two page research paper on "Security Issues with IoT Based Smart Home Devices"
Security Issues with IoT Based Smart Home Devices
by
XXXXXX
An assignment submitted in partial fulfillment of the requirements for ITS-699 course as part of the degree of Masters
In
Information Technology
School of Computing and Information Sciences
University of the Cumberlands
ITS-699-01 – Information Technology Project
Professor: Dr. Zadok Hakim Due: August 2, 2020
Summer 2020
Abstract
Internet of Things (IoT) is a system that enables connectivity of the devices over the Internet. Smart home devices have been increasing lately due to the increased energy efficiency and the flexibility to control and operate multiple home appliances, all from one place. But, the use of technology has also raised various security and privacy threats. IoT security has become an issue of primary concern to safeguard user's personal information from being misused. This paper investigates multiple security issues with IoT based smart home devices, the threats of different protocols, the different types of architecture in IoT technology, the preferred architecture for smart-home devices, and how user awareness can minimize risks that IoT smart home devices face. Based on qualitative research, through secondary data that are different peer-review journals from previous years, thorough data analysis has been performed on the various security issues. Our investigations resulted in the conclusion that there is a need for more user awareness and identifying key security issues before implementing their solutions as often; these issues are not known. Choosing the right architecture is extremely important to reduce the security issues associated with smart-home devices.
Keywords : IoT, Smart Home Devices, Authentication, Confidentiality, Social Engineering, IoT Security, Privacy
Table of Contents 1. Introduction 1 2. Background, Problem, and Significance 1 2.1 Background 1 2.2 Problem 1 3. Purpose Statement 2 4. Research Question 2 5. Paradigm and conduct of the researcher 3 6. Research Design & Methodology 4 6.1 Case Study Design 4 6.2 Qualitative Methodology 5 7. Participants and Sampling 6 8. Instruments 6 9. Research Procedures 7 10. Data Analysis 8 10.1 IoT Technology 8 10.2 IoT Architecture 8 10.2.1 Three Layer Architecture 8 10.2.2 Four Layer Architecture 9 10.2.3 Five Layer Architecture 10 10.2.4 Six Layer Architecture 11 10.3 IoT Security Issues in smart home devices 12 10.3.1 Security Issue # 1: IoT being IP based 13 10.3.2 Security Issue # 2: IoT Application Domains 13 10.3.3 Security Issue # 3: Issues with verification and access control 13 10.3.4 Security Issue#4: Security Implementation 14 10.4 Different Security Architectures for Smart Home Devices 14 10.4.1 Middleware Architecture 14 10.4.2 Cloud Architecture 15 10.4.1 Gateway Architecture 15 10.5 Different Security Protocols in IoT 16 10.5.1 Protocol # 1: HTTP 16 10.5.2 Protocol # 2: MQTT 16 10.5.3 Protocol # 3: CoAP 16 11. User Awareness 17 12. Ethical Considerations 18 13. Plan for Presenting the Results 18 14. Summary & Conclusion 18 14.1 Summary 18 14.2 Conclusion 19 15. References 21 16. Certification Page 25 Short Bio 26
1. Introduction
Internet of Things (IoT) is a system that allows for the connectivity of devices over the Internet. A new era of IoT has emerged in which a network connects the electronic devices around us. IoT-enabled smart home devices allow a smart home to be more intelligent, automated, and interrelated. But, the idea of a smart home poses new difficulties in terms of our privacy (Varghese & Hayajneh, 2018). Lack of security and trust is a significant risk associated with IoT devices (Alhalafi & Veeraraghavan, 2019). Addressing these issues is essential as the misuse of the user's personal information could result in grave consequences.
2. Background, Problem, and Significance
2.1 Background
Internet of Things has enabled homes to get linked to technology and the Internet for making daily activities more convenient (Razzaq et al., 2017). There is a strong need to address the vulnerabilities in these devices and spread awareness regarding them since a lot of users are unaware of these security issues (Yoon et al., 2015). The different types of attacks need to be identified, and their threat levels should be determined. Only then can we find solutions that can be implemented (Razzaq et al., 2017).
