Using Experimentation to Evaluate Security Requirements in IoT Software Systems

Bruno Pedraça de Souza, Bruno D. de Paiva, Guilherme Horta Travassos · 2023

Security requirements are critical success factors for Internet of Things (IoT) software systems due to how they can mitigate vulnerabilities, for instance, prevent unauthorized access to system and device data by third parties, assuring the final quality of the software system. Then, problems related to security requirements and vulnerabilities must be addressed in the early stage of IoT development projects. In this way, Continuous Experimentation (CE) is a promising software construction practice to observe alternative security and vulnerability solutions. Thus, this paper evaluates security requirements based on the vulnerabilities of IoT software systems using such CE. First, we identified an evidence-based set of IoT vulnerability issues to be assessed. Thus, this work reports an exploratory study using CE to mitigate some vulnerabilities in IoT software systems, indicating that not all security requirements can be worked out with CE. Therefore, further studies are necessary to categorize the IoT software systems vulnerabilities that can be mitigated using continuous experimentation.

Read the paper · More papers on PaperTik