Location Research Breakthrough Possible @S-Logix pro@slogix.in

Restricting Unauthorized MQTT Command Injection Against IoT Devices Through Protocol-Level Message Validation and Real-Time Security Monitoring

Description

Modern IoT environments use lightweight messaging protocols such as MQTT (Message Queuing Telemetry Transport) to exchange commands, sensor data, and device-status information between IoT devices and backend applications.

MQTT is widely used in smart-home systems, industrial IoT environments, connected devices, and real-time monitoring systems because of its lightweight publish/subscribe communication model.

However, insecure MQTT topic permissions and insufficient message validation can allow an unauthorized client to publish malicious or unauthorized commands to IoT devices.

In this use case, Eclipse Mosquitto is deployed as the MQTT broker and Node-RED is used as the IoT application for simulating device control and monitoring. The environment is hosted on Ubuntu Linux inside an isolated VirtualBox laboratory.

A controlled unauthorized MQTT command-injection scenario is performed from Kali Linux using open-source MQTT client utilities.

The assessment evaluates whether an unauthorized MQTT client can publish a crafted command to a device-control topic and whether the IoT environment correctly identifies and prevents unauthorized commands.

Wireshark is used to analyze MQTT network traffic. Wazuh is used for security monitoring, while OpenSearch is used for centralized investigation and event correlation.

After identifying the weakness, MQTT topic access controls and message-validation mechanisms are strengthened. The same controlled attack is then repeated to verify that unauthorized commands are rejected while legitimate IoT communication continues to function.

Existing Security Problem

Application: Node-RED IoT Application

Node-RED is used as the IoT application in this project.

Existing Problem:

MQTT uses topics to organize communication between publishers and subscribers. If MQTT topic permissions are incorrectly configured, an unauthorized client may be able to publish messages to a device-command topic. If the receiving application also fails to validate the message content, an unauthorized command may be processed by the simulated IoT device.

The security problem is therefore:

Unauthorized MQTT Client → MQTT Broker → Insufficient Topic Access Control → Malicious / Unauthorized Command → Node-RED IoT Application → Command Accepted → IoT Device Behavior Changed

Attack

Specific Attack: Unauthorized MQTT Command Injection

The controlled attack evaluates whether an unauthorized MQTT client can publish a crafted command to an IoT device-control topic. The attack is performed only against the locally deployed laboratory environment. No real IoT devices or production MQTT infrastructure are involved.

Attack Behavior:
Kali Linux
→
Unauthorized MQTT Client
→
MQTT Command Topic
→
Eclipse Mosquitto
→
Weak Topic Authorization
→
Crafted MQTT Command
→
Node-RED IoT Application
→
Command Processing
→
Unauthorized Device Action
→
Wazuh Detection
→
OpenSearch Investigation
→
Access-Control + Message Validation Remediation
→
Retesting
→
Unauthorized Command Rejected

Security Concept

MQTT Topic Security and IoT Command Validation:

The primary security concept is secure MQTT communication and command authorization.

IoT devices should process commands only when the message originates from an authorized MQTT client and the command satisfies the application's validation requirements.

The secure processing flow is:

MQTT Client
→
Authentication
→
Topic Authorization
→
Message Validation
→
Command Authorization
→
IoT Device

Defensive Mechanism

MQTT Client Authentication

Require authentication for MQTT clients connecting to protected topics.

Purpose

Prevent unidentified clients from communicating with protected IoT services.

MQTT Topic Access Control

Restrict which clients can publish or subscribe to specific MQTT topics.

Purpose

Prevent unauthorized clients from publishing commands to device-control topics.

Least-Privilege Topic Permissions

Assign only the MQTT permissions required by each IoT component.

Purpose

Reduce the impact of compromised or unauthorized clients.

MQTT Message Validation

Validate incoming MQTT commands before processing them.

Purpose

Prevent malformed or unauthorized command messages from being processed.

