SAFER: Development and Evaluation of an IoT Device Risk Assessment Framework in a Multinational Organization

07/29/2020
by   Pascal Oser, et al.
0

Users of Internet of Things (IoT) devices are often unaware of their security risks and cannot sufficiently factor security considerations into their device selection. This puts networks, infrastructure and users at risk. We developed and evaluated SAFER, an IoT device risk assessment framework designed to improve users' ability to assess the security of connected devices. We deployed SAFER in a large multinational organization that permits use of private devices. To evaluate the framework, we conducted a mixed-method study with 20 employees. Our findings suggest that SAFER increases users' awareness of security issues. It provides valuable advice and impacts device selection. Based on our findings, we discuss implications for the design of device risk assessment tools, with particular regard to the relationship between risk communication and user perceptions of device complexity.

READ FULL TEXT

page 6

page 14

research
11/23/2021

Is this IoT Device Likely to be Secure? Risk Score Prediction for IoT Devices Using Gradient Boosting Machines

Security risk assessment and prediction are critical for organisations d...
research
05/14/2020

MagicPairing: Apple's Take on Securing Bluetooth Peripherals

Device pairing in large Internet of Things (IoT) deployments is a challe...
research
10/26/2017

Situational Awareness based Risk-Adapatable Access Control in Enterprise Networks

As the computing landscape evolves towards distributed architectures suc...
research
02/18/2023

Security of IT/OT Convergence: Design and Implementation Challenges

IoT is undoubtedly considered the future of the Internet. Many sectors a...
research
04/03/2023

What You See is Not What You Get: The Role of Email Presentation in Phishing Susceptibility

Phishing is one of the most prevalent social engineering attacks that ta...

Please sign up or login with your details

Forgot password? Click here to reset