2.2 Problem
Devices are linked with real-life and can cause severe damage to families (Yoon et al., 2015). There are direct impacts on the privacy and security of the user due to confidentiality, authentication, and access issues being a few (Razzaq et al., 2017).
2.3 Significance
Once the security of a user is compromised, the consequences of that could be severe. A weakness in the smart home architecture can compromise confidentiality, integrity, and availability of user data(Usha and Bobby, 2018, p.567). The security issues that come with a smart home can be prevented if we are aware of how the users and their privacy are put at risk.
3. Purpose Statement
The purpose of the project is to investigate various security issues with IoT based smart home devices. The paper will utilize a qualitative case study approach to research different security issues related to the IoT based smart home devices. This research aims to explore how the security issues are affecting the individual users, how different protocols and unencrypted communication instigate different privacy and security issues. Further, it explores the underlying architecture and the technologies behind the security issues. Furthermore, this research provides solutions to various security issues explored during the research
4. Research Question
What are the security issues of IoT based smart home devices?
Like computer networks, IoT devices are prone to security issues that need to be addressed. Apart from the benefits of IoT devices, users should not overlook the Security aspect of IoT based smart home devices (D. Bastos et al., 2018). According to (Zhi-Kai Zhang et al., 2014, p.232), Unauthorized access to data can expose the user and breach privacy.
Since IoT is intended to connect devices at large scale, IP based protocols are implemented. These IP based protocols increase the risk as they can communicate with any other device/attacker via open ports and security misconfigurations (Ashvini Kamble, & Sonali Bhutad. 2018 )
According to Usha and Bobby (2018, p. 567), unencrypted communication in IoT devices will lead to a breach of Data privacy. Security threats like Man-in-the-Middle attacks, Eavesdropping, and spoofing are possible with unencrypted communication. Data captured by malicious users can lead to data theft and unauthorized account takeover.
Users should be aware of what data is collected by IoT devices and their limitations. Securing the privacy of IoT devices should be a shared responsibility by both users and software providers.
5. Paradigm and conduct of the researcher
A research paradigm is a broadly diverse system of interconnected actions and thought processes that define the quest for knowledge within the three dimensions of the universe. Every way of doing research can be traced back to some fundamental philosophical assumptions rooted in what constitutes pertinent research and the research method that is fitting for the application of new ideas to practical problems in a given study (Denscombe, 2008). This writing seeks to discuss the entire research framework strategies underpinning this study.
Additionally, this section discusses the research methodology used in the case study, inclusive of the strategies, instruments, data collection techniques, and analytical approaches (Denscombe, 2008). The stages and processes involved in the research study incorporate a descriptive and interpretive case study that will be analyzed through qualitative methods. Nonetheless, the interpretive paradigm was selected and identified as the framework of the research study. Common assumptions will also be examined, reviewed, and exhibited. To add in, detailed open-ended questionnaires will be used to evaluate the satisfaction levels of the participants in the case study.
6. Research Design & Methodology
6.1 Case Study Design
A case study approach is used in generating an in-depth, multifaceted understanding of a complicated issue in its real-life context. This design is very established, and its use is applicable in a variety of scientific disciplines. This design is also referred to as a "naturalistic design" as it majorly explores phenomena in their natural context without any sort of manipulation of the variables or controlling the environment. The findings of a case study have implications on the development of a theory and its testing. According to Crowe et al. (2011), a case study approach is used in generating an in-depth, multifaceted understanding of a complex issue in its real-life context. Case Study may be characterized into three broad categories which are:
● Case studies may be intrinsic, instrumental, or collective. (Crowe et al., 2011)
● Intrinsic analyses the uniqueness of a phenomenon while the collective assesses multiple cases sequentially to attain a broader perspective about a phenomenon.
● The paper explores a case study of security issues with IoT based smart home devices.
