Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric Vendors
Sandra Rivera Pérez, Michel van Eeten, Carlos Hernandez Gañán
摘要
The enduring problems with IoT security has shifted the attention of researchers and governments to the role of vendors. The security community is no stranger to the repeated claim that vendors are dropping the ball on security and privacy, with numerous papers highlighting the many vulnerabilities in IoT products. Are IoT-centric vendors performing worse than other vendors in the industry? To answer this question, we need to do more than simply count the number of vulnerabilities disclosed by each vendor. In our study we analyze the factors influencing the number of vulnerabilities per vendor, like its size, its location and the presence of a vulnerability disclosure policy. We then statistically estimate if IoT-centric vendors produce more vulnerabilities, while controlling for those other factors. The answer is that they do. We can more directly observe the security performance of a vendor by looking at its patching behavior. We collect a unique dataset on the availability and timeliness of patches for 2,741 IoT and non-IoT vulnerabilities from 104 leading vendors. We also collect data on a set of potential causal factors for vendor patching performance. This allows us to estimate a statistical model of factors to explain why some vendors do better than others. We find that IoT-centric vendors are no worse in terms of releasing patches for their vulnerabilities, in fact, they tend to release more patches on-time than non-IoT-centric vendors. Our study increases our understanding of the factors shaping IoT security and provides an empirical basis for regulatory interventions that aim to improve the security performance of IoT vendors.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- Mind the Advisory Gap: Comparing Security Advisory and Patch Management Practices Across IoT and Non-IoT VendorsSandra Rivera Pérez, Mathew Vermeer, Savvas Zannettou, Arwa Al Alsadi 等CCS 2026
- Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air UpdatesHuancheng Hu, Christian DoerrUSENIX Security 2026
- "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and CertificationPrianka Mandal, Adwait NadkarniS&P 2025
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin 等S&P 2025
- Unveiling IoT Security in Reality: A Firmware-Centric JourneyNicolas Nino, Ruibo Lu, Wei Zhou, Kyu Hyung Lee 等USENIX Security 2024 · 被引用 12 次
