错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Software Bill of Materials (SBOM) Approach to IoT Security Vulnerability Assessment

  • James Bonacci,
  • Reese Martin

摘要

This paper presents a study of the security vulnerabilities surrounding Internet of Things (IoT) devices, and how these vulnerabilities can be detected and analyzed utilizing the Software Bill of Materials (SBOM). This methodology allows a user to gain more information about a device than what was available before using tools such as an automated vulnerability scanner. Compared to the information available from current popular security vulnerability scanners, the information gathered from the SBOM approach allows a user to have far more insight into a device’s vulnerabilities and composition. This study emphasizes the importance of the SBOM and how it can be used to assess such security vulnerabilities on a deeper level than automated scanners. In this study, we compare the security vulnerability assessment capabilities of three different methods: NetRise, Tenable OT Security, and the free National Vulnerability Database (NVD) provided by the National Institute of Standards and Technology. NetRise is the method that will be used to demonstrate the capabilities of SBOM security. Tenable OT Security is a traditional vulnerability scanner. The last method used is referencing the NVD. This is the U.S. government repository of vulnerability management data. Limitations and deficiencies of the SBOM approach to security analysis are also addressed throughout the study.