An Empirical Study on the Insecurity of End-of-Life (EoL) IoT Devices

被引:1
|
作者
Wang, Dingding [1 ]
Jiang, Muhui [2 ]
Chang, Rui [1 ]
Zhou, Yajin [1 ]
Wang, Hexiang [1 ]
Hou, Baolei [1 ]
Wu, Lei [1 ]
Luo, Xiapu [2 ]
机构
[1] Zhejiang Univ, Sch Comp Sci & Technol, Hangzhou 310027, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Hung Hom, Hong Kong, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Empirical study; end-of-life (EoL); IoT device; security;
D O I
10.1109/TDSC.2023.3334017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Researchers actively work on the security of Internet of Things (IoT) devices when IoT devices become popular. However, previous works ignore the insecurity about a special category of devices, i.e., the end-of-life (EoL) devices. Once a product becomes EoL, vendors no longer maintain its firmware, which makes it susceptible to attacks. In this article, we conduct the first empirical study to shed light on the (in)security of EoL devices. Our study performs two types of analysis, including the liveness analysis and the vulnerability analysis. The first one aims to detect the scale of EoL devices that are still alive in the wild in the long term. The second one is to evaluate the vulnerabilities existing in (active) EoL devices. We analyzed 894 EoL models from three vendors (i.e., D-Link, Tp-Link, and Netgear) for more than two years. Our study reveals some worrisome facts that were unknown by the community. There exist more than three million active EoL devices, while more than one million of them have been alive for more than five years. Furthermore, more than half of the vulnerabilities are discovered after the EoL date. Although vendors may release security patches after the EoL date, the process is ad hoc and incomplete, with limited functionality. In summary, more than three million active EoL devices are vulnerable, and nearly half of them are threatened by high-risk vulnerabilities. By compromising EoL devices, attackers can achieve a minimum of 8.67 Tbps DDoS attack.
引用
收藏
页码:3501 / 3514
页数:14
相关论文
共 50 条
  • [41] Burdensome end-of-life (EOL) transitions among frail older adults with advanced cancer
    Lage, Daniel E.
    Lee, Yoojin
    Mitchell, Susan L.
    Temel, Jennifer S.
    Berry, Sarah
    El-Jawahri, Areej
    JOURNAL OF CLINICAL ONCOLOGY, 2018, 36 (15)
  • [42] Development of a sustainable decision framework for the implementation of end-of-life (EoL) options for the railcar industry
    Phuluwa, Humbulani Simon
    Daniyan, Ilesanmi
    Mpofu, Khumbulani
    ENVIRONMENT DEVELOPMENT AND SUSTAINABILITY, 2021, 23 (06) : 9433 - 9453
  • [43] Empirical Ethics: The Case of Dignity in End-of-Life Decisions
    Leget, Carlo
    Borry, Pascal
    ETHICAL PERSPECTIVES, 2010, 17 (02) : 231 - 252
  • [44] End-of-life dialogue, end-of-life education
    Mazzola, Paolo
    BMJ SUPPORTIVE & PALLIATIVE CARE, 2014, 4 (02) : 130 - 131
  • [45] End-of-Life Care, Not End-of-Life Spending
    Jha, Ashish K.
    JAMA-JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 2018, 320 (07): : 631 - 632
  • [46] Associations between hospice use and end-of-life (EOL) care outcomes in patients with advanced cancer
    Kumar, Pallavi
    Hatfield, Laura
    Wright, Alexi A.
    Temel, Jennifer S.
    Keating, Nancy Lynn
    JOURNAL OF CLINICAL ONCOLOGY, 2015, 33 (29)
  • [47] Factors Associated with High Healthcare Utilization at the End-of-Life (EOL) for Patients with Acute Myeloid Leukemia
    Vaughn, Dagny M.
    Johnson, P. Connor
    Jagielo, Annemarie D.
    Reynolds, Matthew J.
    Kavanaugh, Alison R.
    Webb, Jason A.
    Fathi, Amir T.
    Hobbs, Gabriela S.
    Brunner, Andrew M.
    O'Connor, Nina R.
    Luger, Selina M.
    Bhatnagar, Bhavana
    LeBlanc, Thomas W.
    El-Jawahri, Areej
    BLOOD, 2020, 136
  • [48] Timeliness of end-of-life (EOL) discussions for blood cancers: A national survey of hematologic oncologists.
    Odejide, Oreofe Olukemi
    Cronin, Angel
    Condron, Nolan
    Earle, Craig
    Wolfe, Joanne
    Abel, Gregory Alan
    JOURNAL OF CLINICAL ONCOLOGY, 2015, 33 (29)
  • [49] END-OF-LIFE (EOL) CARE OUTCOMES FOR PATIENTS WITH NEWLY-DIAGNOSED DECOMPENSATED CIRRHOSIS (DC)
    Ufere, Nneka
    Halford, Jennifer
    Caldwell, Joshua
    Jang, Megan
    Bhatt, Sunil
    Donlan, John
    Chung, Raymond T.
    El-Jawahri, Areej
    HEPATOLOGY, 2019, 70 : 402A - 402A
  • [50] Management of Patients with ICDs at the End of Life (EOL): A Qualitative Study
    Kelley, Amy S.
    Mehta, Sonal S.
    Reid, M. Carrington
    AMERICAN JOURNAL OF HOSPICE & PALLIATIVE MEDICINE, 2008, 25 (06): : 440 - 446