Security Weaknesses in IoT Management Platforms
Bhaskar Tejaswi, Mohammad Mannan, Amr Youssef

TL;DR
This paper systematically evaluates the security of 52 IoT management platforms, uncovering critical vulnerabilities like unauthorized access, broken authentication, and remote code execution, highlighting the urgent need for improved security measures.
Contribution
Introduces a comprehensive framework for security assessment of IoT management platforms and applies it to identify significant vulnerabilities in real-world systems.
Findings
9 platforms had high severity unauthorized access vulnerabilities
13 platforms exhibited broken authentication issues
2 platforms were vulnerable to remote code execution
Abstract
A diverse set of Internet of Things (IoT) devices are becoming an integrated part of daily lives, and playing an increasingly vital role in various industry, enterprise and agricultural settings. The current IoT ecosystem relies on several IoT management platforms to manage and operate a large number of IoT devices, their data, and their connectivity. Considering their key role, these platforms must be properly secured against cyber attacks. In this work, we first explore the core operations/features of leading platforms to design a framework to perform a systematic security evaluation of these platforms. Subsequently, we use our framework to analyze a representative set of 52 IoT management platforms, including 42 web-hosted and 10 locally-deployable platforms. We discover a number of high severity unauthorized access vulnerabilities in 9/52 evaluated IoT management platforms, which…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · IoT and Edge/Fog Computing
