This paper surveys and categorizes potential software vulnerabilities in consumer-based IoT applications. We look at the currently available reported vulnerabilities in the SmartThings platform as well as potential vulnerabilities that face IoT platforms in general. We provide a multi-step categorization that applies available guidance as well as connecting it to frameworks such as OWASP and MITRE ATT&CK to classify the vulnerabilities depending on their platform, layer, nature, class as well as the suggested mitigation.
CITATION STYLE
Nazzal, B., Zaid, A. A., Alalfi, M. H., & Valani, A. (2022). Vulnerability Classification of Consumer-based IoT Software. In Proceedings - 4th International Workshop on Software Engineering Research and Practice for the IoT, SERP4IoT 2022 (pp. 17–24). Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1145/3528227.3528566
Mendeley helps you to discover research relevant for your work.