Back to Search Start Over

A Large-Scale Empirical Study on the Vulnerability of Deployed IoT Devices

Authors :
Haiqin Weng
Jingzheng Wu
Raheem Beyah
Wei-Han Lee
Liming Fang
Shouling Ji
Binbin Zhao
Changting Lin
Pan Zhou
Source :
IEEE Transactions on Dependable and Secure Computing. 19:1826-1840
Publication Year :
2022
Publisher :
Institute of Electrical and Electronics Engineers (IEEE), 2022.

Abstract

The Internet of Things (IoT) has become ubiquitous and greatly affected peoples‘ daily lives. With the increasing development of IoT devices, the corresponding security issues are becoming more and more challenging. Such a severe security situation raises the following questions that need urgent attention: What are the primary security threats that IoT devices face currently‘ How do vendors and users deal with these threats‘ In this paper, we aim to answer these critical questions through a large-scale systematic study. Specifically, we perform a ten-month-long empirical study on the vulnerability of 1,362,906 IoT devices varying from six types. The results show sufficient evidence that N-days vulnerability is seriously endangering the IoT devices: 385,060 (28.25%) devices suffer from at least one N-days vulnerability. Moreover, 2,669 of these vulnerable devices may have been compromised by botnets. We further reveal the massive differences among five popular IoT search engines: Shodan, Censys, Zoomeye, Fofa and NTI. Besides, we measure the security of MQTT servers and identify that 12,740 (88%) MQTT servers have no password protection. Our analysis can serve as an important guideline for investigating the security of IoT devices, as well as advancing the development of a more secure environment for IoT systems.

Details

ISSN :
21609209 and 15455971
Volume :
19
Database :
OpenAIRE
Journal :
IEEE Transactions on Dependable and Secure Computing
Accession number :
edsair.doi...........596099f62e602e058787ec5fd7e4d940
Full Text :
https://doi.org/10.1109/tdsc.2020.3037908