A Rapid Review on Software Vulnerabilities and Embedded, Cyber-Physical, and IoT Systems

被引:0
|
作者
Marchetto, Alessandro [1 ]
Scanniello, Giuseppe [2 ]
机构
[1] Univ Trento, Trento, Italy
[2] Univ Salerno, Salerno, Italy
关键词
Cybersecurity; Embedded systems; Rapid Review; Software Vulnerability;
D O I
10.1007/978-3-031-49266-2_32
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a Rapid Review (RR) conducted to identify and characterize existing approaches and methods that discover, fix, and manage vulnerabilities in Embedded, Cyber-Physical, and Internet-of-Things systems and software (ESs hereafter). In the last years, a growing interest concerned the adoption of ESs in different domains (e.g., automotive, healthcare) and with different purposes. Modern ESs are heterogeneous, computationally powerful, connected, and intelligent systems characterized by many technologies, devices, and an extensive use of embedded software (SW). Adopting software that could emulate or substitute hardware (HD) components makes the ESs flexible, tunable, and less costly but demands attention to security aspects such as SW vulnerabilities. Vulnerabilities can be exploited by attackers and compromise entire systems. The findings of our RR emerge from 61 papers and can be summarized as follows: (i) complex and connected ESs are studied especially for autonomous vehicles and robots; (ii) new methods and approaches are proposed mainly to discover software-vulnerabilities related to memory management in ES firmware software; and (iii) most of the proposed methods apply fuzzy-based dynamic analysis to binary and executable files of ES software.
引用
收藏
页码:468 / 477
页数:10
相关论文
共 50 条
  • [1] Vulnerabilities and safety assurance methods in Cyber-Physical Systems: A comprehensive review
    Bolbot, Victor
    Theotokatos, Gerasimos
    Bujorianu, Luminita Manuela
    Boulougouris, Evangelos
    Vassalos, Dracos
    [J]. RELIABILITY ENGINEERING & SYSTEM SAFETY, 2019, 182 : 179 - 193
  • [2] Cyber-physical systems challenges: a needs analysis for collaborating embedded software systems
    Mosterman, Pieter J.
    Zander, Justyna
    [J]. SOFTWARE AND SYSTEMS MODELING, 2016, 15 (01): : 5 - 16
  • [3] Cyber-physical systems challenges: a needs analysis for collaborating embedded software systems
    Pieter J. Mosterman
    Justyna Zander
    [J]. Software & Systems Modeling, 2016, 15 : 5 - 16
  • [4] A Systematic Literature Review on Software Maintenance for Cyber-Physical Systems
    Khezami, Nadhira
    Kessentini, Marouane
    Ferreira, Thiago Do N.
    [J]. IEEE ACCESS, 2021, 9 : 159858 - 159872
  • [5] Review on Cyber-physical Systems
    Liu, Yang
    Peng, Yu
    Wang, Bailing
    Yao, Sirui
    Liu, Zihe
    [J]. IEEE-CAA JOURNAL OF AUTOMATICA SINICA, 2017, 4 (01) : 27 - 40
  • [6] Review on Cyber-physical Systems
    Yang Liu
    Yu Peng
    Bailing Wang
    Sirui Yao
    Zihe Liu
    [J]. IEEE/CAA Journal of Automatica Sinica, 2017, 4 (01) : 27 - 40
  • [7] A review on cyber-physical systems
    Lin, Feng
    Shu, Shaolong
    [J]. Tongji Daxue Xuebao/Journal of Tongji University, 2010, 38 (08): : 1243 - 1248
  • [8] A Co-Design Approach for Embedded Control Software of Cyber-Physical Systems
    Broenink, Jan F.
    Vos, Peter-Jan D.
    Lu, Zhou
    Bezemer, Maarten M.
    [J]. 2016 11TH SYSTEMS OF SYSTEM ENGINEERING CONFERENCE (SOSE), IEEE, 2016,
  • [9] Roundtable: Reliability of Embedded and Cyber-Physical Systems
    Barnum, Sean
    Sastry, Shankar
    Stankovic, John A.
    [J]. IEEE SECURITY & PRIVACY, 2010, 8 (05) : 27 - 32
  • [10] Framework for Rapid Development of Embedded Human-in-the-Loop Cyber-Physical Systems
    Feng, Shen
    Quivira, Fernando
    Schirner, Gunar
    [J]. 2016 IEEE 16TH INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOENGINEERING (BIBE), 2016, : 208 - 215