IDEAS home Printed from https://ideas.repec.org/a/eee/ijocip/v38y2022ics1874548222000373.html
   My bibliography  Save this article

A taxonomy of IoT firmware security and principal firmware analysis techniques

Author

Listed:
  • Nadir, Ibrahim
  • Mahmood, Haroon
  • Asadullah, Ghalib

Abstract

Internet of Things (IoT) has come a long way since its inception. However, the standardization process in IoT systems for a secure IoT solution is still in its early days. Numerous quality review articles have been contributed by researchers on existing frameworks, architectures, as well as the threats to IoT on different layers. However, most of the existing work neglects the security aspects of firmware in the IoT ecosystem. As such, there is a lack of comprehensive survey on IoT firmware security that highlights critical reasons for firmware insecurity in IoT, lists vulnerabilities, and perform an in-depth review of the principal analysis techniques. This article aims to fill that gap by delivering, to the best of our knowledge, the first comprehensive review article of the firmware (in)security of IoT devices. Starting by highlighting the importance of firmware security, this research work recognizes critical reasons behind the insecurity of firmware by discussing technical, commercial, standardization, and researching aspects. In particular, the scope, evolution, and internals of IoT firmware along with their security implications are discussed. Furthermore, a taxonomic classification of IoT firmware vulnerabilities has been presented. We also discuss complications that hinder the detection of firmware vulnerabilities before doing a detailed analysis of existing vulnerability assessment tools and techniques. A comparative analysis of the principal analysis techniques is provided in terms of the vulnerabilities they discover, the methodology they employ, and the platform and/or architectures they support. Towards the end, some key research issues have been identified to encourage and facilitate research in the firmware security domain of IoT. Finally, some recommendations have been provided for the IoT device vendors, developers, and integrators.

Suggested Citation

  • Nadir, Ibrahim & Mahmood, Haroon & Asadullah, Ghalib, 2022. "A taxonomy of IoT firmware security and principal firmware analysis techniques," International Journal of Critical Infrastructure Protection, Elsevier, vol. 38(C).
  • Handle: RePEc:eee:ijocip:v:38:y:2022:i:c:s1874548222000373
    DOI: 10.1016/j.ijcip.2022.100552
    as

    Download full text from publisher

    File URL: http://www.sciencedirect.com/science/article/pii/S1874548222000373
    Download Restriction: Full text for ScienceDirect subscribers only

    File URL: https://libkey.io/10.1016/j.ijcip.2022.100552?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to search for a different version of it.

