IDEAS home Printed from https://ideas.repec.org/a/vrs/poicbe/v17y2023i1p959-968n9.html
   My bibliography  Save this article

Improving Internet of Things Vulnerability Disclosure and Coordination

Author

Listed:
  • Berte Dan-Radu

    (Santa Clara, California, USA)

Abstract

Internet of Things (“IoT”), specifically in the consumer space, describes an environment where consumer devices, connected to the Internet in a smart home, communicate to each other directly or through the cloud. Cheap manufacturing and a fast-growing market brought billions such devices in everyday homes, and consequently new concerns emerged about their security. The complexity added by these new systems, with fragmented in-house hardware and software platforms, have been recently the target of both scrutiny and controversy. When IoT devices get hacked it’s no longer just “script kiddies” and part-time hackers, it’s state actors and national security on the line. Where for PCs there is a robust cybersecurity product market (eg. “antivirus”), the majority of IoT devices in households are designed with little or no regard towards cybersecurity and the typical consumer’s understanding of how to secure these is lacking. Effective ways to safeguard IoT products are bug bounties, programs that offer a financial reward to anyone discovering vulnerabilities, but they are costly and hard to manage, thus usually adopted by more mature companies. All manufacturers can additionally benefit from responsible vulnerability disclosure, or ethical hacking, where researchers attempt to find vulnerabilities for recognition or as a public service. Unfortunately disclosing and coordinating vulnerability research challenges are downplayed. This paper proposes to investigate impact, discuss time considerations, and suggest potential solutions for consumers, companies, and regulators to mitigate and improve IoT vulnerability reporting, fixing and disclosure.

Suggested Citation

  • Berte Dan-Radu, 2023. "Improving Internet of Things Vulnerability Disclosure and Coordination," Proceedings of the International Conference on Business Excellence, Sciendo, vol. 17(1), pages 959-968, July.
  • Handle: RePEc:vrs:poicbe:v:17:y:2023:i:1:p:959-968:n:9
    DOI: 10.2478/picbe-2023-0087
    as

    Download full text from publisher

    File URL: https://doi.org/10.2478/picbe-2023-0087
    Download Restriction: no

    File URL: https://libkey.io/10.2478/picbe-2023-0087?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:vrs:poicbe:v:17:y:2023:i:1:p:959-968:n:9. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Peter Golla (email available below). General contact details of provider: https://www.sciendo.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.