On the Contents and Utility of IoT Cybersecurity Guidelines
Jesse Chen, Dharun Anandayuvaraj, James C. Davis, Sazzadur Rahaman
摘要
Cybersecurity concerns of Internet of Things (IoT) devices and infrastructure are growing each year. In response, organizations worldwide have published IoT security guidelines to protect their citizens and customers by providing recommendations on the development and operation of IoT systems. While these guidelines are being adopted, e.g. by US federal contractors, their content and merits have not been critically examined. Specically, we do not know what topics and recommendations they cover and their eectiveness at preventing real-world IoT failures. In this paper, we address these gaps through a qualitative study of guidelines. We collect 142 IoT cybersecurity guidelines and sample them for recommendations until reaching saturation at 25 guidelines. From the resulting 958 unique recommendations, we iteratively develop a hierarchical taxonomy following grounded theory coding principles and study the guidelines' comprehensiveness. In addition, we evaluate the actionability and specicity of each recommendation and match recommendations to CVEs and security failures in the news they can prevent. We report that: (1) Each guideline has gaps in its topic coverage and comprehensiveness; (2) 87.2% recommendations are actionable and 38.7% recommendations can prevent specic threats; and (3) although the union of the guidelines mitigates all 17 of the failures from our news stories corpus, 21% of the CVEs evade the guidelines. In summary, we report shortcomings in each guideline's depth and breadth, but as a whole they address major security issues. CCS Concepts: • General and reference ! Empirical studies; • Security and privacy ! Software security engineering; Security requirements.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines 等ICSE 2026 · 被引用 5 次
- On the Characteristics and Impacts of Protestware LibrariesTanner Finken, Jesse Chen, Sazzadur RahamanFSE 2025
- Learning From Software Failures: A Case Study at a National Space Research CenterDharun Anandayuvaraj, Tanmay Singla, Zain Alabedin Haj Hammadeh, Andreas Lund 等ICSE 2026
它引用的顶会 Paper9
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 被引用 684 次
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 被引用 411 次
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar 等VLDB 2020 · 被引用 82 次
- IoT Bugs and Development ChallengesAmir Makhshari, Ali MesbahICSE 2021 · 被引用 76 次
相关 Paper
- "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and CertificationPrianka Mandal, Adwait NadkarniS&P 2025
- Measuring Up to (Reasonable) Consumer Expectations: Providing an Empirical Basis for Holding IoT Manufacturers Legally ResponsibleLorenz Kustosch, Carlos Gañán, Mattis van 't Schip, Michel van Eeten 等USENIX Security 2023
- Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese IndustriesFumihiro Kanei, Ayako Akiyama Hasegawa, Eitaro Shioji, Mitsuaki AkiyamaCHI 2023 · 被引用 4 次
- A First Look at Governments' Enterprise Security GuidanceKimberly Ruth, Raymond Buernor Obu, Ifeoluwa Shode, Gavin Li 等USENIX Security 2025
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 被引用 14 次