Command Allowlisting

Allow only predefined commands and acceptable parameter values.

Purpose

Prevent commands from being redirected toward unintended devices.

Secure MQTT Communication

Use the secure communication mechanisms supported by the MQTT deployment.

Purpose

Protect MQTT communication from unauthorized network access.

Security Monitoring

Monitor MQTT and IoT application activity.

Purpose

Detect suspicious publishing behavior and unauthorized commands.

Network Traffic Analysis

Analyze MQTT communication within the controlled environment.

Purpose

Identify abnormal publishing and command activity.

Centralized Investigation

Use Wazuh and OpenSearch to correlate security events.

Purpose

Investigate unauthorized MQTT activity and establish the attack timeline.

Security Tools

Target IoT Application: Node-RED

Node-RED is used as the real open-source IoT application.

Purpose
  • Create IoT workflows.
  • Communicate with the MQTT broker.
  • Receive device commands.
  • Simulate IoT device behavior.
  • Provide a controlled IoT environment.

MQTT Broker: Eclipse Mosquitto

Eclipse Mosquitto is used as the MQTT broker.

Purpose
  • Receive MQTT connections.
  • Manage MQTT topics.
  • Forward published messages.
  • Enforce MQTT authentication and authorization.
  • Provide the communication layer between MQTT clients and Node-RED.

MQTT Testing Tool: Mosquitto Clients

The open-source Mosquitto client utilities are used from Kali Linux.

Purpose
  • Connect to the MQTT broker.
  • Publish controlled MQTT messages.
  • Subscribe to MQTT topics.
  • Test topic permissions.
  • Simulate an unauthorized MQTT client.

Network Analysis Tool: Wireshark

Wireshark is used to analyze MQTT traffic.

Purpose
  • Capture MQTT communication.
  • Identify publishers and subscribers.
  • Analyze MQTT topics where observable.
  • Compare normal and unauthorized traffic.
  • Support post-remediation validation.

Security Monitoring Tool: Wazuh

Wazuh is used for security monitoring.

Purpose
  • Monitor Ubuntu activity.
  • Monitor MQTT-related logs.
  • Collect security events.
  • Detect suspicious activity.
  • Support security-event investigation.

Investigation Platform: OpenSearch

OpenSearch is used to investigate Wazuh security events.

Purpose
  • Search security events.
  • Correlate MQTT-related activity.
  • Review timestamps.
  • Investigate unauthorized publishing.
  • Establish an attack timeline.

Security Testing Platform: Kali Linux

Kali Linux is used as the authorized security-testing environment.

Purpose
  • Run MQTT client utilities.
  • Perform controlled MQTT testing.
  • Capture network traffic.
  • Perform security validation.
  • Test the remediated configuration.

Target Platform: Ubuntu Linux

Ubuntu hosts the IoT environment.

Purpose
  • Run Eclipse Mosquitto.
  • Run Node-RED.
  • Maintain MQTT configuration.
  • Generate application activity.
  • Support security monitoring.

Virtualization Platform: VirtualBox

VirtualBox provides the isolated cybersecurity laboratory.

Purpose
  • Host Ubuntu.
  • Host Kali Linux.
  • Provide isolated networking.
  • Maintain a reproducible IoT security environment.

Process

STEP 01

Prepare the Isolated IoT Security Laboratory

  • Install VirtualBox.
  • Create an Ubuntu virtual machine.
  • Create a Kali Linux virtual machine.
  • Configure an isolated virtual network.
  • Assign laboratory IP addresses.
  • Verify connectivity between the virtual machines.
  • Ensure the environment is isolated from production networks.
Tools: VirtualBox + Ubuntu + Kali Linux
STEP 02

Deploy Eclipse Mosquitto

  • Install Eclipse Mosquitto on Ubuntu.
  • Start the MQTT broker.
  • Verify that the broker is running.
  • Configure the required MQTT listener.
  • Verify connectivity from Kali Linux.
  • Establish the MQTT communication baseline.
Tools: Eclipse Mosquitto
STEP 03

