Hi,
we also have received an acceptance notice for a paper submitted to the IEEE Transactions
on Software Engineering:
F. Ebbers, "A Large-Scale Analysis of IoT Firmware Version Distribution in the
Wild," in IEEE Transactions on Software Engineering, doi: 10.1109/TSE.2022.3163969.
Abstract:
This paper examines the up-to-dateness of installed firmware versions of Internet of
Things devices accessible via public Internet. It takes a novel approach to identify
versions based on the source code of their web interfaces. It analyzes data sets of 1.06m
devices collected using the IoT search engine Censys and then maps the results against the
latest version each manufacturer offers. A fully scalable and adaptive approach is
developed by applying the SEMMA data mining process. This approach relies on three data
artifacts: raw data from Censys, a mapping table with firmware versions, and a keyword
search list. The results confirm the heterogeneity of connected IoT devices and show that
only 2.45 percent of the IoT devices in the wild run the latest available firmware.
Installed versions are 19.2 months old on average. This real-world evidence suggests that
the updating processes and methods used by engineers so far are not sufficient to keep IoT
devices up-to-date. This paper identifies and quantifies influencing factors and captures
the global and diverse distribution of IoT devices. It finds manufacturer and device type
influence the up-to-dateness of firmware, whereas the country in which the device is
deployed is less significant.
Best
Michael
---
Dr. Michael Friedewald
Fraunhofer-Institut für System- und Innovationsforschung ISI
Competence Center Emerging Technologies
Coordinator ICT Research
Breslauer Straße 48 | 76139 Karlsruhe
fon: +49 721 6809-146 (-166, ass.)
michael.friedewald(a)isi.fraunhofer.de
http://www.isi.fraunhofer.de
Neue Veröffentlichungen:
Friedewald M., Schiffner S., Krenn S. (Eds.) (2021): Privacy and Identity Management. 15th
IFIP WG 9.2 9.6/11.7 11.6/SIG 9.2.2 International Summer School Maribor Slovenia September
20-23 2020 Revised Selected Papers. Cham: Springer International (IFIP Advances in
Information and Communication Technology, 619).
Stapf, I.; Ammicht Quinn, R.; Friedewald, M.; Heesen, J.; Krämer, N. C. (Hrsg.) (2021):
Aufwachsen in überwachten Umgebungen: Interdisziplinäre Positionen zu Privatheit und
Datenschutz in Kindheit und Jugend. Baden-Baden: Nomos (Kommunikations- und Medienethik,
14). Open access:
https://www.nomos-elibrary.de/10.5771/9783748921639.pdf
Martin, N.; Friedewald, M.; Schiering, I. et al. (2020): Die Datenschutz-Folgenabschätzung
nach Art. 35 DSGVO: Ein Handbuch für die Praxis. Stuttgart: Fraunhofer Verlag. Open
access:
http://publica.fraunhofer.de/documents/N-586394.html