РОЗШИРЕНА МОДЕЛЬ ЗАГРОЗ STRIDE ДЛЯ ОФЛАЙН-ЗАСТОСУНКІВ АВАРІЙНОГО ЗВ'ЯЗКУ НА ОСНОВІ BLE MESH-МЕРЕЖ
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1368Ключові слова:
моделювання загроз; STRIDE; Bluetooth Low Energy; BLE mesh; аварійний зв’язок; офлайн-обмін повідомленнями; приватність сторонніх осіб; відмова в обслуговуванні; ResQMesh AI.Анотація
Офлайн-обмін повідомленнями через Bluetooth Low Energy (BLE) дедалі частіше застосовується як комунікаційний рівень останньої надії, коли інфраструктура виходить з ладу. Безпеку таких систем зазвичай аналізують на рівні стеку BLE і майже ніколи - на рівні розгорнутого застосунку в умовах катастрофи. У статті представлено систематичну модель загроз для цього класу систем. Методологію STRIDE розширено двома категоріями, яких вимагає контекст катастрофи і які стандартний STRIDE не виражає, - шкода стороннім особам та фізична компрометація; для впорядкування загроз застосовано спрощену трифакторну схему оцінювання (Damage x Reproducibility x Affected parties) з опублікованими анкерами. Методологію інстанційовано на одному кейсі - ResQMesh AI, відкритій Android-платформі аварійного зв’язку на BLE mesh, - що визначає межі узагальнення зіставлення з механізмами захисту. Каталог містить 29 загроз і шість профілів порушника; за результатами зіставлення з механізмами захисту 3 загрози закриті ефективно, 19 - частково, 7 - не закриті. Два передбачені моделлю ефекти зв’язності перевірено дискретною симуляцією mesh-мережі з 60 вузлів (TTL 7, 20 прогонів): підроблений трафік критичного пріоритету з інтенсивністю, утричі більшою за пропускну здатність вузла, знижує частку своєчасної доставки справжніх критичних повідомлень з 0,87 до 0,59; бюджет ретрансляції на ідентичність відновлює її до 0,85, а ротація Sybil-ідентичностей повністю нівелює бюджет; переведення 40% вузлів у найнижчий енергорежим знижує доставку з 0,88 до 0,50, а нижня межа ретрансляції критичного трафіку повертає 3-5 в.п. Три висновки мають загальне значення: відмова від інфраструктури переносить усе початкове встановлення довіри на обмін trust-on-first-use через радіоканал, що робить підміну особи найвищим за рангом класом загроз; пріоритезація повідомлень на основі ШІ утворює примітив підсилення, оскільки підроблений високопріоритетний трафік витісняє справжній аварійний; енергоощадне ретранслювання дає порушникові дешевий важіль для сегментації мережі.
Завантаження
Посилання
Macintyre, A. G., Barbera, J. A., & Smith, E. R. (2006). Surviving collapsed structure entrapment after earthquakes: A “time-to-rescue” analysis. Prehospital and Disaster Medicine, 21(1), 4–17. https://doi.org/10.1017/S1049023X00003253
Albrecht, M. R., Blasco, J., Jensen, R. B., & Mareková, L. (2021). Mesh messaging in large-scale protests: Breaking Bridgefy. In K. G. Paterson (Ed.), Topics in Cryptology – CT-RSA 2021 (Lecture Notes in Computer Science, Vol. 12704, pp. 375–398). Springer. https://doi.org/10.1007/978-3-030-75539-3_16
Permissionless Technologies. (2026). bitchat for Android [Software repository, README]. GitHub. https://github.com/permissionlesstech/bitchat-android
Radocea, A. (2025, July 7). Identity is a Bitchat challenge (MITM flaw). Supernetworks. https://www.supernetworks.org/pages/blog/agentic-insecurity-vibes-on-bitchat
Barua, A., Al Alamin, M. A., Hossain, M. S., & Hossain, E. (2022). Security and privacy threats for Bluetooth Low Energy in IoT and wearable devices: A comprehensive survey. IEEE Open Journal of the Communications Society, 3, 251–281. https://doi.org/10.1109/OJCOMS.2022.3149732
Koulouras, G., Katsoulis, S., & Zantalis, F. (2025). Evolution of Bluetooth technology: BLE in the IoT ecosystem. Sensors, 25(4), 996. https://doi.org/10.3390/s25040996
Lacava, A., Zottola, V., Bonaldo, A., Cuomo, F., & Basagni, S. (2022). Securing Bluetooth Low Energy networking: An overview of security procedures and threats. Computer Networks, 211, 108953. https://doi.org/10.1016/j.comnet.2022.108953
Wang, L., Li, J., & Li, M. (2024). A rapid flooding approach based on adaptive delay and low-power sleep for BLE mesh networks. IEEE Access, 12, 65323–65332. https://doi.org/10.1109/ACCESS.2024.3398348
Shostack, A. (2014). Threat modeling: Designing for security. Wiley.
