А.І. Abakumov, V.S. Kharchenko

Èlektron. model. 2022, 44(4):79-104


The spread of the Internet of Things (IoT) and IoT based systems is accompanied by an increa­sing the rate and types of cyberattacks on the system assets. The potential threats and negative consequences of attacks on various types of IoT devices btcome critical. This circumstance determines the urgency of improving the methods of IoT cyber security assessment, in particular, by use penetration testing (PT) based on the simulation of real attacks. The purpose of the study is to analyze the threats and vulnerabilities of IoT systems, methods and stages of PT implementation. The analysis of the features of IoT systems as objects of PT was carried out. Rating threats and vulnerabilities of IoT systems are determined based on the analysis of references classified on five main areas. The consequences of attacks were assessed using the IMECA method and modified risk table and matrix. The main countermeasures and their effectiveness in reducing the consequences of attacks are analyzed. The stages of IoT systems PT are specified and analyzed. Directions of future research, development and improving IoT systems PT effectiveness are formulated.


Internet of Things, penetration testing, threats, cyberattacks, IMECA analysis.