The intrinsic nature in which the security issues with IoT is the subject of the case study, which forms the primary factor of the home-based smart home devices. Security issues in IoT are one of the constraints in realizing smart energy-efficient homes' vision. The main security requirements of smart home devices comprise integrity, confidentiality, availability, and authorization. The realization of these security requirements ensures the integration of smart home systems into a well-structured network (Usha and Bobby, 2018, p.566). Privacy is the key security issue experienced in smart homes.
Smart home devices are prone to privacy issues as hackers can easily attack them due to the availability of information when connected to the Internet. Ali, Dustgeer, Awais, and Shah (2017, p. 530) to secure these devices' data encryption of the firmware of the IoT is necessary. Protecting the user and encrypting communication links, therefore, is critical for the secure operation of IoT in smart home devices.
6.2 Qualitative Methodology
According to M. Gordon Hunter from the University of Lethbridge (2004), "qualitative research is an interpretive approach to investigating subjects in their natural surroundings." This method helps to clarify the perspective of people. Qualitative research involves the use of qualitative data, such as interviews, documents, case studies, and participant observation data, to understand and explain social phenomena (Hunter, 2004).
A book review is done by Cairney & St Denny (2015), which points to the most common qualitative research characteristics of acknowledgment of personal feelings, tastes, or opinions. The evaluation and the research of occurrences in their natural and real-world environments is another character they pointed out. They also mentioned the tendency in qualitative research to analyze a limited number of cases, which makes it easier to apply to any field of study (Cairney & St Denny, 2015). Among the most appropriate applications for qualitative research is the assessment, analysis, and way to solve failures in the information system. The qualitative method also helps in identifying the relationship between technological innovation and the need for the target consumers, the cultural, social, personal beliefs, and behavioral impact (Zahran & Galal-Edeen, 2006).
7. Participants and Sampling
For the purposes of this research paper, we have chosen to go with nonprobability sampling techniques and mainly with the Purposive Sampling Techniques. According to Bernhard, H. R. (As cited in Etikan, Musa & Alkassim, 2016), "The purposive sampling technique, also called judgment sampling, is the deliberate choice of a participant due to the qualities the participant possesses. It is a nonrandom technique that does not need underlying theories or a set number of participants. Simply put, the researcher decides what needs to be known and sets out to find people who can and are willing to provide the information by virtue of knowledge or experience". According to Wu Suen, Huang & Lee (2014, p. 111), "purposive sampling is typically used in qualitative studies. Researchers who use this technique carefully select subjects based on study purpose with the expectation that each participant will provide unique and rich information of value to the study. As a result, members of the accessible population are not interchangeable, and the sample size is determined by data saturation, not by statistical power analysis." Peer-reviewed journals are the participants for this research paper.
8. Instruments
Instruments in the context of a research paper are the tools that are used to collect the data. These research instruments can include questionnaires, interviews, scales, examples, reviewing existing literature, among others. Since, for this research paper purposes, as we are not allowed to collect any data and only use the existing peer-reviewed journals for any research purpose, we have chosen to use existing peer-reviewed journals as the instrument to conduct our research. These peer-reviewed journal papers would be used to understand the existing IoT's architecture with reference to the home devices, its limitations, recent improvements, and the current state. It will then be used to help us conduct our analysis of the Security Issues with IoT based Smart Home Devices and provide a summary and conclusion.
9. Research Procedures
In order to identify and address the vulnerabilities in the devices, we used qualitative research from case studies to understand the cyber flaws of having a smart home. When using a case study to conduct research, we are able to explore the structure of the study, the events that led up to the results and conclusion of the study, and the actions to be taken after the study(Razzaq et al., 2017). Hence, this makes it one of the most effective research design approaches and the reason why we chose it.
There are many methods that fall under qualitative research, such as interviews, focus groups, participant observation, and existing data. In order to better comprehend the cyber flaws of a smart home, we utilized existing data. For this research paper, we selected multiple peer-reviewed journals that discussed our main research question. A specific qualitative method that was used was a thematic analysis in which the existing data was examined, and general themes and patterns were acknowledged for our research (Denscombe, 2008). Some of the general themes and patterns that were identified were the types of security issues that came with smart homes and how the architecture of the smart home could affect the security of the users of it.
