본문

서브메뉴

Towards Evaluating the Security Risks of Using Third-Party Components in IoT Firmware
Towards Evaluating the Security Risks of Using Third-Party Components in IoT Firmware
Towards Evaluating the Security Risks of Using Third-Party Components in IoT Firmware

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20260209102913
ISBN  
9798265406675
DDC  
000
저자명  
Zhao, Binbin.
서명/저자  
Towards Evaluating the Security Risks of Using Third-Party Components in IoT Firmware
발행사항  
[Sl] : Georgia Institute of Technology, 2023
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2023
형태사항  
158 p
주기사항  
Source: Dissertations Abstracts International, Volume: 87-05, Section: A.
주기사항  
Advisor: Beyah, Raheem.
학위논문주기  
Thesis (Ph.D.)--Georgia Institute of Technology, 2023.
초록/해제  
요약1.1 Problem StatementThe Internet of Things (IoT) has become an essential part of Internet connectivity and offered great convenience to our daily lives. For instance, router changes the way of surfing the Internet; smart door lock avoids the cumbersome process of door opening; voice assistant (e.g., Amazon Echo and Google Home) enables us to interact with Internet services and other smart devices through voice commands. Second, developers may fail to strictly follow the API specifications when adopting TPCs, resulting in the TPC usage violation problem, which is typically caused by a set of API misuses, e.g., unchecked return value and incorrect invocation sequence. Many previous works have indicated that the API misuse will introduce serious security implications [5, 6, 7, 8, 9, 10]. For instance, the incorrect use of OpenSSL APIs can cause Man-In-The-Middle attacks [11, 12]. To make things worse, vendors may reuse TPCs with known vulnerabilities or misused APIs in different firmware, or call misused APIs multiple times in firmware, leading to aggravated security risks caused by TPCs.
일반주제명  
Firmware
일반주제명  
Violations
일반주제명  
Search engines
일반주제명  
Third party
일반주제명  
Computer science
일반주제명  
Information technology
일반주제명  
Web studies
기타저자  
Georgia Institute of Technology.
기본자료저록  
Dissertations Abstracts International. 87-05A.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008260203s2023        us                              c    eng  d
■001000017366010
■00520260209102913
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798265406675
■035    ▼a(MiAaPQ)AAI32316186
■035    ▼a(MiAaPQ)GeorgiaTech72688
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a000
■1001  ▼aZhao,  Binbin.
■24510▼aTowards  Evaluating  the  Security  Risks  of  Using  Third-Party  Components  in  IoT  Firmware
■260    ▼a[Sl]▼bGeorgia  Institute  of  Technology▼c2023
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2023
■300    ▼a158  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  87-05,  Section:  A.
■500    ▼aAdvisor:  Beyah,  Raheem.
■5021  ▼aThesis  (Ph.D.)--Georgia  Institute  of  Technology,  2023.
■520    ▼a1.1  Problem  StatementThe  Internet  of  Things  (IoT)  has  become  an  essential  part  of  Internet  connectivity  and  offered  great  convenience  to  our  daily  lives.  For  instance,  router  changes  the  way  of  surfing  the  Internet;  smart  door  lock  avoids  the  cumbersome  process  of  door  opening;  voice  assistant  (e.g.,  Amazon  Echo  and  Google  Home)  enables  us  to  interact  with  Internet  services  and  other  smart  devices  through  voice  commands.  Second,  developers  may  fail  to  strictly  follow  the  API  specifications  when  adopting  TPCs,  resulting  in  the  TPC  usage  violation  problem,  which  is  typically  caused  by  a  set  of  API  misuses,  e.g.,  unchecked  return  value  and  incorrect  invocation  sequence.  Many  previous  works  have  indicated  that  the  API  misuse  will  introduce  serious  security  implications  [5,  6,  7,  8,  9,  10].  For  instance,  the  incorrect  use  of  OpenSSL  APIs  can  cause  Man-In-The-Middle  attacks  [11,  12].  To  make  things  worse,  vendors  may  reuse  TPCs  with  known  vulnerabilities  or  misused  APIs  in  different  firmware,  or  call  misused  APIs  multiple  times  in  firmware,  leading  to  aggravated  security  risks  caused  by  TPCs.
■590    ▼aSchool  code:  0078.
■650  4▼aFirmware
■650  4▼aViolations
■650  4▼aSearch  engines
■650  4▼aThird  party
■650  4▼aComputer  science
■650  4▼aInformation  technology
■650  4▼aWeb  studies
■690    ▼a0984
■690    ▼a0489
■690    ▼a0646
■71020▼aGeorgia  Institute  of  Technology.
■7730  ▼tDissertations  Abstracts  International▼g87-05A.
■790    ▼a0078
■791    ▼aPh.D.
■792    ▼a2023
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17366010▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF16762 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.