Bara' Nazzal, Atheer Abu Zaid, Manar H. Alalfi, A. Valani
{"title":"基于消费者的物联网软件漏洞分类","authors":"Bara' Nazzal, Atheer Abu Zaid, Manar H. Alalfi, A. Valani","doi":"10.1145/3528227.3528566","DOIUrl":null,"url":null,"abstract":"This paper surveys and categorizes potential software vulnerabilities in consumer-based IoT applications. We look at the currently available reported vulnerabilities in the SmartThings platform as well as potential vulnerabilities that face IoT platforms in general. We provide a multi-step categorization that applies available guidance as well as connecting it to frameworks such as OWASP and MITRE ATT&CK to classify the vulnerabilities depending on their platform, layer, nature, class as well as the suggested mitigation.","PeriodicalId":275034,"journal":{"name":"2022 IEEE/ACM 4th International Workshop on Software Engineering Research and Practices for the IoT (SERP4IoT)","volume":"45 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Vulnerability Classification of Consumer-based IoT Software\",\"authors\":\"Bara' Nazzal, Atheer Abu Zaid, Manar H. Alalfi, A. Valani\",\"doi\":\"10.1145/3528227.3528566\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper surveys and categorizes potential software vulnerabilities in consumer-based IoT applications. We look at the currently available reported vulnerabilities in the SmartThings platform as well as potential vulnerabilities that face IoT platforms in general. We provide a multi-step categorization that applies available guidance as well as connecting it to frameworks such as OWASP and MITRE ATT&CK to classify the vulnerabilities depending on their platform, layer, nature, class as well as the suggested mitigation.\",\"PeriodicalId\":275034,\"journal\":{\"name\":\"2022 IEEE/ACM 4th International Workshop on Software Engineering Research and Practices for the IoT (SERP4IoT)\",\"volume\":\"45 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-05-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 IEEE/ACM 4th International Workshop on Software Engineering Research and Practices for the IoT (SERP4IoT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3528227.3528566\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE/ACM 4th International Workshop on Software Engineering Research and Practices for the IoT (SERP4IoT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3528227.3528566","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Vulnerability Classification of Consumer-based IoT Software
This paper surveys and categorizes potential software vulnerabilities in consumer-based IoT applications. We look at the currently available reported vulnerabilities in the SmartThings platform as well as potential vulnerabilities that face IoT platforms in general. We provide a multi-step categorization that applies available guidance as well as connecting it to frameworks such as OWASP and MITRE ATT&CK to classify the vulnerabilities depending on their platform, layer, nature, class as well as the suggested mitigation.