Audit of IoT networks: assessing vulnerabilities and protecting against cyber attacks
Yuriy Pidlisnyi · TECHNICAL SCIENCES AND TECHNOLOGIES · 2025
This article addresses current challenges in ensuring security within the Internet of Things (IoT) networks, taking into account the modern challenges of the digital transformation era. The key risks associated with the use of IoT devices are outlined: the limitations of built-in security mechanisms, the lack of unified standards, hardware resource constraints, and the complexity of managing heterogeneous environments. Special attention is given to the role of security auditing as a tool for identifying vulnerabilities, assessing risks, and developing strategies to counter cyber threats. Existing auditing approaches, including reactive (retroactive), proactive, and incremental methods, are analyzed in the context of IoT environments. A comparative analysis of IoT system architectures—centralized, decentralized, and hybrid—is provided, highlighting their impact on security. A test model of an IoT network is proposed for practical threat modeling and auditing procedure verification. The article also focuses on modern risk management methodologies, including: ISO/IEC 27005, NIST RMF, OCTAVE, EBIOS, FAIR, COBIT, and CRAMM. The advantages and disadvantages of each are discussed in the context of IoT, emphasizing the suitability of the EBIOS methodology as the most adaptable for complex hybrid systems. The article also stresses the need for the improvement of security policies, adaptation of standards, and the development of auditing procedures that address both technical and organizational aspects of IoT operations. The main goal is to contribute to the creation of a reliable, scalable, and threat-resistant IoT ecosystem.