Research
I work on sustainable security for embedded and IoT systems. I study how devices, their firmware, and the people who maintain them can stay secure for decades, well beyond a single product cycle. My research sits between systems security, software supply chains, and the long tail of devices that outlive their vendors.
Publications
2023
-
Sustainable Security: Exploring Longevity Challenges and Solutions for IoT.
Carleton University · School of Computer Science (master's thesis).abstract
The Internet of Things (IoT) has become increasingly integrated with our everyday lives providing physical and direct value to societies across the world. While small embedded devices are increasingly becoming integrated into products by IoT device vendors, so are our concerns about the longevity of these integrations. Unlike general-purpose computers, IoT devices are expected to be in service for long periods. While an IoT device may only need to perform simple tasks over its lifespan, the surrounding networked environment and potential threats will evolve. To ensure that IoT devices remain secure, they need to be supported throughout their entire lifespan. This places a significant burden on reluctant device vendors, and sometimes technically unable to maintain software for decades after deployment. We propose solutions for supporting IoT devices after vendor support ends based on the concept of longevity as a new security paradigm.
bibtex
@mastersthesis{bradley2023sustainable, author = {Conner Bradley}, title = {Sustainable Security: Exploring Longevity Challenges and Solutions for IoT}, school = {Carleton University}, year = {2023}, month = sep, type = {Master's thesis} } -
Escaping Vendor Mortality: A New Paradigm for Extending IoT Device Longevity.
NSPW 2023.abstract
Internet of Things (IoT) devices are increasingly being treated as disposable, becoming unsupported shortly after deployment and ending up in landfills prematurely. IoT manufacturers lock devices to their ecosystems and prioritize the development of new devices over the support of legacy product lines. This paper argues that a paradigm shift is needed to increase IoT device longevity. We review the unique challenges that IoT manufacturers face in extending device lifetimes, and identify software and security updates as a key requirement for device longevity. We propose a new IoT device software stack and lifecycle that allows devices to continue safe operation even after the vendor disappears. While we recognize that the sustainable design and management of IoT devices is a complex sociotechnical problem, we hope that the ideas in this paper helps guide future discussions on this important topic.
bibtex
@inproceedings{bradley2023escaping, author = {Bradley, Conner and Barrera, David}, title = {Escaping Vendor Mortality: A New Paradigm for Extending IoT Device Longevity}, booktitle = {New Security Paradigms Workshop (NSPW)}, year = {2023}, doi = {10.1145/3633500.3633501} } -
Poster: Improving Legacy IoT Device Security through Open-Source Intervention.
NDSS 2023 (poster).abstract
When a vendor can no longer support an Internet of Things (IoT) device, what is next? With the rapid growth of IoT, vendors are constantly motivated to develop new products to keep up with market demands. Over time, older products become “legacy” or “unsupported” by vendors and no longer receive software updates and security patches. Due to the long- term deployment nature of many IoT devices, they may remain active for years with several unpatched vulnerabilities. We first examine the security threat that unsupported and unpatched devices pose to IoT ecosystems, and then propose a model that enables legacy IoT devices to transition to an open-source support model while respecting the original vendor’s intellectual property.
2022
-
Toward Identification and Characterization of IoT Software Update Practices: Awarded best paper runner-up.
FPS 2022.abstract
Software updates are critical for ensuring systems remain free of bugs and vulnerabilities while they are in service. While many Internet of Things (IoT) devices are capable of outlasting desktops and mobile phones, their software update practices are not yet well understood, despite a large body of research aiming to create new methodologies for keeping IoT devices up to date. This paper discusses efforts towards characterizing the IoT software update landscape through network-level analysis of IoT device traffic. Our results suggest that vendors do not currently follow security best practices, and that software update standards, while available, are not being deployed.
bibtex
@inproceedings{bradley2022iot, author = {Bradley, Conner and Barrera, David}, title = {Toward Identification and Characterization of IoT Software Update Practices}, booktitle = {Foundations and Practice of Security (FPS)}, year = {2022}, doi = {10.1007/978-3-031-30122-3_25} }
2021
-
Extending Heterogeneous Recommenders Beyond First-Party Datasets.
Carleton University · School of Computer Science (honours thesis).abstract
In today's day in age, recommender systems are ubiquitous among e-commerce players, advertising agencies, and social media platforms. The main premise of a recommender system is relatively simple: based on a temporally learned dataset, make effective guesses and predictions to find entities relevant to the user. Therefore, the data being leveraged to make these guesses is integral to the success of the system's accuracy. Many companies purchase datasets derived by online advertising firms; however, can these preference datasets be mined through third parties, such as Twitter? Furthermore, there has been significant developments in the area of heterogeneous recommender systems. Many platforms focus on homogeneous data as their platform does not span multiple domains of data; however, for the vast majority of platforms there is a strong heterogeneity in the domains that are spanned (i.e, Amazon). This paper explores data mining for heterogeneous recommender systems, namely mining relevant data from Twitter, along with the interaction with the third party datasets with first party datasets.