
<mods xmlns="http://www.loc.gov/mods/v3" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-4.xsd">
    
    <titleInfo>
        <title>Reflections on the Engineering and Operation of a Large-Scale Embedded Device Vulnerability Scanner</title>
    </titleInfo>
    <name type="personal" ID="ac2024">
        <namePart type="family">Cui</namePart>
        <namePart type="given">Ang</namePart>
        <role>
            <roleTerm type="text">author</roleTerm>
        </role>
        <affiliation>Columbia University. Computer Science</affiliation>
    </name>
    <name type="personal" ID="sjs11">
        <namePart type="family">Stolfo</namePart>
        <namePart type="given">Salvatore</namePart>
        <role>
            <roleTerm type="text">author</roleTerm>
        </role>
        <affiliation>Columbia University. Computer Science</affiliation>
    </name>
    <name type="corporate">
        <namePart>Columbia University. Computer Science</namePart>
        <role>
            <roleTerm type="text">originator</roleTerm>
        </role>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre>Articles</genre>
    
    <originInfo>
        <dateIssued encoding="w3cdtf" keyDate="yes">2011</dateIssued>
        <edition>manuscript version</edition>
    </originInfo>
    
    <language>
        <languageTerm type="text">English</languageTerm>
    </language>
    <abstract>We present important lessons learned from the engineering and operation of a large-scale embedded device vulnerability scanner infrastructure. Developed and refined over the period of one year, our vulnerability scanner monitored large portions of the Internet and was able to identify over 1.1 million publicly accessible trivially vulnerable embedded devices. The data collected has helped us move beyond vague, anecdotal suspicions of embedded insecurity towards a realistic quantitative understanding of the current threat. In this paper, we describe our experimental methodology and reflect on key technical, organizational and social challenges encountered during our research. We also discuss several key technical design missteps and operational failures and their solutions.</abstract>
    <subject>
        <topic>Computer science</topic>
    </subject>
    <subject>
        <topic>Web studies</topic>
    </subject>
    <relatedItem type="host">
        <titleInfo>
            <title>Proceedings of the First Workshop on Building Analysis Datasets and Gathering Experience Returns for Security: BADGERS 2011: April 10, 2011, Salzburg, Austria</title>
        </titleInfo>
        <name type="personal">
            <namePart type="family">Kirda</namePart>
            <namePart type="given">Engin</namePart>
            <role>
                <roleTerm type="text">editor</roleTerm>
            </role>
        </name>
        <name type="personal">
            <namePart type="family">Holz</namePart>
            <namePart type="given">Thorsten</namePart>
            <role>
                <roleTerm type="text">editor</roleTerm>
            </role>
        </name>
        <originInfo>
            <place>
               <placeTerm type="text">New York</placeTerm>
            </place>
            <publisher>ACM Press</publisher>
            <dateIssued encoding="w3cdtf">2011</dateIssued>
        </originInfo>
        <part>
            <extent unit="page">
                <start>8</start>
                <end>18</end>
            </extent>
        </part>
        <identifier type="doi">http://dx.doi.org/10.1145/1978672.1978674</identifier>
        <relatedItem type="series">
            <titleInfo>
                <title></title>
            </titleInfo>
        </relatedItem>
    </relatedItem>
    <identifier type="hdl">http://hdl.handle.net/10022/AC:P:14879</identifier>
    
    <location>
        <physicalLocation authority="marcorg">NNC</physicalLocation>
    </location>
    
    <recordInfo>
        <recordContentSource authority="marcorg">NNC</recordContentSource>
        <recordCreationDate encoding="w3cdtf">2012-10-10 15:48:55 -0400</recordCreationDate>
        <recordChangeDate encoding="w3cdtf">2012-10-10 15:56:05 -0400</recordChangeDate>
        <recordIdentifier>8883</recordIdentifier>
        <languageOfCataloging>
            <languageTerm authority="iso639-2b">eng</languageTerm>
        </languageOfCataloging>
    </recordInfo>
    
</mods>
