Vulnerabilities and Attacks in Bluetooth: a Survey
-
Abstract
Bluetooth is a short-range wireless communication technology widely used for commands and data exchange among billions of mobile, wearable, and IoT devices. Despite significant improvements in Bluetooth security mechanisms with the upgrade of the Bluetooth Specification, various security vulnerabilities have continued to be discovered over the past few decades, leading to attacks that impact a huge number of devices. In contrast to the enthusiasm for research on specific Bluetooth security issues, a systematic understanding of this field is still lacking, especially concerning the security and privacy properties of different versions and features, including both Bluetooth Classic and Bluetooth Low Energy. This gap hinders the development of a systematic methodology in Bluetooth security research. In this paper, we review the evolution of the Bluetooth Specification and its security mechanisms over the past two decades. We then systematically provide a comprehensive summary of more than 100 vulnerabilities and attacks in Bluetooth communication using our well-defined taxonomy. Through this taxonomy, we categorize vulnerabilities and attacks based on affected system levels and locations in the Bluetooth protocols and stack. We also offer insights into the strengths and limitations of these attacks. Based on our systematic review, we propose promising directions to inspire future research in Bluetooth security.
-
-