Demystifying IoT Security: An Exhaustive Survey on IoT Vulnerabilities and a First Empirical Look on Internet-Scale IoT Exploitations

Demystifying IoT Security: An Exhaustive Survey on IoT Vulnerabilities and a First Empirical Look on Internet-Scale IoT Exploitations
复制标题

DOI:
10.1109/comst.2019.2910750
复制
发表时间:
2019-01-01
影响因子:
35.6
通讯作者:
Ghani, Nasir
Ghani, Nasir
中科院分区:
计算机科学1区
文献类型:
--
作者:
Neshenko, Nataliia;Bou-Harb, Elias;Ghani, Nasir

文献摘要

被引文献

相似文献

影响物联网(IoT)范式的安全问题最近引起了研究界的极大关注。为此,针对各种以物联网为中心的主题提出了几项调查,包括入侵检测系统,威胁建模和新兴技术。相比之下,在本文中,我们只关注不断发展的物联网漏洞。在这种情况下,我们首先提供了最先进的调查的全面分类,这些调查涉及物联网范式的各个方面。这旨在通过合并,比较和对比分散的研究贡献来促进物联网研究工作。随后,我们提供了一个独特的分类法,它揭示了物联网漏洞,它们的攻击向量,对众多安全目标的影响,利用这些漏洞的攻击,相应的补救方法,以及目前提供的操作网络安全能力来推断和监控这些弱点。这旨在为读者提供与物联网漏洞相关的多维研究视角,包括其技术细节和后果,这被认为是用于补救目标的。此外,由于缺乏与物联网范式相关的经验(和恶意)数据,本文还通过借鉴超过1.2 GB的宏观被动测量数据,对互联网规模的物联网利用进行了初步研究。这旨在实际突出物联网问题的严重性,同时提供操作态势感知能力,这无疑将有助于缓解任务。除了公开的挑战和研究问题之外,本文还披露了有见地的发现,推断和结果,我们希望这将为未来的研究工作铺平道路,解决与物联网安全这一迫切主题相关的理论和实证方面。
The security issue impacting the Internet-of-Things (IoT) paradigm has recently attracted significant attention from the research community. To this end, several surveys were put forward addressing various IoT-centric topics, including intrusion detection systems, threat modeling, and emerging technologies. In contrast, in this paper, we exclusively focus on the ever-evolving IoT vulnerabilities. In this context, we initially provide a comprehensive classification of state-of-the-art surveys, which address various dimensions of the IoT paradigm. This aims at facilitating IoT research endeavors by amalgamating, comparing, and contrasting dispersed research contributions. Subsequently, we provide a unique taxonomy, which sheds the light on IoT vulnerabilities, their attack vectors, impacts on numerous security objectives, attacks which exploit such vulnerabilities, corresponding remediation methodologies and currently offered operational cyber security capabilities to infer and monitor such weaknesses. This aims at providing the reader with a multidimensional research perspective related to IoT vulnerabilities, including their technical details and consequences, which is postulated to be leveraged for remediation objectives. Additionally, motivated by the lack of empirical (and malicious) data related to the IoT paradigm, this paper also presents a first look on Internet-scale IoT exploitations by drawing upon more than 1.2 GB of macroscopic, passive measurements' data. This aims at practically highlighting the severity of the IoT problem, while providing operational situational awareness capabilities, which undoubtedly would aid in the mitigation task, at large. Insightful findings, inferences and outcomes in addition to open challenges and research problems are also disclosed in this paper, which we hope would pave the way for future research endeavors addressing theoretical and empirical aspects related to the imperative topic of IoT security.