Software updates are critical for ensuring systems remain free of bugs and vulnerabilities while they are in service. While many Internet of Things (IoT) devices are capable of outlasting desktops and mobile phones, their software update practices are not yet well understood, despite a large body of research aiming to create new methodologies for keeping IoT devices up to date. This paper discusses efforts towards characterizing the IoT software update landscape through network-level analysis of IoT device traffic. Our results suggest that vendors do not currently follow security best practices, and that software update standards, while available, are not being deployed.
翻译:软件更新对于确保系统在使用过程中免受漏洞和缺陷的影响至关重要。尽管许多物联网(IoT)设备的使用寿命可能超过台式机和移动电话,但尽管已有大量研究致力于创建保持物联网设备更新的新方法,其软件更新实践仍未被充分理解。本文探讨了通过对物联网设备流量进行网络级分析来表征物联网软件更新现状的努力。我们的研究结果表明,供应商目前并未遵循安全最佳实践,且软件更新标准虽已存在,但并未得到部署。