MQTT Client Authentication
Require authentication for MQTT clients connecting to protected topics.
Prevent unidentified clients from communicating with protected IoT services.
Modern IoT environments use lightweight messaging protocols such as MQTT (Message Queuing Telemetry Transport) to exchange commands, sensor data, and device-status information between IoT devices and backend applications.
MQTT is widely used in smart-home systems, industrial IoT environments, connected devices, and real-time monitoring systems because of its lightweight publish/subscribe communication model.
However, insecure MQTT topic permissions and insufficient message validation can allow an unauthorized client to publish malicious or unauthorized commands to IoT devices.
In this use case, Eclipse Mosquitto is deployed as the MQTT broker and Node-RED is used as the IoT application for simulating device control and monitoring. The environment is hosted on Ubuntu Linux inside an isolated VirtualBox laboratory.
A controlled unauthorized MQTT command-injection scenario is performed from Kali Linux using open-source MQTT client utilities.
The assessment evaluates whether an unauthorized MQTT client can publish a crafted command to a device-control topic and whether the IoT environment correctly identifies and prevents unauthorized commands.
Wireshark is used to analyze MQTT network traffic. Wazuh is used for security monitoring, while OpenSearch is used for centralized investigation and event correlation.
After identifying the weakness, MQTT topic access controls and message-validation mechanisms are strengthened. The same controlled attack is then repeated to verify that unauthorized commands are rejected while legitimate IoT communication continues to function.
Node-RED is used as the IoT application in this project.
MQTT uses topics to organize communication between publishers and subscribers. If MQTT topic permissions are incorrectly configured, an unauthorized client may be able to publish messages to a device-command topic. If the receiving application also fails to validate the message content, an unauthorized command may be processed by the simulated IoT device.
The security problem is therefore:
The controlled attack evaluates whether an unauthorized MQTT client can publish a crafted command to an IoT device-control topic. The attack is performed only against the locally deployed laboratory environment. No real IoT devices or production MQTT infrastructure are involved.
The primary security concept is secure MQTT communication and command authorization.
IoT devices should process commands only when the message originates from an authorized MQTT client and the command satisfies the application's validation requirements.
The secure processing flow is:
Require authentication for MQTT clients connecting to protected topics.
Prevent unidentified clients from communicating with protected IoT services.
Restrict which clients can publish or subscribe to specific MQTT topics.
Prevent unauthorized clients from publishing commands to device-control topics.
Assign only the MQTT permissions required by each IoT component.
Reduce the impact of compromised or unauthorized clients.
Validate incoming MQTT commands before processing them.
Prevent malformed or unauthorized command messages from being processed.
Allow only predefined commands and acceptable parameter values.
Prevent commands from being redirected toward unintended devices.
Use the secure communication mechanisms supported by the MQTT deployment.
Protect MQTT communication from unauthorized network access.
Monitor MQTT and IoT application activity.
Detect suspicious publishing behavior and unauthorized commands.
Analyze MQTT communication within the controlled environment.
Identify abnormal publishing and command activity.
Use Wazuh and OpenSearch to correlate security events.
Investigate unauthorized MQTT activity and establish the attack timeline.
Node-RED is used as the real open-source IoT application.
Eclipse Mosquitto is used as the MQTT broker.
The open-source Mosquitto client utilities are used from Kali Linux.
Wireshark is used to analyze MQTT traffic.
Wazuh is used for security monitoring.
OpenSearch is used to investigate Wazuh security events.
Kali Linux is used as the authorized security-testing environment.
Ubuntu hosts the IoT environment.
VirtualBox provides the isolated cybersecurity laboratory.