Deploy the Node-RED IoT Application

  • Install Node-RED on Ubuntu.
  • Start the Node-RED service.
  • Access the Node-RED interface.
  • Create the IoT workflow.
  • Configure MQTT communication with Mosquitto.
  • Verify that Node-RED receives MQTT messages.
Tools: Node-RED + Eclipse Mosquitto
STEP 04

Create the Simulated IoT Device

  • Create a Node-RED flow representing a controlled IoT device.
  • Create device-status topics.
  • Create a device-command topic.
  • Configure normal device commands.
  • Verify that authorized commands produce the expected simulated device behavior.
Tools: Node-RED
STEP 05

Establish Normal MQTT Communication

  • Create an authorized MQTT client.
  • Connect the client to Mosquitto.
  • Publish legitimate device commands.
  • Verify that Node-RED receives the commands.
  • Confirm that the simulated IoT device processes legitimate commands.
  • Record the normal MQTT behavior.
Tools: Eclipse Mosquitto + Node-RED + Mosquitto Clients
STEP 06

Configure MQTT Topic Permissions

  • Define the required MQTT topics.
  • Identify publishers and subscribers.
  • Configure client permissions.
  • Restrict command-topic publishing to authorized clients.
  • Verify legitimate client access.
  • Establish the secure baseline configuration.
Tools: Eclipse Mosquitto
STEP 07

Capture Normal MQTT Traffic

  • Start Wireshark on the laboratory network interface.
  • Generate legitimate MQTT communication.
  • Publish normal device commands.
  • Capture the MQTT traffic.
  • Stop the packet capture.
  • Preserve the capture for comparison.
Tools: Wireshark + Eclipse Mosquitto
STEP 08

Introduce the Controlled MQTT Access Weakness

  • Within the isolated laboratory, temporarily weaken MQTT topic authorization.
  • Allow the unauthorized test client to interact with the command topic.
  • Record the secure configuration before changing it.
  • Record the intentionally weakened configuration.
  • Verify the changed configuration.
  • The purpose is to safely reproduce an MQTT access-control weakness.
Tools: Eclipse Mosquitto
STEP 09

Perform the Controlled MQTT Command-Injection Test

  • Using the unauthorized MQTT test client, connect to the laboratory MQTT broker.
  • Attempt to publish a controlled command to the device-command topic.
  • Use only laboratory test commands.
  • Observe whether Node-RED receives the message.
  • Record the resulting device behavior.
Tools: Kali Linux + Mosquitto Clients + Eclipse Mosquitto + Node-RED
STEP 10

Analyze the MQTT Network Activity

  • Capture the unauthorized MQTT activity using Wireshark.
  • Identify the MQTT connection.
  • Identify the publishing behavior.
  • Compare unauthorized traffic with normal authorized traffic.
  • Document the observed behavior.
  • Preserve the laboratory packet capture.
Tools: Wireshark
STEP 11

Analyze the IoT Application Behavior

  • Using Node-RED, review the MQTT message received by the IoT workflow.
  • Determine whether the unauthorized command reached the application.
  • Observe the simulated device behavior.
  • Compare legitimate and unauthorized commands.
  • Document the security impact.
Tools: Node-RED
STEP 12

Configure Security Monitoring

  • Identify relevant Mosquitto and Ubuntu logs.
  • Configure Wazuh monitoring.
  • Generate normal MQTT activity.
  • Generate the controlled unauthorized publishing attempt.
  • Verify that Wazuh receives the relevant telemetry.
  • Review the collected events.
Tools: Wazuh
STEP 13

Detect the Unauthorized MQTT Activity

  • Review Wazuh events.
  • Identify the unauthorized MQTT activity where observable.
  • Review the event timestamp.
  • Identify the affected MQTT broker.
  • Correlate related events.
  • Preserve the security evidence.
Tools: Wazuh
STEP 14