    References listed on IDEAS

    as
    1. Lee, In & Lee, Kyoochun, 2015. "The Internet of Things (IoT): Applications, investments, and challenges for enterprises," Business Horizons, Elsevier, vol. 58(4), pages 431-440.
    2. Miao Yu & Jianwei Zhuge & Ming Cao & Zhiwei Shi & Lin Jiang, 2020. "A Survey of Security Vulnerability Analysis, Discovery, Detection, and Mitigation on IoT Devices," Future Internet, MDPI, vol. 12(2), pages 1-23, February.
    3. Vipindev Adat & B. B. Gupta, 2018. "Security in Internet of Things: issues, challenges, taxonomy, and architecture," Telecommunication Systems: Modelling, Analysis, Design and Management, Springer, vol. 67(3), pages 423-441, March.
    4. Kshetri, Nir, 2017. "The evolution of the internet of things industry and market in China: An interplay of institutions, demands and supply," Telecommunications Policy, Elsevier, vol. 41(1), pages 49-67.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Silviu-Gabriel Szentesi & Lavinia Denisia Cuc & Ramona Lile & Paul Nichita Cuc, 2021. "Internet of Things (IoT), Challenges and Perspectives in Romania: A Qualitative Research," The AMFITEATRU ECONOMIC journal, Academy of Economic Studies - Bucharest, Romania, vol. 23(57), pages 448-448.
    2. Eric Forcael & Isabella Ferrari & Alexander Opazo-Vega & Jesús Alberto Pulido-Arcas, 2020. "Construction 4.0: A Literature Review," Sustainability, MDPI, vol. 12(22), pages 1-28, November.
    3. Leonel Jorge Ribeiro Nunes & Radu Godina & João Carlos de Oliveira Matias, 2019. "Technological Innovation in Biomass Energy for the Sustainable Growth of Textile Industry," Sustainability, MDPI, vol. 11(2), pages 1-12, January.
    4. Athanasios Tsipis & Asterios Papamichail & Ioannis Angelis & George Koufoudakis & Georgios Tsoumanis & Konstantinos Oikonomou, 2020. "An Alertness-Adjustable Cloud/Fog IoT Solution for Timely Environmental Monitoring Based on Wildfire Risk Forecasting," Energies, MDPI, vol. 13(14), pages 1-35, July.
    5. Bent Flyvbjerg & Alexander Budzier & Jong Seok Lee & Mark Keil & Daniel Lunn & Dirk W. Bester, 2022. "The Empirical Reality of IT Project Cost Overruns: Discovering A Power-Law Distribution," Papers 2210.01573, arXiv.org.
    6. Akhtar, Pervaiz & Khan, Zaheer & Tarba, Shlomo & Jayawickrama, Uchitha, 2018. "The Internet of Things, dynamic data and information processing capabilities, and operational agility," Technological Forecasting and Social Change, Elsevier, vol. 136(C), pages 307-316.
    7. Li, Ying & Dai, Jing & Cui, Li, 2020. "The impact of digital technologies on economic and environmental performance in the context of industry 4.0: A moderated mediation model," International Journal of Production Economics, Elsevier, vol. 229(C).
    8. Kumar, V. & Ramachandran, Divya & Kumar, Binay, 2021. "Influence of new-age technologies on marketing: A research agenda," Journal of Business Research, Elsevier, vol. 125(C), pages 864-877.
    9. Madhukar Patil & M. Suresh, 2019. "Modelling the Enablers of Workforce Agility in IoT Projects: A TISM Approach," Global Journal of Flexible Systems Management, Springer;Global Institute of Flexible Systems Management, vol. 20(2), pages 157-175, June.
    10. Abdel Ghafar, Ahmed Ismail & Vazquez Castro, Ágeles & Essam Khedr, Mohamed, 2019. "Multidimensional Self-Organizing Chord-Based Networking for Internet of Things," 2nd Europe – Middle East – North African Regional ITS Conference, Aswan 2019: Leveraging Technologies For Growth 201736, International Telecommunications Society (ITS).
    11. Vasja Roblek & Maja Meško & Alojz Krapež, 2016. "A Complex View of Industry 4.0," SAGE Open, , vol. 6(2), pages 21582440166, June.
    12. Artur Pollak & Agata Hilarowicz & Maciej Walczak & Damian Gąsiorek, 2020. "A Framework of Action for Implementation of Industry 4.0. an Empirically Based Research," Sustainability, MDPI, vol. 12(14), pages 1-16, July.
    13. Pillai, Rajasshrie & Sivathanu, Brijesh & Dwivedi, Yogesh K., 2020. "Shopping intention at AI-powered automated retail stores (AIPARS)," Journal of Retailing and Consumer Services, Elsevier, vol. 57(C).
    14. Kumar Prateek & Nitish Kumar Ojha & Fahiem Altaf & Soumyadev Maity, 2023. "Quantum secured 6G technology-based applications in Internet of Everything," Telecommunication Systems: Modelling, Analysis, Design and Management, Springer, vol. 82(2), pages 315-344, February.
    15. Zahra, Shaker A. & Liu, Wan & Si, Steven, 2023. "How digital technology promotes entrepreneurship in ecosystems," Technovation, Elsevier, vol. 119(C).
    16. Zhang, Yimeng & Ma, Xinyu & Pang, Jianing & Xing, Hailong & Wang, Jian, 2023. "The impact of digital transformation of manufacturing on corporate performance — The mediating effect of business model innovation and the moderating effect of innovation capability," Research in International Business and Finance, Elsevier, vol. 64(C).
    17. Jelena Končar & Aleksandar Grubor & Radenko Marić & Sonja Vučenović & Goran Vukmirović, 2020. "Setbacks to IoT Implementation in the Function of FMCG Supply Chain Sustainability during COVID-19 Pandemic," Sustainability, MDPI, vol. 12(18), pages 1-21, September.
    18. Sandeep Jagtap & George Skouteris & Vilendra Choudhari & Shahin Rahimifard & Linh Nguyen Khanh Duong, 2021. "An Internet of Things Approach for Water Efficiency: A Case Study of the Beverage Factory," Sustainability, MDPI, vol. 13(6), pages 1-10, March.
    19. Evans, Olaniyi, 2018. "Digital Agriculture: Mobile Phones, Internet & Agricultural Development in Africa," MPRA Paper 90359, University Library of Munich, Germany.
    20. In Lee, 2020. "Internet of Things (IoT) Cybersecurity: Literature Review and IoT Cyber Risk Management," Future Internet, MDPI, vol. 12(9), pages 1-21, September.

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:eee:ijocip:v:38:y:2022:i:c:s1874548222000373. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Catherine Liu (email available below). General contact details of provider: https://www.journals.elsevier.com/international-journal-of-critical-infrastructure-protection .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.