By using existing data in our research, we were able to be efficient with the time spent on conducting this research. This was mainly due to the fact that we did not need to collect data to conduct an experiment to answer the research question. Instead, we were able to comprehend our research question on a deeper level in the same amount of time.
10. Data Analysis
10.1 IoT Technology
IoT Technology has been on the rise in recent years. This technology uses microprocessor-based controllers in devices and connects it to the Internet, and this has increasingly become widespread in the world. A combination of IoT technology, along with RFID (radio frequency identification), is used to make the location of these devices available on the Internet. Lin and Bergmann (2016), states that even though IoT technology is being adopted rapidly, there are still many reasons why its dispersion is disruptive.
10.2 IoT Architecture
There are different layered architectures. Each one of them is explained in detail below.
10.2.1 Three Layer Architecture
Three-layer architecture is the very basic architecture, and this architecture provides the basic idea of the IoT. This three-layer architecture was proposed in the earlier stages of IoT development. Since then, there have been many new proposals, varying in the number of layers the IoT architecture should consist of. The three different layers of this architecture are listed below, along with the diagram (Burhan, Rehman, Khan & Kim, 2018).
· Application Layer
· Network Layer
· Perception Layer
Picture source: Burhan, Rehman, Khan & Kim, 2018
10.2.2 Four Layer Architecture
In the four-layered architecture, it has all the layers similar to the three-layered architecture, but it has an additional layer called the Support layer. This layer was proposed by researchers as the existing three-layered architecture was not able to meet the new technologies and address the security threats posed. The support layer provides the architecture to first send the information to this layer and then pass it to the next layer. This confirms the validity of the information as well as the sender. The four different layers of this architecture are listed below, along with the diagram (Burhan, Rehman, Khan & Kim, 2018).
· Application Layer
· Support Layer
· Network Layer
· Perception Layer
Picture source: Burhan, Rehman, Khan & Kim, 2018
10.2.3 Five Layer Architecture
Since the four-layered architecture was also not able to address all the concerns, it played a very important role and laid the foundation in formulating the Five Layered Architecture. This architecture was proposed by the researchers to make it even more secure than the previous architecture. Both the application layer and network layer were replaced by three new layers, namely Business layer, Processing layer, and Transport layer. Researchers thought that this would bring stability to the architecture. The five different layers of this architecture are listed below, along with the diagram (Burhan, Rehman, Khan & Kim, 2018).
· Business Layer
· Application Layer
· Processing Layer
· Transport Layer
· Perception Layer
Picture source: Burhan, Rehman, Khan & Kim, 2018
10.2.4 Six Layer Architecture
One of the basic fundamentals that researchers understood was that the architecture of the IoT is different from the architecture of the Internet. For this reason, researchers understood that the aforementioned different architectures would not be suitable for IoT, and they proposed a new generic architecture that would fulfill the requirements of privacy and security that were subjected to various security risks. In this new architecture, there were six different layers, and they called it Six Layered Architecture. With this six-layered architecture, they provided the mechanisms to enhance and improve various functions to any layer with very minimal impact on the other layers. The six different layers of this architecture are listed below, along with the diagram (Burhan, Rehman, Khan & Kim, 2018).
· Application Layer
· Network Layer
· Security Layer
· Processing Layer
· Observer Layer
· Perception Layer
Picture source: Burhan, Rehman, Khan & Kim, 2018
10.3 IoT Security Issues in smart home devices
The ability of IoT to deliver linkages of "things" across the world through miniature systems and sensor networks allows global connectivity. This poses questions regarding protection, privacy, and confidence issues when the information is exchanged (Ahanger & Aljumah, 2019).
10.3.1 Security Issue # 1: IoT being IP based
Similar to every other IP-based System, actively behaving adversaries may try to scrutinize usable communications in order to collect information that can either be used to track consumer activity, or gathered and manipulated in the later stage of an aggressive attack. Adversaries may aim to catch the traffic at different points in the smart home network based on their strengths and priorities to obtain this kind of knowledge. Adversaries may, therefore, have an effect on the security and privacy of consumers, as they will gather details about the state of the smart home (Geneiatakis et al., 2017).