Investigate the Attack Activity

  • Open the relevant Wazuh events in OpenSearch.
  • Search for MQTT-related activity.
  • Review timestamps.
  • Correlate MQTT broker and system events.
  • Identify the sequence of the unauthorized publishing attempt.
  • Establish the attack timeline.
Tools: Wazuh + OpenSearch
STEP 15

Assess the Security Risk

  • Evaluate MQTT authentication.
  • Evaluate topic permissions.
  • Evaluate publisher authorization.
  • Evaluate command-message validation.
  • Evaluate unauthorized command behavior.
  • Evaluate simulated device impact.
  • Evaluate monitoring visibility.
  • Evaluate potential IoT security impact.
  • Evaluate remediation requirements.
  • Document the security finding and assign an appropriate risk level.
Tools: Eclipse Mosquitto + Node-RED + Wireshark + Wazuh + OpenSearch
STEP 16

Remediate MQTT Command Access

  • Restore the secure MQTT configuration.
  • Require authentication for protected MQTT clients.
  • Restrict publishing to device-command topics.
  • Apply least-privilege topic permissions.
  • Implement command/message validation in the Node-RED workflow.
  • Allow only approved command values.
  • Reject unauthorized or invalid commands.
  • Verify the corrected configuration.
Tools: Eclipse Mosquitto + Node-RED
STEP 17

Retest Unauthorized and Authorized MQTT Commands

  • Unauthorized Command Retest: Use the unauthorized test client.
  • Attempt to publish to the protected command topic.
  • Verify that the broker rejects the unauthorized publishing attempt or the application rejects the command.
  • Record the result.
  • Authorized Command Retest: Use the authorized MQTT client.
  • Publish a legitimate device command.
  • Verify that Node-RED receives the command.
  • Verify that the simulated IoT device continues to function correctly.
Tools: Kali Linux + Mosquitto Clients + Eclipse Mosquitto + Node-RED
STEP 18

Perform Final IoT Security Validation

  • Review the original MQTT configuration.
  • Review the controlled command-injection evidence.
  • Review Wireshark traffic analysis.
  • Review Node-RED application behavior.
  • Review Wazuh security events.
  • Review OpenSearch investigation results.
  • Verify MQTT topic authorization.
  • Verify command-message validation.
  • Confirm unauthorized MQTT commands are rejected.
  • Confirm legitimate IoT communication continues to function.
  • Document the final Emerging Technology Security assessment.
Tools: Eclipse Mosquitto + Node-RED + Mosquitto Clients + Wireshark + Wazuh + OpenSearch + Kali Linux

Outcome

  1. Eclipse Mosquitto is successfully deployed as the open-source MQTT broker within an isolated Ubuntu-based IoT security laboratory.
  2. Node-RED is successfully configured as the real open-source IoT application with a simulated IoT device and MQTT-based command workflow.
  3. A controlled unauthorized MQTT command-injection scenario is successfully simulated using open-source MQTT client utilities from Kali Linux.
  4. Wireshark successfully captures and analyzes normal and unauthorized MQTT communication within the controlled laboratory.
  5. Wazuh successfully monitors relevant MQTT broker and Ubuntu activity and provides security-event visibility.
  6. OpenSearch successfully supports centralized investigation and correlation of MQTT-related security events.
  7. The identified MQTT topic-access weakness is remediated through client authentication, least-privilege topic authorization, and command/message validation.
  8. Post-remediation testing confirms that unauthorized MQTT clients cannot successfully publish commands to protected IoT command topics.
  9. Authorized MQTT clients continue to publish legitimate commands and the simulated IoT device continues to function normally after remediation.
  10. The complete MQTT security assessment, unauthorized command-injection simulation, detection, network analysis, investigation, access-control remediation, message validation, and post-remediation validation is successfully demonstrated as an Emerging Technology Security use case.