Sustainable Security: Exploring Longevity Challenges and Solutions for IoT
Bibliographic record
Abstract
The Internet of Things (IoT) has become increasingly integrated with our everyday lives providing physical and direct value to societies across the world.While small embedded devices are increasingly becoming integrated into products by IoT device vendors, so do our concerns about the longevity of these integrations.Unlike generalpurpose computers, IoT devices are expected to be in service for long periods of time.While an IoT device may only need to perform simple tasks over its lifespan, the surrounding networked environment and potential threats will evolve.To ensure that IoT devices remain secure over extended periods and are not compromised by adversaries, they need to be supported throughout their entire lifespan.This places a significant burden on device vendors who are reluctant, and sometimes technically unable to maintain software for decades after deployment.In this thesis, we examine IoT device longevity through the lens of security.Specifically, we are interested in the aspects of IoT device security that limits device longevity.To begin, we focus on understanding the current landscape of software updates in IoT.To our knowledge, software update practices in current IoT devices i are not yet well understood, despite a large body of research aiming to create new methodologies for keeping IoT devices up to date.We then discuss a major shortcoming of current software update systems for IoT, which is characterized by a single point of failure: the IoT device vendor.Without support and updates from the device vendor, the software for the IoT device will become outdated and may experience negative consequences due to the constantly evolving security landscape.To overcome this challenge, we propose a new vendor agility approach for IoT device longevity.This approach would allow devices to receive support from sources beyond their first-party vendors.Finally, we implement part of our vendor agility model to demonstrate feasibility on embedded devices.Our aim is to demonstrate how cross-platform embedded code can be created without the need for proprietary tools.Our proof of concept serves as a starting point for future research and work to break the dependency between devices and vendors, enabling long-term support and security for embedded systems.Finally, I would like to thank my friends and family for their support and encouragement -this milestone would not have been possible without your support.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.001 | 0.002 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.001 | 0.001 |
| Science and technology studies | 0.001 | 0.002 |
| Scholarly communication | 0.004 | 0.011 |
| Open science | 0.001 | 0.003 |
| Research integrity | 0.002 | 0.002 |
| Insufficient payload (model declined to judge) | 0.004 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".