Deng, M., Wuyts, K., Scandariato, R., Preneel, B., & Joosen, W. (2011). A privacy threat analysis framework: Supporting the elicitation and fulfillment of privacy requirements. Requirements Engineering, 16(1), 3–32. https://doi.org/10.1007/s00766-010-0115-7
Naik, N., Jenkins, P., Grace, P., Naik, D., Prajapat, S., & Song, J. (2024). A comparative analysis of threat modelling methods: STRIDE, DREAD, VAST, PASTA, OCTAVE, and LINDDUN. In N. Naik, P. Jenkins, S. Prajapat, & P. Grace (Eds.), Contributions presented at the International Conference on Computing, Communication, Cybersecurity and AI (C3AI 2024) (Lecture Notes in Networks and Systems, Vol. 884, pp. 271–280). Springer. https://doi.org/10.1007/978-3-031-74443-3_16
Danielis, P., Beckmann, M., & Skodzik, J. (2020). An ISO-compliant test procedure for technical risk analyses of IoT systems based on STRIDE. In 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC) (pp. 499–504). IEEE. https://doi.org/10.1109/COMPSAC48688.2020.0-203
Cäsar, M., Pawelke, T., Steffan, J., & Terhorst, G. (2022). A survey on Bluetooth Low Energy security and privacy. Computer Networks, 205, 108712. https://doi.org/10.1016/j.comnet.2021.108712
von Tschirschnitz, M., Peuckert, L., Franzen, F., & Grossklags, J. (2021). Method confusion attack on Bluetooth pairing. In 2021 IEEE Symposium on Security and Privacy (SP) (pp. 1332–1347). IEEE. https://doi.org/10.1109/SP40001.2021.00013
Wu, J., Nan, Y., Kumar, V., Tian, D. J., Bianchi, A., Payer, M., & Xu, D. (2020). BLESA: Spoofing attacks against reconnections in Bluetooth Low Energy. In 14th USENIX Workshop on Offensive Technologies (WOOT ’20). USENIX Association. https://www.usenix.org/conference/woot20/presentation/wu
Wu, J., Wu, R., Xu, D., Tian, D. J., & Bianchi, A. (2022). Formal model-driven discovery of Bluetooth protocol design vulnerabilities. In 2022 IEEE Symposium on Security and Privacy (SP) (pp. 2285–2303). IEEE. https://doi.org/10.1109/SP46214.2022.9833777
Tucker, T., Searle, H., Butler, K., & Traynor, P. (2023). Blue’s Clues: Practical discovery of non-discoverable Bluetooth devices. In 2023 IEEE Symposium on Security and Privacy (SP) (pp. 3098–3112). IEEE. https://doi.org/10.1109/SP46215.2023.10179358
Che, X., He, Y., Feng, X., Sun, K., Xu, K., & Li, Q. (2024). BlueSWAT: A lightweight state-aware security framework for Bluetooth Low Energy. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS ’24) (pp. 2087–2101). ACM. https://doi.org/10.1145/3658644.3670397
Celosia, G., & Cunche, M. (2019). Fingerprinting Bluetooth-Low-Energy devices based on the Generic Attribute Profile. In Proceedings of the 2nd International ACM Workshop on Security and Privacy for the Internet-of-Things (pp. 24–31). ACM. https://doi.org/10.1145/3338507.3358617
Greß, H., Krüger, B., & Tischhauser, E. (2025). The newer, the more secure? Standards-compliant Bluetooth Low Energy man-in-the-middle attacks on fitness trackers. Sensors, 25(6), 1815. https://doi.org/10.3390/s25061815
Pirayesh, H., & Zeng, H. (2022). Jamming attacks and anti-jamming strategies in wireless networks: A comprehensive survey. IEEE Communications Surveys & Tutorials, 24(2), 767–809. https://doi.org/10.1109/COMST.2022.3159185
Sokolov, V., Skladannyi, P., & Astapenya, V. (2023). Bluetooth low-energy beacon resistance to jamming attack. In IEEE 13th International Conference on Electronics and Information Technologies (ELIT) (pp. 270–274). IEEE. https://doi.org/10.1109/ELIT61488.2023.10310815
Sokolov, V., Skladannyi, P., & Korshun, N. (2023). ZigBee network resistance to jamming attacks. In IEEE 6th International Conference on Information and Telecommunication Technologies and Radio Electronics (UkrMiCo) (pp. 161–165). IEEE. https://doi.org/10.1109/UkrMiCo61577.2023.10380360
