IoT Security Best Practices
ICT & Cyber Security
Client company:INTERSCT.
Raphael Galli
Freek van Lier
Bas Weijs
Victor Florea
Ivan Arbaliev
Stefan Rachev
Sjors Loomans
Project description
This project aims to contribute to the IoT security knowledge base by testing consumer IoT devices for vulnerabilities and compliance with security best practices. The scope of the project also includes the exploration of novel tools and techniques to facilitate the investigation and pentesting of IoT devices.
Context
Our project is part of INTERSCT. INTERSCT's goal is to tackle the problem of IoT security integrally from various different, and complementary, perspectives. Fontys participates in INTERSCT by creating a knowledge base for IoT security with guidelines, best practices and tooling.
Results
This semester, we have tested a variety of consumer IoT devices, including an internet camera and the Philips Hue, for vulnerabilities and compliance with security best practices. We have also looked into new tooling to research IoT devices and set up a lab to test IoT devices in a controlled environment.