论文标题

评估数百个IoT设备的未来设备安全风险指标

Evaluating the Future Device Security Risk Indicator for Hundreds of IoT Devices

论文作者

Oser, Pascal, Engelmann, Felix, Lüders, Stefan, Kargl, Frank

论文摘要

物联网设备存在于许多人,尤其是公司和敏感的网络中,并且由于供应商对脆弱性的响应缓慢和修补难度而定期引入安全风险。在本文中,我们希望根据历史信息来评估由于新的和未解决的漏洞,可以在多大程度上预测由于新的和未捕获的漏洞的未来风险。为了进行此分析,我们基于可提供的现有预测算法(Prophet和Arima),我们通过793个IoT设备的大量漏洞和补丁进行评估。我们的分析表明,更安全的框架可以预测91%的设备的正确未来风险,以证明其适用性。我们得出的结论是,这种方法是网络运营商有效地检测和采取行动对来自其网络中物联网设备发出的风险的可靠手段。

IoT devices are present in many, especially corporate and sensitive, networks and regularly introduce security risks due to slow vendor responses to vulnerabilities and high difficulty of patching. In this paper, we want to evaluate to what extent the development of future risk of IoT devices due to new and unpatched vulnerabilities can be predicted based on historic information. For this analysis, we build on existing prediction algorithms available in the SAFER framework (prophet and ARIMA) which we evaluate by means of a large data-set of vulnerabilities and patches from 793 IoT devices. Our analysis shows that the SAFER framework can predict a correct future risk for 91% of the devices, demonstrating its applicability. We conclude that this approach is a reliable means for network operators to efficiently detect and act on risks emanating from IoT devices in their networks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源