Bara' Nazzal, Atheer Abu Zaid, Manar H. Alalfi, A. Valani
{"title":"Vulnerability Classification of Consumer-based IoT Software","authors":"Bara' Nazzal, Atheer Abu Zaid, Manar H. Alalfi, A. Valani","doi":"10.1145/3528227.3528566","DOIUrl":null,"url":null,"abstract":"This paper surveys and categorizes potential software vulnerabilities in consumer-based IoT applications. We look at the currently available reported vulnerabilities in the SmartThings platform as well as potential vulnerabilities that face IoT platforms in general. We provide a multi-step categorization that applies available guidance as well as connecting it to frameworks such as OWASP and MITRE ATT&CK to classify the vulnerabilities depending on their platform, layer, nature, class as well as the suggested mitigation.","PeriodicalId":275034,"journal":{"name":"2022 IEEE/ACM 4th International Workshop on Software Engineering Research and Practices for the IoT (SERP4IoT)","volume":"45 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE/ACM 4th International Workshop on Software Engineering Research and Practices for the IoT (SERP4IoT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3528227.3528566","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
This paper surveys and categorizes potential software vulnerabilities in consumer-based IoT applications. We look at the currently available reported vulnerabilities in the SmartThings platform as well as potential vulnerabilities that face IoT platforms in general. We provide a multi-step categorization that applies available guidance as well as connecting it to frameworks such as OWASP and MITRE ATT&CK to classify the vulnerabilities depending on their platform, layer, nature, class as well as the suggested mitigation.