Machine Learning Framework to Harden IoT Devices Faster
Open Access DepositedDownloadable Content
This research develops a data-driven approach to analyze and prioritize software vulnerabilities in Internet of Things (IoT) devices using publicly available data from Common Vulnerabilities and Exposures (CVE) databases, cybersecurity websites, and open-source repositories. Leveraging Python-based machine learning (ML) techniques, the study offers a repeatable methodology to aggregate vulnerability data, identify trends, and prioritize hardening strategies for device categories. The research focuses on original equipment manufacturers (OEMs) with public CVEs over the past decade, the CVE’s Common Vulnerability Scoring System (CVSS) score and the newer Exploit Prediction Scoring System (EPSS) score, to assess predicted cyber-risks and better quantify the return on investment for remediation efforts. By addressing the lack of transparent vulnerability risk-assessment approaches, this study aims to optimize OEMs’ remediation prioritization, improving the effectiveness of vulnerability management programs (VMPs) to reduce delays in patching vulnerabilities most likely to be exploited.The results validated the hypothesis that integrating machine learning cyber-risk predictive vulnerability analysis significantly enhances the prioritization of IoT/OT vulnerabilities compared to traditional CVSS-only methods. This approach demonstrated substantial improvements in accurately identifying vulnerabilities at high risk of exploitation, which can optimize OEMs efforts hardening their IoT/OT “smart” devices.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.