Illuminating threats: Exploring cybersecurity threats in smart bulbs and illuminating a path to enhanced protection
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE credits
Student thesis
Abstract [en]
There are serious security risks with the growing use of IoT devices. Historically, manufacturers prioritized profit over security due to high demand, a perspective that has evolved but remains a challenge. With this, the security of IoT devices has been overlooked, especially regarding smart bulbs, as they tend to be bundled with other IoT devices by the research community, and consequently not receive the attentionthey require.
This thesis aims to identify and analyze potential threats regarding smart bulbs, and it does so by exploring proactive strategies in order to mitigate vulnerabilities. To understand the challenges smart bulbs face, some of the current applicable legislation, cyber attacks, defense mechanisms, and vulnerabilities were analyzed. Then, a network topology and a data flow diagram of a home network with smart bulbs was developed. Consequently, layers were assigned to the smart bulb, and threat modeling was performed on a each layer using STRIDE. This procedure was then formalized with a framework that encapsulates the stages of analysing the smart bulb’s landscape through threat modeling.
This work contributes to the research community’s body of knowledge by providing valuable insights detailing the smart bulb’s landscape, not only through the framework but also through the conducted threat modeling, the data flow diagrams, and the information gathered regarding the threats to smart bulb security.
Place, publisher, year, edition, pages
2024. , p. v, 44
Keywords [en]
Smart bulb security, Internet of things, threat modeling, framework, design science research
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-23960OAI: oai:DiVA.org:his-23960DiVA, id: diva2:1871562
External cooperation
Knightec AB
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
2024-06-172024-06-172024-06-17Bibliographically approved