Back to Search
Start Over
A Large-Scale Empirical Study on the Vulnerability of Deployed IoT Devices
- Source :
- IEEE Transactions on Dependable and Secure Computing. 19:1826-1840
- Publication Year :
- 2022
- Publisher :
- Institute of Electrical and Electronics Engineers (IEEE), 2022.
-
Abstract
- The Internet of Things (IoT) has become ubiquitous and greatly affected peoples‘ daily lives. With the increasing development of IoT devices, the corresponding security issues are becoming more and more challenging. Such a severe security situation raises the following questions that need urgent attention: What are the primary security threats that IoT devices face currently‘ How do vendors and users deal with these threats‘ In this paper, we aim to answer these critical questions through a large-scale systematic study. Specifically, we perform a ten-month-long empirical study on the vulnerability of 1,362,906 IoT devices varying from six types. The results show sufficient evidence that N-days vulnerability is seriously endangering the IoT devices: 385,060 (28.25%) devices suffer from at least one N-days vulnerability. Moreover, 2,669 of these vulnerable devices may have been compromised by botnets. We further reveal the massive differences among five popular IoT search engines: Shodan, Censys, Zoomeye, Fofa and NTI. Besides, we measure the security of MQTT servers and identify that 12,740 (88%) MQTT servers have no password protection. Our analysis can serve as an important guideline for investigating the security of IoT devices, as well as advancing the development of a more secure environment for IoT systems.
- Subjects :
- MQTT
021110 strategic, defence & security studies
Computer science
business.industry
0211 other engineering and technologies
Botnet
02 engineering and technology
Computer security
computer.software_genre
Empirical research
Server
Scale (social sciences)
Password protection
Electrical and Electronic Engineering
Internet of Things
business
computer
Vulnerability (computing)
Subjects
Details
- ISSN :
- 21609209 and 15455971
- Volume :
- 19
- Database :
- OpenAIRE
- Journal :
- IEEE Transactions on Dependable and Secure Computing
- Accession number :
- edsair.doi...........596099f62e602e058787ec5fd7e4d940
- Full Text :
- https://doi.org/10.1109/tdsc.2020.3037908