Skip to main navigation Skip to search Skip to main content

Bits and Pieces: Piecing Together Factors of IoT Vulnerability Exploitation

Research output: Chapter in Book/Conference proceedings/Edited volumeConference contributionScientificpeer-review

18 Downloads (Pure)

Abstract

The proliferation of Internet of Things (IoT) devices has led to a surge in vulnerabilities, with traditional metrics like CVSS and PoC exploits failing to fully explain exploitation patterns. To address this, we leverage features from the-state-of-the-art prediction model EPSS – such as CVSS, CWE, vendors, external references, vulnerability age, and PoCs – and combine it with new features derived from hacking communities. Our study of 23,373 IoT-related CVEs and 25k posts from 25 hacking forums highlights the importance of including insights on attacker behavior from discussions involving vulnerabilities. We identified 38 features with a p-value < 0.05 that impact attackers’ selection of IoT vulnerabilities. We use two metrics to evaluate our model with features from hacking forums: McFadden’s pseudo R2, which showed a 21% improvement in explaining variance, and the Brier score for prediction accuracy, with a 17% improvement over EPSS. These results emphasize that current state-of-the-art methods struggle to capture the distinct nuances and complexity of IoT threats, and incorporating available information such as insights into attacker behavior can enhance the factors influencing the targeting of IoT vulnerability better.
Original languageEnglish
Title of host publicationASIA CCS '25: Proceedings of the 20th ACM Asia Conference on Computer and Communications Security
Place of PublicationNew York, NY
PublisherAssociation for Computing Machinery (ACM)
Pages1032-1049
Number of pages18
ISBN (Electronic)979-8-4007-1410-8
DOIs
Publication statusPublished - 2025
Event20th ACM ASIA Conference on Computer and Communications Security, ASIA CCS 2025 - Hanoi, Vietnam
Duration: 25 Aug 202529 Aug 2025
https://asiaccs2025.hust.edu.vn/

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery (ACM)
ISSN (Print)1543-7221

Conference

Conference20th ACM ASIA Conference on Computer and Communications Security, ASIA CCS 2025
Country/TerritoryVietnam
CityHanoi
Period25/08/2529/08/25
Internet address

Keywords

  • Exploits
  • IoT
  • Underground forums
  • Vulnerability

Fingerprint

Dive into the research topics of 'Bits and Pieces: Piecing Together Factors of IoT Vulnerability Exploitation'. Together they form a unique fingerprint.

Cite this