Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air Updates
Huancheng Hu, Christian Doerr
摘要
Over-the-air (OTA) firmware updates are essential for maintaining IoT device security. However, vendors frequently reduce update frequency and discontinue support before devices reach end of life. Prior work has focused on protocol design and deployment measurements, but has not explained why vendors struggle to sustain long-term update support. Through interviews with 30 IoT vendors and a survey of over 100 practitioners, we examine OTA practices from the vendor perspective. We find that OTA failures stem from fragmented responsibility across multi-tier supply chains, economic constraints that determine support duration independent of security needs, and structural mismatches between component lifecycles and deployment periods. These organizational and economic factors create systematic barriers to security maintenance that technical solutions alone cannot address. Our findings reveal why current approaches to IoT security are insufficient and suggest policy interventions for sustainable update practices.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper11
- "It's the Company, the Government, You and I": User Perceptions of Responsibility for Smart Home Privacy and SecurityJulie M. Haney, Yasemin Acar, Susanne FurmanUSENIX Security 2021 · 被引用 49 次
- Security Update Labels: Establishing Economic Incentives for Security Patching of IoT Consumer ProductsPhilipp Morgner, Christoph Mai, Nicole Koschate-Fischer, Felix C. Freiling 等S&P 2020 · 被引用 41 次
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai 等USENIX Security 2024 · 被引用 33 次
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke 等USENIX Security 2021 · 被引用 30 次
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu 等ICSE 2022 · 被引用 21 次
相关 Paper
- Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric VendorsSandra Rivera Pérez, Michel van Eeten, Carlos Hernandez GañánS&P 2024 · 被引用 3 次
- Missing, Present and Conflicting: A Large Scale Analysis of IoT Update Information in the EU MarketSwaathi Vetrivel, Michel van Eeten, Carlos H. GañánUSENIX Security 2026
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
- Mind the Advisory Gap: Comparing Security Advisory and Patch Management Practices Across IoT and Non-IoT VendorsSandra Rivera Pérez, Mathew Vermeer, Savvas Zannettou, Arwa Al Alsadi 等CCS 2026
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin 等S&P 2025
