OWASP IoT attack surfaces

As part of OWASP's IoT Project, a non-exhaustive list of attack surfaces has been identified for IoT systems (OWASP-IoT). The list is included here to provide a basic idea of attack surfaces for IoT systems, and it is applicable to IIoT as well and can be used in attack surface-based analysis. You also can visit the OWASP website, provided in the reference section, for further elaboration:

  • Attack surface ecosystem (general)
  • Third-party backend APIs
  • Device memory
  • Update mechanism
  • Device physical interfaces
  • Mobile application
  • Device web interface
  • Vendor backend APIs
  • Device firmware
  • Ecosystem communication
  • Device network service
  • Network traffic
  • Administrative interface
  • Authentication/authorization
  • Local data storage
  • Privacy
  • Cloud web interface
  • Hardware (sensors)
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.216.123.120