Rytel Marcin, Felkner Anna, Janiszewski Marek
Research and Academic Computer Network (NASK), Kolska 12, 01-045 Warsaw, Poland.
Sensors (Basel). 2020 Oct 22;20(21):5969. doi: 10.3390/s20215969.
The security of the Internet of Things (IoT) is an important yet often overlooked subject. Specifically, the publicly available information sources about vulnerabilities affecting the connected devices are unsatisfactory. Our research shows that, while the information is available on the Internet, there is no single service offering data focused on the IoT in existence. The national vulnerability databases contain some IoT related entries, but they lack mechanisms to distinguish them from the remaining vulnerabilities. Moreover, information about many vulnerabilities affecting the IoT world never reaches these databases but can still be found scattered over the Internet. This review summarizes our effort at identifying and evaluating publicly available sources of information about vulnerabilities, focusing on their usefulness in the scope of IoT. The results of our search show that there is not yet a single satisfactory source covering vulnerabilities affecting IoT devices and software available.
物联网(IoT)的安全性是一个重要但常被忽视的主题。具体而言,关于影响连接设备的漏洞的公开可用信息源并不令人满意。我们的研究表明,虽然互联网上有相关信息,但目前没有单一的专注于物联网的数据服务。国家漏洞数据库包含一些与物联网相关的条目,但它们缺乏将这些条目与其他漏洞区分开来的机制。此外,许多影响物联网领域的漏洞信息从未进入这些数据库,但仍可在互联网上零散地找到。本综述总结了我们在识别和评估关于漏洞的公开可用信息源方面所做的工作,重点关注它们在物联网范围内的实用性。我们的搜索结果表明,目前还没有一个令人满意的涵盖影响物联网设备和软件的漏洞的信息源。