PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 13, 2021IEEE Internet of Things Journal169 citations

Consumer, Commercial, and Industrial IoT (In)Security: Attack Taxonomy and Case Studies

View Full Paper
CXChristos XenofontosIZIoannis ZografopoulosCKCharalambos Konstantinou

Key Points

Key points are not available for this paper at this time.

Abstract

Internet of Things (IoT) devices are becoming ubiquitous in our lives, with applications spanning from the consumer domain to commercial and industrial systems. The steep growth and vast adoption of IoT devices reinforce the importance of sound and robust cybersecurity practices during the device development life cycles. IoT-related vulnerabilities, if successfully exploited can affect, not only the device itself but also the application field in which the IoT device operates. Evidently, identifying and addressing every single vulnerability are an arduous, if not impossible, task. Attack taxonomies can assist in classifying attacks and their corresponding vulnerabilities. Security countermeasures and best practices can then be leveraged to mitigate threats and vulnerabilities before they emerge into catastrophic attacks and ensure overall secure IoT operation. Therefore, in this article, we provide an attack taxonomy, which takes into consideration the different layers of the IoT stack, i.e., device, infrastructure, communication, and service, and each layer’s designated characteristics, which can be exploited by adversaries. Furthermore, using nine real-world cybersecurity incidents that had targeted IoT devices deployed in the consumer, commercial, and industrial sectors, we describe the IoT-related vulnerabilities, exploitation procedures, attacks, impacts, and potential mitigation mechanisms and protection strategies. These (and many other) incidents highlight the underlying security concerns of IoT systems and demonstrate the potential attack impacts of such connected ecosystems, while the proposed taxonomy provides a systematic procedure to categorize attacks based on the affected layer and corresponding impact.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Xenofontos et al. (2021) studied this question.

synapsesocial.com/papers/6a04201784f4a64869de4e69https://doi.org/10.1109/jiot.2021.3079916
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Security threats and issues in automation IoT2017 · 120 citations
  2. 2Cyber-physical systems and their security issues2018 · 471 citations
  3. 3Security Challenges in CPS and IoT: From End-Node to the System2016 · 42 citations
  4. 4History of Industrial Control System Cyber Incidents2018 · 197 citations