Skallak, C., & Schmidt, S. (2024). Indescribably blue: Bluetooth Low Energy threat landscape. In Proceedings of the 9th International Conference on Internet of Things, Big Data and Security (IoTBDS) (pp. 339–350). SciTePress. https://doi.org/10.5220/0012737300003705
Karlof, C., & Wagner, D. (2003). Secure routing in wireless sensor networks: Attacks and countermeasures. Ad Hoc Networks, 1(2–3), 293–315. https://doi.org/10.1016/S1570-8705(03)00008-8
Douceur, J. R. (2002). The Sybil attack. In P. Druschel, F. Kaashoek, & A. Rowstron (Eds.), Peer-to-Peer Systems (Lecture Notes in Computer Science, Vol. 2429, pp. 251–260). Springer. https://doi.org/10.1007/3-540-45748-8_24
Álvarez, F., Almon, L., Hahn, A.-S., & Hollick, M. (2019). Toxic friends in your network: Breaking the Bluetooth mesh friendship concept. In Proceedings of the 5th ACM Workshop on Security Standardisation Research (SSR ’19) (pp. 1–12). ACM. https://doi.org/10.1145/3338500.3360334
Pliekhov, O., & Babii, K. (2025). Wi-Fi Direct in Android: Creating seamless device-to-device communication. Sustainable Engineering and Innovation, 7(2), 477–492. https://doi.org/10.37868/sei.v7i2.id539
Pliekhov, O. (2026). AI-driven message prioritization for offline BLE mesh networks in disaster response scenarios [Preprint]. SSRN. https://doi.org/10.2139/ssrn.6428398
Wang, X., Peng, K., Yi, X., & Li, H. (2026). Mind the gap: Mapping wearer-bystander privacy tensions and context-adaptive pathways for camera glasses. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems (CHI ’26). ACM. https://doi.org/10.1145/3772318.3791848
Langley, A., Hamburg, M., & Turner, S. (2016). Elliptic curves for security (RFC 7748). IETF. https://doi.org/10.17487/RFC7748
Nir, Y., & Langley, A. (2018). ChaCha20 and Poly1305 for IETF protocols (RFC 8439). IETF. https://doi.org/10.17487/RFC8439
Bluetooth SIG. (2021). Bluetooth SIG statement regarding the “Impersonation Attack in Bluetooth Mesh Provisioning” vulnerability (CVE-2020-26560). https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/
Pliekhov, O. (2026). ResQMesh AI Platform [Software repository]. GitHub. https://github.com/AleksPlekhov/ai-mesh-emergency-communication-platform
Oliinyk, Y. S., Platonenko, A. V., Cherevyk, V. M., Vorokhob, M. V., & Shevchuk, Y. (2025). Methods of information security in IoT technologies. Cybersecurity: Education, Science, Technique, 3(27), 100–108. https://doi.org/10.28925/2663-4023.2025.27.705
Locatelli, P., Perri, M., Jimenez Gutierrez, D., Lacava, A., & Cuomo, F. (2023). Device discovery and tracing in the Bluetooth Low Energy domain. Computer Communications, 202, 42–56. https://doi.org/10.1016/j.comcom.2023.02.008
Fischlin, M., & Sanina, O. (2024). Fake it till you make it: Enhancing security of Bluetooth Secure Connections via deferrable authentication. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS ’24) (pp. 4762–4776). ACM. https://doi.org/10.1145/3658644.3670360
Grynkevych, G., Vasylenko, V., & Rudin, D. (2025). Data protection in Wi-Fi networks of financial institutions: WEP to WPA3 evolution and economic impact. International Scientific Journal “Internauka”, (8). https://doi.org/10.25313/2520-2057-2025-8-12018
Grynkevych, G., Vasylenko, V., & Rudin, D. (2025). AI agents for automated network incident detection and misconfiguration identification. International Scientific Journal “Internauka”, (12). https://doi.org/10.25313/2520-2057-2025-12-12019
Grynkevych, G., Vasylenko, V., & Rudin, D. (2026). Adaptive network security automation: DevSecOps, ML detection, and policy-as-code. International Scientific Journal “Internauka”, (1). https://doi.org/10.25313/2520-2057-2026-1-12020
Опубліковано
Як цитувати
Номер
Розділ
Ліцензія
Авторське право (c) 2026 Олександр Плєхов, Ганна Гринкевич, Володимир Василенко

Ця робота ліцензується відповідно до Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.