2023
DOI: 10.1109/tse.2022.3163969
|View full text |Cite
|
Sign up to set email alerts
|

A Large-Scale Analysis of IoT Firmware Version Distribution in the Wild

Abstract: This paper examines the up-to-dateness of installed firmware versions of Internet of Things devices accessible via public Internet. It takes a novel approach to identify versions based on the source code of their web interfaces. It analyzes data sets of 1.06m devices collected using the IoT search engine Censys and then maps the results against the latest version each manufacturer offers. A fully scalable and adaptive approach is developed by applying the SEMMA data mining process. This approach relies on thre… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

1
6
1

Year Published

2023
2023
2025
2025

Publication Types

Select...
4
2
1

Relationship

1
6

Authors

Journals

citations
Cited by 7 publications
(8 citation statements)
references
References 52 publications
1
6
1
Order By: Relevance
“…Our results suggest that a regulation like the GDPR, even when enforced, may not be su cient on its own to signi cantly improve the situation. Consequently, technical means are needed to automate or disburden U&P [15].…”
Section: Discussionmentioning
confidence: 99%
See 1 more Smart Citation
“…Our results suggest that a regulation like the GDPR, even when enforced, may not be su cient on its own to signi cantly improve the situation. Consequently, technical means are needed to automate or disburden U&P [15].…”
Section: Discussionmentioning
confidence: 99%
“…The IoT ecosystem has "fundamentally changed the way information technology and communication environments work" [16], thereby transforming the way information is captured and processed. The omnipresence of IoT devices in both private and industry settings [1,15] has resulted in the processing of various types of data [1][2][3][4]. However, users are often unaware that their IoT devices can intrude upon their privacy [17].…”
Section: Related Workmentioning
confidence: 99%
“…Shodan (https://www.shodan.io/, accessed on 18 September 2023), an online search engine and scanning service, specialises in detecting and monitoring Internet-connected devices and systems. Conceived by John Matherly and launched in 2009, this search engine scans both IPv4 and IPv6 spaces [21]. Shodan is an interesting option for locating IoT devices owing to its extensive database of devices and online services, making it a valuable resource for research and analysis.…”
Section: Iot Portalsmentioning
confidence: 99%
“…Censys (https://search.censys.io/, accessed on 18 September 2023), an online search engine and scanning service akin to Shodan, specialises in tracking and compiling information about devices and resources on the Internet. It is open source and freely available for academic purposes [21]. This platform enables users to conduct advanced searches to locate devices and services based on diverse criteria.…”
Section: Iot Portalsmentioning
confidence: 99%
“… Yu et al (2020) presented a method for determining IoT device software using website page data and weak passwords. Ebbers (2022) analyzed firmware upgrades on IoT devices using data mining and mapping techniques. Feng et al (2023) examined challenges and solutions for firmware security analysis in IoT devices.…”
Section: Related Workmentioning
confidence: 99%