Electronic Thesis/Dissertation
 

Machine Learning Framework to Harden IoT Devices Faster

Open Access Deposited

This research develops a data-driven approach to analyze and prioritize software vulnerabilities in Internet of Things (IoT) devices using publicly available data from Common Vulnerabilities and Exposures (CVE) databases, cybersecurity websites, and open-source repositories. Leveraging Python-based machine learning (ML) techniques, the study offers a repeatable methodology to aggregate vulnerability data, identify trends, and prioritize hardening strategies for device categories. The research focuses on original equipment manufacturers (OEMs) with public CVEs over the past decade, the CVE’s Common Vulnerability Scoring System (CVSS) score and the newer Exploit Prediction Scoring System (EPSS) score, to assess predicted cyber-risks and better quantify the return on investment for remediation efforts. By addressing the lack of transparent vulnerability risk-assessment approaches, this study aims to optimize OEMs’ remediation prioritization, improving the effectiveness of vulnerability management programs (VMPs) to reduce delays in patching vulnerabilities most likely to be exploited.The results validated the hypothesis that integrating machine learning cyber-risk predictive vulnerability analysis significantly enhances the prioritization of IoT/OT vulnerabilities compared to traditional CVSS-only methods. This approach demonstrated substantial improvements in accurately identifying vulnerabilities at high risk of exploitation, which can optimize OEMs efforts hardening their IoT/OT “smart” devices.

Author Language Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Johnson_gwu_0075A_17422.pdf File 2025-12-11 Embargo