论文标题
基于CVE的脆弱物联网系统的分类
CVE based classification of vulnerable IoT systems
论文作者
论文摘要
常见的漏洞和暴露数据库(CVE)是最大的软件和硬件漏洞数据和报告的最大公开来源之一。在这项工作中,我们在物联网设备和系统漏洞的上下文中分析了CVE数据库。我们介绍了基于现实世界的物联网系统的分类。然后,我们在CVE数据库选定子集中使用SVM算法来对本框架中的“新”漏洞记录进行分类。兴趣的子集由描述不同应用程序的潜在IoT设备的漏洞组成的记录,例如:家庭,行业,移动控制器,网络等。分类的目的是开发和测试自动系统,以识别弱点IoT设备并在这方面测试CVE数据的完整,足够和可靠性。
Common Vulnerabilities and Exposures database (CVE) is one of the largest publicly available source of software and hardware vulnerability data and reports. In this work we analyze the CVE database in the context of IoT device and system vulnerabilities. We introduce a real-world based classification of IoT systems. Then, we employ a SVM algorithm on selected subset of CVE database to classify "new" vulnerability records in this framework. The subset of interest consists of records that describe vulnerabilities of potential IoT devices of different applications, such as: home, industry, mobile controllers, networking, etc. The purpose of the classification is to develop and test an automatic system for recognition of vulnerable IoT devices and to test completes, sufficiency and reliability of CVE data in this respect.