10.3.2 Security Issue # 2: IoT Application Domains
There are several relatively common standardized Smart Home protocols, such as X.10 powerline carrier communications, without some form of encryption, and built prior to linking such home control networks to the Internet. A plethora of networking protocols are now found in a household (Zwave, Insteon, Bluetooth, Zigbee, Ethernet, Wifi, RS232, RS485, C-bus, UPB, KNX, EnOcean, Thread). Each has its advantages and disadvantages, and it poses major difficulties to expect a heterogeneous network of several separate protocols to be handled effectively and safely by non-experts (Lin & Bergmann, 2016)
10.3.3 Security Issue # 3: Issues with verification and access control
IoT offers a whole new means of connecting with people, devices, and even among devices themselves. The Internet of Things has reworked the Internet's destiny to make human life easy to communicate with all those wireless devices around us to control and to organize their tasks without our intervention. Now, these clever devices are attacked by some evil hackers, who ultimately jeopardize the protection of these IoT devices and have the potential to spread these threats far more widely than the Internet has to date (Kamble & Bhutad, 2018).
10.3.4 Security Issue#4: Security Implementation
There has been ever-increasing use of smart home devices such as lights, smoke-alarms, baby monitors, etc. With more and more smart home devices being manufactured and put into use, the means by which the attacker can gain access to the device or the network increases, which in turn makes the security implementation challenging due to the factors such as mode of operation, device capabilities, manufacturer, etc. (Sivaraman et al., 2015). Hence there is a need to have a common security solution that can augment the security features offered by device manufacturers. This can be achieved through a network-level security solution with the use of SDN (Software-defined networking) to implement dynamic security rules (Sivaraman et al., 2015).
10.4 Different Security Architectures for Smart Home Devices
There are different layered architectures that can be potentially be used with smart home devices. Each one of them is explained in detail below.
10.4.1 Middleware Architecture
According to Lin and Bergmann (2016), the middleware layer has a common interface, and the structure of data exchange is to extract the complicated details of the hardware. Lin and Bergmann (2016) mentioned that VIRTUS middleware is a solution based on XMPP (eXtensible Messaging and Presence Protocol). Lin and Bergamann (2016) stated that due to the complex software layers and cryptographic routines involved, it is hard to implement this architecture since IoT devices do not have the computational power or memory to support it. Also, if there are any coding errors by developers, it will directly translate to security issues in the IoT devices. Therefore, Lin and Bergmann (2016) rejected middleware architecture as a feasible solution for IoT devices.
10.4.2 Cloud Architecture
A cloud architecture based on the three stages has been proposed, which uses IETF's CoAP protocol in Lin and Bergmann's (2016) paper. The positive aspects of cloud-based security architecture are it can allow for ease to connect and cooperate amongst the IoT devices. But due to the nature of cloud architecture, which needs continuous, uninterrupted connectivity, Lin and Bergmann (2016) concluded that this is not a viable option for providing security to smart home devices.
10.4.1 Gateway Architecture
IoT gateway architecture works on the same LAN with other IoT devices and can allow for connectedness also a way to manage these devices from a central point. Lin and Bergmann (2016) stated that it also acts as a firewall to guard these smart home devices. Lin and Bergmann (2016) have suggested Server-Based Internet-Of-Things (SBIOTA) as a server that can provide an excellent solution for IoT. This concept uses an auto-configuration method, so it does not have to be interrupted with manual configuration. Lin and Bergmann (2016) have concluded this method to be their recommendation for preferred architecture and the reasoning for it being that even in the temporary absence of the Internet, it can still provide security through firewall and proxy and does not need complex middleware for the IoT devices.
