As technology becomes more widely available, millions of users worldwide have installed some form of smart device in their homes or workplaces. These devices are often off-the-shelf commodity systems, such as Google Home or Samsung SmartThings, that are installed by end-users looking to automate a small deployment. In contrast to these "plug-and-play" systems, purpose-built Enterprise Internet-of-Things (E-IoT) systems such as Crestron, Control4, RTI, Savant offer a smart solution for more sophisticated applications (e.g., complete lighting control, A/V management, security). In contrast to commodity systems, E-IoT systems are usually closed source, costly, require certified installers, and are overall more robust for their use cases. Due to this, E-IoT systems are often found in expensive smart homes, government and academic conference rooms, yachts, and smart private offices. However, while there has been plenty of research on the topic of commodity systems, no current study exists that provides a complete picture of E-IoT systems, their components, and relevant threats. As such, lack of knowledge of E-IoT system threats, coupled with the cost of E-IoT systems has led many to assume that E-IoT systems are secure. To address this research gap, raise awareness on E-IoT security, and motivate further research, this work emphasizes E-IoT system components, E-IoT vulnerabilities, solutions, and their security implications. In order to systematically analyze the security of E-IoT systems, we divide E-IoT systems into four layers: E-IoT Devices Layer, Communications Layer, Monitoring and Applications Layer, and Business Layer. We survey attacks and defense mechanisms, considering the E-IoT components at each layer and the associated threats. In addition, we present key observations in state-of-the-art E-IoT security and provide a list of open research problems that need further research.
翻译:随着技术的普及,全世界数百万用户在家中或工作场所安装了某种形式的智能装置。这些装置往往是现成的商品系统,如谷歌家园或三星智能系统,这些装置是终端用户安装的,目的是实现小规模部署的自动化。与这些“插接和游戏”系统、特制企业互联网(E-IoT)系统(E-IoT)系统(E-I-I)系统(E-I-I)不同,例如Crestron、Calt4、RTI、Savant等系统为更系统的复杂应用(例如,完全的照明控制、A/V管理、安全 )提供了一种智能的解决方案。与商品系统不同,E-I系统通常是封闭源,费用昂贵,需要认证安装系统,而且总体而言,电子-I系统(E-I)往往在昂贵的智能家庭、政府和学术会议室、游艇和智能私人办公室中找到。然而,关于商品系统问题的研究、进一步的研究、目前没有为E-I-T系统提供完整的信息差距、其组件和相关威胁。