SoK: Security Evaluation
- f Home-based IoT
Deployments
1
Omar Alrawi, Chaz Lever, Fabian Monrose, Manos Antonakakis
SoK: Security Evaluation of Home-based IoT Deployments Omar Alrawi - - PowerPoint PPT Presentation
SoK: Security Evaluation of Home-based IoT Deployments Omar Alrawi , Chaz Lever, Fabian Monrose, Manos Antonakakis 1 2 Alexa, unlock the front door. 3 Internet of Things 4 Internet of Things 4 Internet of Things 4 Internet of Things
1
Omar Alrawi, Chaz Lever, Fabian Monrose, Manos Antonakakis
2
3
4
4
4
4
4
4
4
4
5
6
Applications
6
Applications
6
Applications
Analysis
6
Applications
Analysis
6
Applications
Analysis
the Home Internet of Things
6
Wouldn’t be nice to know
Wouldn’t be nice to know
Wouldn’t be nice to know
Wouldn’t be nice to know
Wouldn’t be nice to know
Wouldn’t be nice to know
Studied Components
Devices Cloud integration services Network (by association)
Mitigations
Patching bugs Vendor responsibility
Unexplored Directions
Mobile app Cloud services Network discovery protocols User control and visibility
8
9
10
10
10
10
11
12
12
12
12
12
12
12
UPnP services RCE vulnerability CVE-2012-5958-65 Dropbear SSH RCE vulnerability CVE-2013-4863
13
13
13
13
13
13
14
14
14
14
14
15
15
15
15
15
Scorecard system Rating components Independent scoring Modular Documented
16
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
17
Component Framework
18
18
19
20
with authenticated services
20
21
21
21
22