10.5 Different Security Protocols in IoT
10.5.1 Protocol # 1: HTTP
Connectivity and Data protocols play a key role in IoT architecture. Data protocols provide rules/guidelines on how communications should be handled between IoT devices. According to (D. Bastos et al., 2018), some of the popular Data transfer protocols in IoT devices are HTTP/REST. HTTP is a widely used Data transfer protocol in IoT devices to send and receive data. RESTful web services are stateless and utilize HTTP methods like GET, POST, PUT, DELETE. To secure HTTP communication, TLS should be implemented for data encryption (D.Bastos et al., 2018). Implementation of TLS will ensure a secure channel for communication and help prevent Man-in-the-Middle attacks.
10.5.2 Protocol # 2: MQTT
Apart from the Data transfer protocol, MQTT and CoAP are some of the popular messaging protocols in IoT environment Giuseppe Nebbione, & Maria Carla Calzarossa (2020, p.5). Message Queue Telemetry Transport(MQTT) supports encryption mechanisms like TLS, and this is not enough to protect MQTT enabled devices. According to Giuseppe Nebbione & Maria Carla Calzarossa (2017, p.5), Security risks in MQTT arise due to poorly configured broker components(server), and these risks are classified as Authentication, Authorization, Message validation, Message delivery, Message Encryption. MQTT broker doesn't properly check the identity of the subscriber and doesn't limit/restrict repeated authentication attempts resulting in a brute force attack. Repeated attempts will overload the server and can lead to Denial of Service attack. Lack of proper input parameter validations will help attackers to craft malicious payloads. MQTT brokers are not robust to handle data containing disallowed characters Giuseppe Nebbione, & Maria Carla Calzarossa (2017, p.5). Man-in-The-Middle attacks can be performed when messages are sent in plain text, and attackers can spoof the messages in transit.
10.5.3 Protocol # 3: CoAP
Constrained Application Protocol (CoAP) is an emerging message transfer protocol like HTTP as it uses request/response for communication (D. Bastos et al., 2018). Giuseppe Nebbione, & Maria Carla Calzarossa (2017, p.8) classified the security threats of CoAP enabled devices as Message parsing, proxying and caching, IP spoofing, key generation. Vulnerabilities like Remote code execution are possible when messages are not properly parsed by the client-server parser. Improper implementation of access control checks will lead to unauthorized disclosure of data, which will break the confidentiality and integrity of messages.
11. User Awareness
As per Shouran, Ashari & Priyambodo (2019), many studies have concentrated on password security. One of the issues faced by the users is they are not able to change the default passwords that come up with the applications, and that helps the hackers to get control of the devices. These kinds of devices or any devices whose username and password have not also been changed also becomes the target for hackers. In order to overcome this, users need to have different passwords for different applications. User awareness and education are thus required when it comes to maintaining the security of IoT based smart home devices.
12. Ethical Considerations
While performing qualitative research, it is essential to consider ethical concerns into account. Some of the key ethical concerns are anonymity, confidentiality, and informed consent (Sanjari et al., 2014).
Anonymity, confidentiality, and informed consent are usually more prevalent in the research that involves human subjects. The study conducted as a part of this research did not include any human subjects. Instead, it entirely relied on secondary data disclosed by the other researchers in peer-reviewed journals. The data researched doesn't include personally identifiable information and protected health information. This paper ensured to cite the references of the original researchers as and when the idea or quote is retrieved from the said journals and also ensured not to affect the original idea presented in peer-reviewed journals.
13. Plan for Presenting the Results
This paper is a qualitative study on various security issues with IoT based smart home devices. The paper explores case studies from various peer-reviewed journals. The research will follow the descriptive method to present the results.
14. Summary & Conclusion
14.1 Summary
This paper identified the various security issues with IoT smart home devices such as IoT being IP based, could expose the state of smart home, the complexity involved in handling different protocols in the heterogeneous network, and issues with verification and access control(Lin & Bergmann, 2016). We then compared the security features of multi-layered IoT architectures and highlighted the benefits of 6 layered architecture over other available architectures. The use of different protocols such as HTTP, MQTT & CoAP with IoT is explored. Apart from manufacturers trying to improve the security features of smart home devices, there is a need to enhance the security at the network level, which can be accomplished by implementing dynamic security rules using software-defined networking(SDN)(Sivaraman et al., 2015). User awareness and education plays a crucial role in the effective implementation and to realize the benefits of all security features either at the network level or on smart home devices. This includes educating users not to use the default passwords, not use the same password for multiple applications, and change the set password regularly.
