The IoT security gap: a look down into the valley between threat models and their implementation

47Citations
Citations of this article
131Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

We claim to have identified gaps between threat modeling frameworks, threat model use in IoT security research and attacks that may be missed by current research. While security research includes sections known as ‘threat models’, these models are not supported by the categorization and standardization that threat modeling frameworks would have to offer. Then again, if existing threat modeling frameworks were used, they would still allow many vulnerabilities to pass through undetected, since they are meant for software-only projects. This work will explain the origins of IoT research, enumerate common threat modeling frameworks and give an insight into the state of IoT security research. In the course of this, it will become clear how these gaps came to be and what research directions would help to close them.

Cite

CITATION STYLE

APA

Aufner, P. (2020). The IoT security gap: a look down into the valley between threat models and their implementation. In International Journal of Information Security (Vol. 19, pp. 3–14). Springer. https://doi.org/10.1007/s10207-019-00445-y

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free