Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk

The introduction of the Internet of Things (IoT), i.e., the interconnection of embedded devices over the Internet, has changed the world we live in from the way we measure, make calls, print information and even the way we get energy in our offices or homes. The convenience of IoT products, like clo...

Full description

Bibliographic Details
Main Authors: Sharad Agarwal, Pascal Oser, Stefan Lueders
Format: Article
Language:English
Published: MDPI AG 2019-09-01
Series:Sensors
Subjects:
Online Access:https://www.mdpi.com/1424-8220/19/19/4107
_version_ 1811185202520653824
author Sharad Agarwal
Pascal Oser
Stefan Lueders
author_facet Sharad Agarwal
Pascal Oser
Stefan Lueders
author_sort Sharad Agarwal
collection DOAJ
description The introduction of the Internet of Things (IoT), i.e., the interconnection of embedded devices over the Internet, has changed the world we live in from the way we measure, make calls, print information and even the way we get energy in our offices or homes. The convenience of IoT products, like closed circuit television (CCTV) cameras, internet protocol (IP) phones, and oscilloscopes, is overwhelming for end users. In parallel, however, security issues have emerged and it is essential for infrastructure providers to assess the associated security risks. In this paper, we propose a novel method to detect IoT devices and identify the manufacturer, device model, and the firmware version currently running on the device using the page source from the web user interface. We performed automatic scans of the large-scale network at the European Organization for Nuclear Research (CERN) to evaluate our approach. Our tools identified 233 IoT devices that fell into eleven distinct device categories and included 49 device models manufactured by 26 vendors from across the world.
first_indexed 2024-04-11T13:25:24Z
format Article
id doaj.art-2b03dd7daf1348deaf588d3e29e3f709
institution Directory Open Access Journal
issn 1424-8220
language English
last_indexed 2024-04-11T13:25:24Z
publishDate 2019-09-01
publisher MDPI AG
record_format Article
series Sensors
spelling doaj.art-2b03dd7daf1348deaf588d3e29e3f7092022-12-22T04:22:05ZengMDPI AGSensors1424-82202019-09-011919410710.3390/s19194107s19194107Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security RiskSharad Agarwal0Pascal Oser1Stefan Lueders2CMS Experiment, European Organization for Nuclear Research (CERN), 1211 Geneva, SwitzerlandCERN Computer Security Team, European Organization for Nuclear Research (CERN), 1211 Geneva, SwitzerlandCERN Computer Security Team, European Organization for Nuclear Research (CERN), 1211 Geneva, SwitzerlandThe introduction of the Internet of Things (IoT), i.e., the interconnection of embedded devices over the Internet, has changed the world we live in from the way we measure, make calls, print information and even the way we get energy in our offices or homes. The convenience of IoT products, like closed circuit television (CCTV) cameras, internet protocol (IP) phones, and oscilloscopes, is overwhelming for end users. In parallel, however, security issues have emerged and it is essential for infrastructure providers to assess the associated security risks. In this paper, we propose a novel method to detect IoT devices and identify the manufacturer, device model, and the firmware version currently running on the device using the page source from the web user interface. We performed automatic scans of the large-scale network at the European Organization for Nuclear Research (CERN) to evaluate our approach. Our tools identified 233 IoT devices that fell into eleven distinct device categories and included 49 device models manufactured by 26 vendors from across the world.https://www.mdpi.com/1424-8220/19/19/4107Internet of Thingssecurityvulnerabilities and protective measurescontrol network securityoperation in multi-user environmentsrisk assessment
spellingShingle Sharad Agarwal
Pascal Oser
Stefan Lueders
Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk
Sensors
Internet of Things
security
vulnerabilities and protective measures
control network security
operation in multi-user environments
risk assessment
title Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk
title_full Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk
title_fullStr Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk
title_full_unstemmed Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk
title_short Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk
title_sort detecting iot devices and how they put large heterogeneous networks at security risk
topic Internet of Things
security
vulnerabilities and protective measures
control network security
operation in multi-user environments
risk assessment
url https://www.mdpi.com/1424-8220/19/19/4107
work_keys_str_mv AT sharadagarwal detectingiotdevicesandhowtheyputlargeheterogeneousnetworksatsecurityrisk
AT pascaloser detectingiotdevicesandhowtheyputlargeheterogeneousnetworksatsecurityrisk
AT stefanlueders detectingiotdevicesandhowtheyputlargeheterogeneousnetworksatsecurityrisk