An Empirical Study on the Insecurity of End-of-Life (EoL) IoT Devices

被引:1
|
作者
Wang, Dingding [1 ]
Jiang, Muhui [2 ]
Chang, Rui [1 ]
Zhou, Yajin [1 ]
Wang, Hexiang [1 ]
Hou, Baolei [1 ]
Wu, Lei [1 ]
Luo, Xiapu [2 ]
机构
[1] Zhejiang Univ, Sch Comp Sci & Technol, Hangzhou 310027, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Hung Hom, Hong Kong, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Empirical study; end-of-life (EoL); IoT device; security;
D O I
10.1109/TDSC.2023.3334017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Researchers actively work on the security of Internet of Things (IoT) devices when IoT devices become popular. However, previous works ignore the insecurity about a special category of devices, i.e., the end-of-life (EoL) devices. Once a product becomes EoL, vendors no longer maintain its firmware, which makes it susceptible to attacks. In this article, we conduct the first empirical study to shed light on the (in)security of EoL devices. Our study performs two types of analysis, including the liveness analysis and the vulnerability analysis. The first one aims to detect the scale of EoL devices that are still alive in the wild in the long term. The second one is to evaluate the vulnerabilities existing in (active) EoL devices. We analyzed 894 EoL models from three vendors (i.e., D-Link, Tp-Link, and Netgear) for more than two years. Our study reveals some worrisome facts that were unknown by the community. There exist more than three million active EoL devices, while more than one million of them have been alive for more than five years. Furthermore, more than half of the vulnerabilities are discovered after the EoL date. Although vendors may release security patches after the EoL date, the process is ad hoc and incomplete, with limited functionality. In summary, more than three million active EoL devices are vulnerable, and nearly half of them are threatened by high-risk vulnerabilities. By compromising EoL devices, attackers can achieve a minimum of 8.67 Tbps DDoS attack.
引用
收藏
页码:3501 / 3514
页数:14
相关论文
共 50 条
  • [1] End-of-life (EOL) decision-making in the ICU: A prospective study
    Rubulotta, FM
    Gullo, A
    CRITICAL CARE MEDICINE, 2002, 30 (12) : A146 - A146
  • [2] A resource recovery model for end-of-life (EOL) electronics
    DiRodi, VF
    PROCEEDINGS OF THE 1996 IEEE INTERNATIONAL SYMPOSIUM ON ELECTRONICS AND THE ENVIRONMENT, CONFERENCE RECORD, 1996, : 78 - 80
  • [3] END-OF-LIFE (EOL) CARE RECIPIENTS IN NURSING HOMES
    Bercovitz, A.
    Decker, F.
    Jones, A.
    Remsburg, R.
    GERONTOLOGIST, 2008, 48 : 542 - 542
  • [4] Death Rounds as a Tool in End-of-Life (EOL) Education
    Smith, L.
    White, D. B.
    Hough, C. L.
    AMERICAN JOURNAL OF RESPIRATORY AND CRITICAL CARE MEDICINE, 2009, 179
  • [5] End-of-Life Transfusions (EOL): A Physician's Dilemma
    Khan, S.
    TRANSFUSION, 2016, 56 : 221A - 221A
  • [6] END-OF-LIFE HEALTH LITERACY: VALIDATION STUDY OF A NEW INSTRUMENT, THE END-OF-LIFE HEALTH LITERACY SCALE (EOL-HLS)
    Meier, Clement
    Vilpert, Sarah
    Borasio, Gian Domenico
    Jox, Ralf J.
    Maurer, Juergen
    INNOVATION IN AGING, 2022, 6 : 258 - 258
  • [7] End-of-life (EOL) decision making in the NICU: A prospective study of physicians' perspectives
    Hellmann, J
    O'Brien, K
    McAllister, M
    Jacobs, S
    Marshall, M
    Harrison, C
    PEDIATRIC RESEARCH, 2002, 51 (04) : 42A - 43A
  • [8] Hyperspectral imaging applied to end-of-life (EOL) concrete recycling
    Bonifazi, Giuseppe
    Palmieri, Roberta
    Serranti, Silvia
    TM-TECHNISCHES MESSEN, 2015, 82 (12) : 616 - 624
  • [9] End-of-life (EOL) issues and options for electric vehicle batteries
    Monsuru Olalekan Ramoni
    Hong-Chao Zhang
    Clean Technologies and Environmental Policy, 2013, 15 : 881 - 891
  • [10] End-of-life (EOL) issues and options for electric vehicle batteries
    Ramoni, Monsuru Olalekan
    Zhang, Hong-Chao
    CLEAN TECHNOLOGIES AND ENVIRONMENTAL POLICY, 2013, 15 (06) : 881 - 891