首页> 外文会议>IEEE Symposium on Security and Privacy >SoK: Security Evaluation of Home-Based IoT Deployments
【24h】

SoK: Security Evaluation of Home-Based IoT Deployments

机译:SoK:基于家庭的物联网部署的安全性评估

获取原文

摘要

Home-based IoT devices have a bleak reputation regarding their security practices. On the surface, the insecurities of IoT devices seem to be caused by integration problems that may be addressed by simple measures, but this work finds that to be a naive assumption. The truth is, IoT deployments, at their core, utilize traditional compute systems, such as embedded, mobile, and network. These components have many unexplored challenges such as the effect of over-privileged mobile applications on embedded devices. Our work proposes a methodology that researchers and practitioners could employ to analyze security properties for home-based IoT devices. We systematize the literature for home-based IoT using this methodology in order to understand attack techniques, mitigations, and stakeholders. Further, we evaluate 45 devices to augment the systematized literature in order to identify neglected research areas. To make this analysis transparent and easier to adapt by the community, we provide a public portal to share our evaluation data and invite the community to contribute their independent findings.
机译:基于家庭的物联网设备在其安全实践方面享有惨淡的声誉。从表面上看,物联网设备的不安全性似乎是由集成问题引起的,可以通过简单的措施来解决,但这项工作发现这是一个幼稚的假设。事实是,IoT部署的核心是利用传统的计算系统,例如嵌入式,移动和网络。这些组件有许多未开发的挑战,例如,过度特权的移动应用程序对嵌入式设备的影响。我们的工作提出了一种方法,研究人员和从业人员可以使用该方法来分析基于家庭的物联网设备的安全性。我们使用此方法将基于家庭的物联网的文献系统化,以了解攻击技术,缓解措施和利益相关方。此外,我们评估了45种设备以扩充系统化文献,以发现被忽视的研究领域。为了使此分析透明并易于社区适应,我们提供了一个公共门户网站来共享我们的评估数据,并邀请社区贡献其独立的发现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号