Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric Vendors
Sandra Rivera Pérez, Michel van Eeten, Carlos Hernandez Gañán
Abstract
The enduring problems with IoT security has shifted the attention of researchers and governments to the role of vendors. The security community is no stranger to the repeated claim that vendors are dropping the ball on security and privacy, with numerous papers highlighting the many vulnerabilities in IoT products. Are IoT-centric vendors performing worse than other vendors in the industry? To answer this question, we need to do more than simply count the number of vulnerabilities disclosed by each vendor. In our study we analyze the factors influencing the number of vulnerabilities per vendor, like its size, its location and the presence of a vulnerability disclosure policy. We then statistically estimate if IoT-centric vendors produce more vulnerabilities, while controlling for those other factors. The answer is that they do. We can more directly observe the security performance of a vendor by looking at its patching behavior. We collect a unique dataset on the availability and timeliness of patches for 2,741 IoT and non-IoT vulnerabilities from 104 leading vendors. We also collect data on a set of potential causal factors for vendor patching performance. This allows us to estimate a statistical model of factors to explain why some vendors do better than others. We find that IoT-centric vendors are no worse in terms of releasing patches for their vulnerabilities, in fact, they tend to release more patches on-time than non-IoT-centric vendors. Our study increases our understanding of the factors shaping IoT security and provides an empirical basis for regulatory interventions that aim to improve the security performance of IoT vendors.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get c8819105-57ef-4adb-9a30-e1272173a15cCited by top-tier papers1
Ask how each one uses itRelated papers
- Mind the Advisory Gap: Comparing Security Advisory and Patch Management Practices Across IoT and Non-IoT VendorsSandra Rivera Pérez, Mathew Vermeer, Savvas Zannettou, Arwa Al Alsadi et al.CCS 2026
- Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air UpdatesHuancheng Hu, Christian DoerrUSENIX Security 2026
- "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and CertificationPrianka Mandal, Adwait NadkarniS&P 2025
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin et al.S&P 2025
- Unveiling IoT Security in Reality: A Firmware-Centric JourneyNicolas Nino, Ruibo Lu, Wei Zhou, Kyu Hyung Lee et al.USENIX Security 2024 · 12 citations
