A Rapid Review on Software Vulnerabilities and Embedded, Cyber-Physical, and IoT Systems

被引:0
|
作者
Marchetto, Alessandro [1 ]
Scanniello, Giuseppe [2 ]
机构
[1] Univ Trento, Trento, Italy
[2] Univ Salerno, Salerno, Italy
关键词
Cybersecurity; Embedded systems; Rapid Review; Software Vulnerability;
D O I
10.1007/978-3-031-49266-2_32
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a Rapid Review (RR) conducted to identify and characterize existing approaches and methods that discover, fix, and manage vulnerabilities in Embedded, Cyber-Physical, and Internet-of-Things systems and software (ESs hereafter). In the last years, a growing interest concerned the adoption of ESs in different domains (e.g., automotive, healthcare) and with different purposes. Modern ESs are heterogeneous, computationally powerful, connected, and intelligent systems characterized by many technologies, devices, and an extensive use of embedded software (SW). Adopting software that could emulate or substitute hardware (HD) components makes the ESs flexible, tunable, and less costly but demands attention to security aspects such as SW vulnerabilities. Vulnerabilities can be exploited by attackers and compromise entire systems. The findings of our RR emerge from 61 papers and can be summarized as follows: (i) complex and connected ESs are studied especially for autonomous vehicles and robots; (ii) new methods and approaches are proposed mainly to discover software-vulnerabilities related to memory management in ES firmware software; and (iii) most of the proposed methods apply fuzzy-based dynamic analysis to binary and executable files of ES software.
引用
收藏
页码:468 / 477
页数:10
相关论文
共 50 条
  • [21] Component-based Timing Analysis for Embedded Software Components in Cyber-Physical Systems
    Li, Haoxuan
    Vanherpen, Ken
    Hellinckx, Peter
    Mercelis, Siegfried
    De Meulenaere, Paul
    [J]. 2020 9TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2020, : 173 - 180
  • [22] Impact of Dew Computing on Cyber-Physical Systems and IoT
    Gusev, M.
    [J]. 2020 43RD INTERNATIONAL CONVENTION ON INFORMATION, COMMUNICATION AND ELECTRONIC TECHNOLOGY (MIPRO 2020), 2020, : 1910 - 1915
  • [23] Architecture of Software Platform for Testing Software of Cyber-Physical Systems
    Golosovskiy, Mikhail
    Tobin, Dmitriy
    Balandov, Mikhail
    Khlopotov, Roman
    [J]. DATA SCIENCE AND ALGORITHMS IN SYSTEMS, 2022, VOL 2, 2023, 597 : 488 - 494
  • [24] Intelligent Embedded Systems Platform for Vehicular Cyber-Physical Systems
    Conrad, Christopher
    Al-Rubaye, Saba
    Tsourdos, Antonios
    [J]. ELECTRONICS, 2023, 12 (13)
  • [25] Cyber-Physical Verification of Intermittently Powered Embedded Systems
    Bohrer, Rose
    Islam, Bashima
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2022, 41 (11) : 4361 - 4372
  • [26] Reliability assessment of cyber-physical power systems considering the impact of predicted cyber vulnerabilities
    Rostami, Amir
    Mohammadi, Mohammad
    Karimipour, Hadis
    [J]. INTERNATIONAL JOURNAL OF ELECTRICAL POWER & ENERGY SYSTEMS, 2023, 147
  • [27] Software architectures for health care cyber-physical systems: A systematic literature review
    Plaza, Andrea M.
    Diaz, Jessica
    Perez, Jennifer
    [J]. JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2018, 30 (07)
  • [28] Identifying Cyber-Physical Vulnerabilities in Additive Manufacturing Systems using a Systems Approach
    Krishnan, Rahul
    Bhada, Shamsnaz Virani
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2020, : 2113 - 2118
  • [29] Research on Cyber-Physical Systems Based on Software Definition
    Zhang, Chen
    Wei, Boyi
    Zhang, Lichen
    [J]. PROCEEDINGS OF 2021 IEEE 12TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS), 2021, : 174 - 177
  • [30] Systems Engineering–Software Engineering Interface for Cyber-Physical Systems
    Sheard, Sarah
    Pafford, Michael E.
    Phillips, Mike
    [J]. INCOSE International Symposium, 2019, 29 (01) : 249 - 268