2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) 2023
DOI: 10.1109/eurosp57164.2023.00065
|View full text |Cite
|
Sign up to set email alerts
|

AoT - Attack on Things: A security analysis of IoT firmware updates

Muhammad Ibrahim,
Andrea Continella,
Antonio Bianchi

Abstract: IoT devices implement firmware update mechanisms to fix security issues and deploy new features. These mechanisms are often triggered and mediated by mobile companion apps running on the users' smartphones. While it is crucial to update devices, these mechanisms may cause critical security flaws if they are not implemented correctly. Given their relevance, in this paper, we perform a systematic security analysis of the firmware update mechanisms adopted by IoT devices via their companion apps. First, we define… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 7 publications
(1 citation statement)
references
References 44 publications
0
1
0
Order By: Relevance
“…None of these systems are inherently designed with security in mind; rather, they prioritize cost-effectiveness and innovation, often at the expense of security and privacy (Girish et al, 2023). Additionally, the devices themselves have intrinsic limitations, including low storage and computing capacities, along with challenges such as manufacturers' reluctance to provide software/firmware updates (Ibrahim et al, 2023) or the complexity involved in installing updates, even for competent users.…”
Section: Introductionmentioning
confidence: 99%
“…None of these systems are inherently designed with security in mind; rather, they prioritize cost-effectiveness and innovation, often at the expense of security and privacy (Girish et al, 2023). Additionally, the devices themselves have intrinsic limitations, including low storage and computing capacities, along with challenges such as manufacturers' reluctance to provide software/firmware updates (Ibrahim et al, 2023) or the complexity involved in installing updates, even for competent users.…”
Section: Introductionmentioning
confidence: 99%