Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart Refrigerator

Internet of things (IoT) devices are becoming more prevalent. Due to a rapidly growing market of these appliances, improper security measures lead to an expanding range of attacks. There is a devoir of testing and securing these devices to contribute to a more sustainable society. This thesis has ev...

Full description

Bibliographic Details
Main Authors: Radholm, Fredrik, Abefelt, Niklas
Format: Others
Language:English
Published: KTH, Skolan för elektroteknik och datavetenskap (EECS) 2020
Subjects:
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-280295
id ndltd-UPSALLA1-oai-DiVA.org-kth-280295
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-kth-2802952020-09-08T17:32:31ZEthical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart RefrigeratorengRadholm, FredrikAbefelt, NiklasKTH, Skolan för elektroteknik och datavetenskap (EECS)KTH, Skolan för elektroteknik och datavetenskap (EECS)2020Internet of things (IoT)devicesecuritypenetration testingthreat assessmentvulnerabilitiesInternet of things (IoT)enhetsäkerhetpenetrationstesterhotbedömningsårbarheterComputer and Information SciencesData- och informationsvetenskapInternet of things (IoT) devices are becoming more prevalent. Due to a rapidly growing market of these appliances, improper security measures lead to an expanding range of attacks. There is a devoir of testing and securing these devices to contribute to a more sustainable society. This thesis has evaluated the security of an IoT-refrigerator by using ethical hacking, where a threat model was produced to identify vulnerabilities. Penetration tests were performed based on the threat model. The results from the penetration tests did not find any exploitable vulnerabilities. The conclusion from evaluating the security of this Samsung refrigerator can say the product is secure and contributes to a connected, secure, and sustainable society. Internet of Things (IoT) enheter blir mer allmänt förekommande. På grund av en snabbt expanderande marknad av dessa apparater, har bristfälliga säkerhetsåtgärder resulterat till en mängd olika attacker. Det finns ett behov att testa dessa enheter for att bidra till ett mer säkert och hållbart samhälle. Denna avhandling har utvärderat säkerheten av ett IoT-kylskåp genom att producera en hot modell för att identifiera sårbarheter. Penetrationstester har utförts på enheten, baserade på hot modellen. Resultatet av penetrationstesterna hittade inga utnyttjningsbara sårbarheter. Slutsatsen från utvärderingen av säkerheten på Samsung-kylskåpet är att produkten är säker och bidrar till ett uppkopplat, säkert, och hållbart samhälle. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-280295TRITA-EECS-EX ; 2020:476application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
topic Internet of things (IoT)
device
security
penetration testing
threat assessment
vulnerabilities
Internet of things (IoT)
enhet
säkerhet
penetrationstester
hotbedömning
sårbarheter
Computer and Information Sciences
Data- och informationsvetenskap
spellingShingle Internet of things (IoT)
device
security
penetration testing
threat assessment
vulnerabilities
Internet of things (IoT)
enhet
säkerhet
penetrationstester
hotbedömning
sårbarheter
Computer and Information Sciences
Data- och informationsvetenskap
Radholm, Fredrik
Abefelt, Niklas
Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart Refrigerator
description Internet of things (IoT) devices are becoming more prevalent. Due to a rapidly growing market of these appliances, improper security measures lead to an expanding range of attacks. There is a devoir of testing and securing these devices to contribute to a more sustainable society. This thesis has evaluated the security of an IoT-refrigerator by using ethical hacking, where a threat model was produced to identify vulnerabilities. Penetration tests were performed based on the threat model. The results from the penetration tests did not find any exploitable vulnerabilities. The conclusion from evaluating the security of this Samsung refrigerator can say the product is secure and contributes to a connected, secure, and sustainable society. === Internet of Things (IoT) enheter blir mer allmänt förekommande. På grund av en snabbt expanderande marknad av dessa apparater, har bristfälliga säkerhetsåtgärder resulterat till en mängd olika attacker. Det finns ett behov att testa dessa enheter for att bidra till ett mer säkert och hållbart samhälle. Denna avhandling har utvärderat säkerheten av ett IoT-kylskåp genom att producera en hot modell för att identifiera sårbarheter. Penetrationstester har utförts på enheten, baserade på hot modellen. Resultatet av penetrationstesterna hittade inga utnyttjningsbara sårbarheter. Slutsatsen från utvärderingen av säkerheten på Samsung-kylskåpet är att produkten är säker och bidrar till ett uppkopplat, säkert, och hållbart samhälle.
author Radholm, Fredrik
Abefelt, Niklas
author_facet Radholm, Fredrik
Abefelt, Niklas
author_sort Radholm, Fredrik
title Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart Refrigerator
title_short Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart Refrigerator
title_full Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart Refrigerator
title_fullStr Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart Refrigerator
title_full_unstemmed Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing : A Survey on Security of a Smart Refrigerator
title_sort ethical hacking of an iot-device: threat assessment and penetration testing : a survey on security of a smart refrigerator
publisher KTH, Skolan för elektroteknik och datavetenskap (EECS)
publishDate 2020
url http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-280295
work_keys_str_mv AT radholmfredrik ethicalhackingofaniotdevicethreatassessmentandpenetrationtestingasurveyonsecurityofasmartrefrigerator
AT abefeltniklas ethicalhackingofaniotdevicethreatassessmentandpenetrationtestingasurveyonsecurityofasmartrefrigerator
_version_ 1719339464486027264