Threat Modelling and Vulnerability Assessment for IoT Solutions: A Case Study
收藏资源简介:
This replication package accompanies the paper titled "Threat Modelling and Vulnerability Assessment for IoT Solutions: A Case Study", which investigates how industry practitioners perform threat modelling and vulnerability assessment in real-world IoT software development. Through a case study in collaboration with an IoT-focused company, the paper explores how security practices such as threat identification and vulnerability testing are integrated into the development lifecycle. The study combines semi-structured interviews with artefact analysis to identify common security challenges and practices. Key contributions include a thematic map of findings, tool recommendations, and guidelines for improving security practices in IoT development. Contents of the Replication Package This package contains the protocols and outputs from the interview study and artefact analysis that support the findings presented in the paper.
本复现包配套于题为《物联网解决方案的威胁建模与漏洞评估:一项案例研究》(Threat Modelling and Vulnerability Assessment for IoT Solutions: A Case Study)的论文,该论文聚焦探讨行业从业者如何在真实物联网(IoT)软件开发场景中开展威胁建模与漏洞评估工作。 本研究通过与一家专注物联网(IoT)的企业合作开展案例研究,探究了威胁识别、漏洞测试等安全实践如何融入软件开发全生命周期。本次研究结合半结构化访谈与制品分析,梳理出物联网开发中常见的安全挑战与成熟实践方案。其核心贡献包括研究发现的主题映射图谱、工具推荐清单,以及用于优化物联网(IoT)开发安全实践的规范性指南。 复现包内容说明 本复现包包含支撑论文中所述研究发现的访谈研究与制品分析相关的协议文件及输出结果。



