Skip to main navigation Skip to search Skip to main content

IoTSE-based open database vulnerability inspection in three Baltic countries: ShoBEVODSDT sees you

  • Artjoms Daskevics
  • , Anastasija Ņikiforova
  • University of Latvia

Research output: Chapter in Book/Report/Conference proceedingConference paperResearchpeer-review

13 Citations (Scopus)

Abstract

This study aims to analyze the state of the security of open data databases, i.e. being accessible from the outside of organization, representing both relational databases and NoSQL of three Baltic countries - Latvia, Lithuania, Estonia. This is done by using previously proposed tool for non-intrusive detection of vulnerable data sources called ShoBEVODSDT (Shodan- and Binary Edge-based vulnerable open data sources detection tool). ShoBEVODSDT is based on the use of Internet of Things Search Engines (IoTSE). It is found to be suitable for this study since it conducts the passive assessment, which means that its use does not harm the databases but rather checks for potentially existing bottlenecks or weaknesses which, if the attack would take place, could be exposed. It allows for both comprehensive analysis for all unprotected data sources falling into the list of predefined data sources - MySQL, PostgreSQL, MongoDB, Redis, Elasticsearch, CouchDB, Cassandra and Memcached, or to define IP range to examine what can be seen from the outside of the organization about the data source. Although some data sources can be described as following the security-by-design principle, some of them face serious challenges in this respect. The study carries out cross-country comparative study on 8 data sources. We inspect both, (1) the most vulnerable data sources and (2) countries characterized by the highest number of open data sources and the highest degree of 'value' of data being available to external actors.

Original languageEnglish
Title of host publication2021 8th International Conference on Internet of Things
Subtitle of host publicationSystems, Management and Security, IOTSMS 2021
Place of Publication[New York]
PublisherIEEE
Pages1-8
ISBN (Electronic)9781665458689
ISBN (Print)978-166545868-9, 9781665458689
DOIs
Publication statusPublished - 2021

Publication series

Name2021 8th International Conference on Internet of Things: Systems, Management and Security, IOTSMS 2021

Keywords

  • BinaryEdge
  • Database
  • Internet of Things (IoT)
  • Internet of Things Search Engine (IoTSE)
  • NoSQL
  • Shodan
  • Vulnerability

OECD Field of Science

  • 1.2 Computer and Information Sciences

Fingerprint

Dive into the research topics of 'IoTSE-based open database vulnerability inspection in three Baltic countries: ShoBEVODSDT sees you'. Together they form a unique fingerprint.

Cite this