Towards Examining The Security Cost of Inexpensive Smart Home IoT Devices

被引:1
|
作者
OConnor, T. J. [1 ]
Jessee, Dylan [1 ]
Campos, Daniel [1 ]
机构
[1] Florida Inst Technol, Melbourne, FL 32901 USA
关键词
internet of things; security and privacy; secure software development;
D O I
10.1109/COMPSAC57700.2023.00196
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
A myriad of security challenges has accompanied the rapid proliferation of internet-of-things (IoT) smart-home devices. While smart-home security cameras, locks, digital speakers, and thermostats offer the promise of security, their naive implementations often introduce vulnerability into our digitally connected lives. We argue that the consumer demand for inexpensive IoT has led to a supply of grossly insecure devices. To examine this hypothesis, we examine the security of five inexpensive IoT devices from three separate vendors. In all five devices, our work uncovers immature software security efforts. Our findings discover new vulnerabilities, document legacy vulnerabilities due to software bill of materials (SBOM) issues, explore security mitigations in firmware, and examine the unsecured communication within the ecosystems of the devices. Our analysis discusses the root causes of these vulnerabilities. While these results indicate a snapshot of an immature and naive state of IoT software, there are several software development lifecycle processes that vendors can immediately implement to overcome the root causes of these vulnerabilities.
引用
收藏
页码:1293 / 1298
页数:6
相关论文
共 50 条
  • [1] Future Security of Smart Speaker and IoT Smart Home Devices
    Godwin, Shawn
    Glendenning, Brett
    Gagneja, Kanwalinderjit
    PROCEEDINGS OF THE 2019 FIFTH INTERNATIONAL CONFERENCE ON MOBILE AND SECURE SERVICES (MOBISECSERV), 2019,
  • [2] Smart IoT Devices in the Home Security and Privacy Implications
    Sivaraman, Vijay
    Gharakheili, Hassan Habibi
    Fernandes, Clinton
    Clark, Narelle
    Karliychuk, Tanya
    IEEE TECHNOLOGY AND SOCIETY MAGAZINE, 2018, 37 (02) : 71 - 79
  • [3] Ranking Security of IoT-Based Smart Home Consumer Devices
    Allifah, Naba M.
    Zualkernan, Imran A.
    IEEE ACCESS, 2022, 10 : 18352 - 18369
  • [4] IoT Smart Home Devices' Security, Privacy, and Firmware Labeling System
    Rajkhan, Naif Waheb
    Song, Jia
    2021 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2021), 2021, : 1874 - 1880
  • [5] Enhancing Smart Home Security using Co-Monitoring of IoT Devices
    Agrawal, Dev
    Bhagwat, Rahul
    Bandopadhyay, Rajdeep
    Kunapareddi, Vineela
    Burden, Eric
    Halse, Shane
    Wisniewski, Pamela
    Kropczynski, Jess
    GROUP'20: COMPANION OF THE 2020 ACM INTERNATIONAL CONFERENCE ON SUPPORTING GROUP WORK, 2019, : 99 - 102
  • [6] Vulnerability Studies and Security Postures of IoT Devices: A Smart Home Case Study
    Davis, Brittany D.
    Mason, Janelle C.
    Anwar, Mohd
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (10) : 10102 - 10110
  • [7] Network-Level Security and Privacy Control for Smart-Home IoT Devices
    Sivaraman, Vijay
    Gharakheili, Hassan Habibi
    Vishwanath, Arun
    Boreli, Roksana
    Mehani, Olivier
    2015 IEEE 11TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2015, : 163 - 167
  • [8] Review of Security and Privacy-Based IoT Smart Home Access Control Devices
    Uppuluri, Sirisha
    Lakshmeeswari, G.
    WIRELESS PERSONAL COMMUNICATIONS, 2024, 137 (03) : 1601 - 1640
  • [9] SMART HOME SECURITY AND AUTOMATION USING IOT
    Srinivasarao, P.
    Rao, G. Siva Nageswara
    ADVANCES AND APPLICATIONS IN MATHEMATICAL SCIENCES, 2021, 20 (12): : 3289 - 3296
  • [10] IoT Based Smart Security and Home Automation
    Somani, Shradha
    Solunke, Parikshit
    Oke, Shaunak
    Medhi, Parth
    Laturkar, P. P.
    2018 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION (ICCUBEA), 2018,