论文标题

野外物联网固件版本的大规模分析

A Large-Scale Analysis of IoT Firmware Version Distribution in the Wild

论文作者

Ebbers, Frank

论文摘要

本文研究了可通过公共互联网访问的IoT设备的已安装固件版本的最新性。它分析了从物联网搜索引擎陈述收集的106万个设备的数据集,并根据每个制造商提供的最新固件版本绘制结果。通过应用SEMMA数据挖掘过程,开发了完全可扩展和适应性的方法。这种方法依赖于三个数据工件:来自Censys的原始数据,带有固件版本的映射表和关键字搜索列表。初步结果证实了连接的物联网设备的异质性。他们表明制造商,设备类型和国家 /地区会影响固件的最新性。结果将用户视为“弱链接”,因为他们没有及时更新设备的固件。但是,异质性导致结果尚未显示出很高的可靠性。

This paper examines the up-to-dateness of installed firmware versions of IoT devices accessible via public internet. It analyzes datasets of 1.06m devices collected from the IoT search engine Censys and maps the results against the latest firmware version each manufacturer offers. By applying the SEMMA data mining process, a fully scalable and adaptive approach is developed. This approach relies on three data artifacts: raw data from Censys, a mapping table with firmware versions and a keyword search list. The preliminary results confirm the heterogeneity of connected IoT devices. They show that manufacturer, device type and country influence the up-to-dateness of firmware. The results suggest users as a "weak link" as they do not update the firmware of their devices in a timely manner. However, the heterogeneity leads to results not showing a high reliability, yet.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源