Sitemap

A list of all the posts and pages found on the site. For you robots out there is an XML version available for digesting as well.

Pages

Posts

Okay, you use password manager, but do your IoT devices get updates regularly?

less than 1 minute read

Published:

TLDR. Do IoT devices update? How is their update practice similar, different, better, or worse than non-IoT devices? Our study examined 2+ years of smart home network traffic data. We found that software components on IoT devices are more outdated than those on non-IoT devices (e.g., computers and phones); and that vendors were slow to roll out updates. These outdated software components presented serious supply chain security risks to the IoT devices.

publications

Publications

Published in , 1900


Assessment of LLM Responses to End-user Security Questions
Vijay Prakash, Kevin Lee, Arkaprabha Bhattacharya, Danny Yuxing Huang, Jessica Staddon
Under submission, 2024

Can Allowlists Capture the Variability of Home IoT Device Network Behavior?
Weijia He, Kevin Bryson, Ricardo Calderon, Vijay Prakash, Nick Feamster, Danny Yuxing Huang, Blase Ur
IEEE, European Symposium on Security and Privacy (EuroS&P). 2024.
[slides]

In the Room Where It Happens: Characterizing Local Communication and Threats in Smart Homes
Aniketh Girish, Tianrui Hu, Vijay Prakash, Daniel J. Dubois, Srdjan Matic, Danny Yuxing Huang, Serge Egelman, Joel Reardon, Juan Tapiador, David Choffnes, Narseo Vallina-Rodriguez
ACM Internet Measurement Conference (IMC), 2023.
[slides]

Behind the Scenes: Uncovering TLS and Server Certificate Practice of IoT Device Vendors in the Wild
Hongying Dong, Hao Shu, Vijay Prakash, Yizhe Zhang, Muhammad Talha Paracha, David Choffnes, Santiago Torres-Arias, Danny Yuxing Huang, Yixin Sun
ACM Internet Measurement Conference (IMC). 2023.

Inferring Software Update Practices on Smart Home IoT Devices Through User Agent Analysis
Vijay Prakash, Sicheng Xie, Danny Yuxing Huang
ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED), 2022.
[slides, pdf]

Examining DES-based Cipher Suite Support within the TLS Ecosystem
Vanessa Frost, Dave (Jing) Tian, Christie Ruales, Vijay Prakash , Patrick Traynor, and Kevin Butler
ACM ASIA Conference on Computer and Communications Security (ASIACCS), 2019.
[pdf]