devices, such as common protocol level mitigations, implementation hardening, and operational security techniques, are covered.
2025
A Survey of Security Vulnerabilities and Countermeasures in Bluetooth Low Energy (BLE) for Microcontroller-Based IoT Devices
Along with the rise of Industry 4.0 and the implementation of IoT in various fields, Bluetooth Low Energy (BLE) has emerged as a very popular communication protocol between these microcontroller-based IoT devices. BLE is characterized by its energy efficiency and its ability to run on resource-constrained microcontrollers. This rapid adoption of IoT devices utilizing BLE has left a security gap in which these devices are vulnerable to different exploits and attacks, particularly considering that BLE is designed to be low energy compared to normal Bluetooth, leaving fewer resources to be used for security. In this thesis, we first explore the architecture of BLE, its underlying mechanisms, and possible limitations to the protocol. We then move into common vulnerabilities and attacks against BLE devices. The thesis covers both passive eavesdropping or sniffing attacks and active ones, such as man-in-the-middle (MITM) attacks. Along with other forms of attacks that affect wireless communication, such as packet injection or denial of service attacks. Finally, the thesis addresses how these common attacks can be mitigated for IoT devices and embedded systems, even if they are resource-constrained. Strategies for securing BLE devices, such as common protocol level mitigations, implementation hardening, and operational security techniques, are covered.
Bluetooth Low Energy
IoT Devices
IoT Security
File in questo prodotto:
File Dimensione Formato  
Mahmoud_OmarMohamedMohamedKamalAli.pdf

accesso aperto

Dimensione 1.7 MB
Formato Adobe PDF
1.7 MB Adobe PDF Visualizza/Apri

The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.12608/114274