A Measurement Study on the (In)security of End-of-Life (EoL) Embedded Devices
Dingding Wang, Muhui Jiang, Rui Chang, Yajin Zhou, Baolei Hou, Xiapu, Luo, Lei Wu, Kui Ren

TL;DR
This study investigates the security risks of End-of-Life embedded devices, revealing millions are still active and vulnerable, posing significant threats like large-scale DDoS attacks, highlighting urgent need for better EoL device security management.
Contribution
First measurement study analyzing the security status of EoL embedded devices, providing insights into their prevalence, vulnerabilities, and potential attack impacts.
Findings
Over 2 million active EoL devices identified
Nearly 300,000 EoL devices remain active after five years
More than 1 million EoL devices are vulnerable to high-risk exploits
Abstract
Embedded devices are becoming popular. Meanwhile, researchers are actively working on improving the security of embedded devices. However, previous work ignores the insecurity caused by a special category of devices, i.e., the End-of-Life (EoL in short) devices. Once a product becomes End-of-Life, vendors tend to no longer maintain its firmware or software, including providing bug fixes and security patches. This makes EoL devices susceptible to attacks. For instance, a report showed that an EoL model with thousands of active devices was exploited to redirect web traffic for malicious purposes. In this paper, we conduct the first measurement study to shed light on the (in)security of EoL devices. To this end, our study performs two types of analysis, including the aliveness analysis and the vulnerability analysis. The first one aims to detect the scale of EoL devices that are still…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Security and Verification in Computing · Cloud Data Security Solutions
