Skip to main content

2024 | OriginalPaper | Buchkapitel

A Rapid Review on Software Vulnerabilities and Embedded, Cyber-Physical, and IoT Systems

verfasst von : Alessandro Marchetto, Giuseppe Scanniello

Erschienen in: Product-Focused Software Process Improvement

Verlag: Springer Nature Switzerland

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

This paper presents a Rapid Review (RR) conducted to identify and characterize existing approaches and methods that discover, fix, and manage vulnerabilities in Embedded, Cyber-Physical, and Internet-of-Things systems and software (ESs hereafter). In the last years, a growing interest concerned the adoption of ESs in different domains (e.g., automotive, healthcare) and with different purposes. Modern ESs are heterogeneous, computationally powerful, connected, and intelligent systems characterized by many technologies, devices, and an extensive use of embedded software (SW). Adopting software that could emulate or substitute hardware (HD) components makes the ESs flexible, tunable, and less costly but demands attention to security aspects such as SW vulnerabilities. Vulnerabilities can be exploited by attackers and compromise entire systems. The findings of our RR emerge from 61 papers and can be summarized as follows: (i) complex and connected ESs are studied especially for autonomous vehicles and robots; (ii) new methods and approaches are proposed mainly to discover software-vulnerabilities related to memory management in ES firmware software; and (iii) most of the proposed methods apply fuzzy-based dynamic analysis to binary and executable files of ES software.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Braun, V., Clarke, V.: Using thematic analysis in psychology. Qual. Res. Psychol. 3(2), 77–101 (2006)CrossRef Braun, V., Clarke, V.: Using thematic analysis in psychology. Qual. Res. Psychol. 3(2), 77–101 (2006)CrossRef
3.
Zurück zum Zitat Dessiatnikoff, A., Deswarte, Y., Alata, E., Nicomette, V.: Potential attacks on onboard aerospace systems. IEEE Secur. Priv. 10(4), 71–74 (2012)CrossRef Dessiatnikoff, A., Deswarte, Y., Alata, E., Nicomette, V.: Potential attacks on onboard aerospace systems. IEEE Secur. Priv. 10(4), 71–74 (2012)CrossRef
4.
Zurück zum Zitat Eceiza, M., Flores, J.L., Iturbe, M.: Fuzzing the internet of things: a review on the techniques and challenges for efficient vulnerability discovery in embedded systems. IEEE Internet Things J. 8(13), 10390–10411 (2021)CrossRef Eceiza, M., Flores, J.L., Iturbe, M.: Fuzzing the internet of things: a review on the techniques and challenges for efficient vulnerability discovery in embedded systems. IEEE Internet Things J. 8(13), 10390–10411 (2021)CrossRef
6.
Zurück zum Zitat Fournaris, A.P., Pocero Fraile, L., Koufopavlou, O.: Exploiting hardware vulnerabilities to attack embedded system devices: a survey of potent microarchitectural attacks. Electron. 6(3) (2017). ISSN 2079-9292 Fournaris, A.P., Pocero Fraile, L., Koufopavlou, O.: Exploiting hardware vulnerabilities to attack embedded system devices: a survey of potent microarchitectural attacks. Electron. 6(3) (2017). ISSN 2079-9292
7.
Zurück zum Zitat Papp, D., Ma, Z., Buttyan, L.: Embedded systems security: threats, vulnerabilities, and attack taxonomy, pp. 145–152. IEEE, Turkey (2015) Papp, D., Ma, Z., Buttyan, L.: Embedded systems security: threats, vulnerabilities, and attack taxonomy, pp. 145–152. IEEE, Turkey (2015)
8.
Zurück zum Zitat Qasem, A., Shirani, P., Debbabi, M., Wang, L., Lebel, B., Agba, B.L.: Automatic vulnerability detection in embedded devices and firmware: survey and layered taxonomies. ACM Comput. Surv. 54(2) (2021). https://doi.org/10.1145/3432893. ISSN 0360-0300 Qasem, A., Shirani, P., Debbabi, M., Wang, L., Lebel, B., Agba, B.L.: Automatic vulnerability detection in embedded devices and firmware: survey and layered taxonomies. ACM Comput. Surv. 54(2) (2021). https://​doi.​org/​10.​1145/​3432893. ISSN 0360-0300
9.
Zurück zum Zitat Schotten, M., M’hamed., E., Meester, W., Steiginga, S., Ross, C.: A Brief History of Scopus: The World’s Largest Abstract and Citation Database of Scientific Literature, pp. 31–58. CRC Press, January 2017 Schotten, M., M’hamed., E., Meester, W., Steiginga, S., Ross, C.: A Brief History of Scopus: The World’s Largest Abstract and Citation Database of Scientific Literature, pp. 31–58. CRC Press, January 2017
10.
Zurück zum Zitat Speckemeier, C., Niemann, A., Wasem, J., Buchberger, B., Neusser, S.: Methodological guidance for rapid reviews in healthcare: a scoping review. Res. Synth. Methods 13(4), 394–404 (2022)CrossRef Speckemeier, C., Niemann, A., Wasem, J., Buchberger, B., Neusser, S.: Methodological guidance for rapid reviews in healthcare: a scoping review. Res. Synth. Methods 13(4), 394–404 (2022)CrossRef
Metadaten
Titel
A Rapid Review on Software Vulnerabilities and Embedded, Cyber-Physical, and IoT Systems
verfasst von
Alessandro Marchetto
Giuseppe Scanniello
Copyright-Jahr
2024
DOI
https://doi.org/10.1007/978-3-031-49266-2_32

Premium Partner