An Empirical Study on the Insecurity of End-of-Life (EoL) IoT Devices

被引:1
|
作者
Wang, Dingding [1 ]
Jiang, Muhui [2 ]
Chang, Rui [1 ]
Zhou, Yajin [1 ]
Wang, Hexiang [1 ]
Hou, Baolei [1 ]
Wu, Lei [1 ]
Luo, Xiapu [2 ]
机构
[1] Zhejiang Univ, Sch Comp Sci & Technol, Hangzhou 310027, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Hung Hom, Hong Kong, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Empirical study; end-of-life (EoL); IoT device; security;
D O I
10.1109/TDSC.2023.3334017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Researchers actively work on the security of Internet of Things (IoT) devices when IoT devices become popular. However, previous works ignore the insecurity about a special category of devices, i.e., the end-of-life (EoL) devices. Once a product becomes EoL, vendors no longer maintain its firmware, which makes it susceptible to attacks. In this article, we conduct the first empirical study to shed light on the (in)security of EoL devices. Our study performs two types of analysis, including the liveness analysis and the vulnerability analysis. The first one aims to detect the scale of EoL devices that are still alive in the wild in the long term. The second one is to evaluate the vulnerabilities existing in (active) EoL devices. We analyzed 894 EoL models from three vendors (i.e., D-Link, Tp-Link, and Netgear) for more than two years. Our study reveals some worrisome facts that were unknown by the community. There exist more than three million active EoL devices, while more than one million of them have been alive for more than five years. Furthermore, more than half of the vulnerabilities are discovered after the EoL date. Although vendors may release security patches after the EoL date, the process is ad hoc and incomplete, with limited functionality. In summary, more than three million active EoL devices are vulnerable, and nearly half of them are threatened by high-risk vulnerabilities. By compromising EoL devices, attackers can achieve a minimum of 8.67 Tbps DDoS attack.
引用
收藏
页码:3501 / 3514
页数:14
相关论文
共 50 条
  • [21] Factors related to end-of-life (EOL) chemotherapy in solid tumor (ST) patients
    Rodriguez, Maria Alma
    DeJesus, Yvette A.
    Cheng, Lee
    Buzdar, Aman
    Burke, Thomas W.
    JOURNAL OF CLINICAL ONCOLOGY, 2013, 31 (15)
  • [22] Pattern of chemotherapy use at end-of-life (EOL) in patients with solid tumors (ST)
    Burke, Thomas W.
    DeJesus, Yvette A.
    Cheng, Lee
    Buzdar, Aman
    Rodriguez, Maria Alma
    JOURNAL OF CLINICAL ONCOLOGY, 2013, 31 (15)
  • [23] Hospitalization burden and end-of-life (EOL) care in elderly patients with glioblastoma (GBM)
    Donovan, Laura
    Buono, Donna
    Accordino, Melissa Kate
    Wright, Jason Dennis
    Lassman, Andrew B.
    Hershman, Dawn L.
    JOURNAL OF CLINICAL ONCOLOGY, 2021, 39 (28)
  • [24] CURRENT STATE OF PROGNOSIS TELLING AND THEIR RESPONSES IN CANCER PATIENTS AT THE END-OF-LIFE (EOL).
    Hayashi, Yoko
    Ogasawara, Chie
    Kato, Akiko
    Asakura, Yuki
    ONCOLOGY NURSING FORUM, 2017, 44 (02)
  • [25] Utilization of Palliative Radiation in Pediatric Oncology Patients During the End-of-Life (EOL)
    Cuviello, Andrea
    Guzman, Angelica F. Figueroa
    Zeng, Emily
    Mothi, Suraj Sarvode
    Baker, Justin N.
    Krasin, Matthew J.
    JOURNAL OF PAIN AND SYMPTOM MANAGEMENT, 2024, 68 (06)
  • [26] A holistic decision support tool for remanufacturing: end-of-life (EOL) strategy planning
    S. S. Yang
    N. Nasr
    S. K. Ong
    A. Y. C. Nee
    Advances in Manufacturing, 2016, 4 : 189 - 201
  • [27] A holistic decision support tool for remanufacturing: end-of-life (EOL) strategy planning
    Yang, S. S.
    Nasr, N.
    Ong, S. K.
    Nee, A. Y. C.
    ADVANCES IN MANUFACTURING, 2016, 4 (03) : 189 - 201
  • [28] End-of-Life Care in Patients with Cardiac Devices
    McNairn, Kim
    Cai, Andrew
    Randall, Paul
    McDonagh, Teresa
    JOURNAL OF PAIN AND SYMPTOM MANAGEMENT, 2016, 52 (06) : E126 - E126
  • [29] End-of-life care and end-of-life medical decisions: the ITAELD study
    Miccinesi, Guido
    Puliti, Donella
    Paci, Eugenio
    EPIDEMIOLOGIA & PREVENZIONE, 2011, 35 (3-4): : 178 - 187
  • [30] Factors related to end-of-life (EOL) chemotherapy in solid tumor (ST) patients.
    Rodriguez, Maria Alma
    DeJesus, Yvette A.
    Cheng, Lee
    Buzdar, Aman
    Burke, Thomas W.
    JOURNAL OF CLINICAL ONCOLOGY, 2013, 31 (31)