14.2 Conclusion
Over the past decade, with the significance of IoT, "it has led to new threats and attacks that pose security issues to IoT devices, and there have been several improvements in the security features of the devices that use IoT (BV & G, 2017). Ultimately the main objective of these devices is to improve the quality of life and make the world a better place for human beings by making the devices around us understand and act according to our needs (Dohr, Modre-opsrian, Drobies & Schreier (as cited by BV & G, 2017)). There are several issues such as, as pointed out by Burhan, Rehman, Khan & Kim (2018, p. 6) that "Eavesdropping is an unauthorized real-time attack where private communications, such as phone calls, text messages, fax transmissions or video conferences are intercepted by an attacker. It tries to steal information that is transmitted over a network". Six layered architecture provides most of the tools to address the security issues (Burhan, Rehman, Khan & Kim, 2018). Using the HTTP makes IoT more secured than other protocols (Bastos, 2018). Burhan, Rehman, Khan, and Kim (2018) have not listed various security threats, but they also contended that future research is needed to overcome the existing security issues by stating there are several new challenges that currently exist, and with every new technological development, it brings its new challenges. Similarly, Gaikwad, Gabhane & Golait (2015) also expressed that there is very low security on the server-side of the Smart home systems, and designing a new secured system should be part of the future work.
15. References
Alhalafi, N., & Veeraraghavan, P. (2019). Privacy and Security Challenges and Solutions in IoT: A review. IOP Conference Series: Earth and Environmental Science, 322, 012013. doi:10.1088/1755-1315/322/1/012013
Ali, W., Dustgeer, G., Awais, M., & Shah, M. A. (2017). IoT based smart home: Security challenges, security requirements, and solutions. 2017 23rd International Conference on Automation and Computing (ICAC). doi:10.23919/iconac.2017.8082057
Bastos, D., Shackleton, M., & El-Moussa, F. (2018). Internet of Things: A Survey of Technologies and Security Risks in Smart Home and City Environments. Living In The Internet Of Things: Cybersecurity Of The IoT - 2018. doi: 10.1049/cp.2018.0030
Burhan, M., Rehman, R., Khan, B., & Kim, B. (2018, August 24). IoT Elements, Layered Architectures, and Security Issues: A Comprehensive Survey. Retrieved from https://www.mdpi.com/1424-8220/18/9/2796
Cairney, P., & St Denny, E. (2015). What is Qualitative Research (Bloomsbury). International Journal of Social Research Methodology, 18(1), 117–125. Business Source Premier.
Crowe, S., Cresswell, K., Robertson, A., Huby, G., Avery, A., & Sheikh, A. (2011). The case study approach. BMC Medical Research Methodology, 11(1). doi.org/10.1186/1471-2288-11-100
Denscombe, M. (2008). Communities of Practice: A Research Paradigm for the Mixed Methods Approach. Journal of Mixed Methods Research, 2(3), 270–283. doi:10.1177/1558689808316807
Etikan, I. (2016). Comparison of Convenience Sampling and Purposive Sampling. American Journal of Theoretical and Applied Statistics, 5(1), 1. doi:10.11648/j.ajtas.20160501.11
Geneiatakis, D., Kounelis, I., Neisse, R., Nai-Fovino, I., Steri, G., & Baldini, G. (2017). Security and privacy issues for an IoT based smart home. 2017 40th International Convention on Information and Communication Technology, Electronics, and Microelectronics (MIPRO), 1292–1297. doi:10.23919/MIPRO.2017.7973622
Heale, R., & Twycross, A. (2017). What is a case study? Evidence Based Nursing, 21(1), 7–8. doi:10.1136/eb-2017-102845
Hunter, M. G. (2004). Qualitative research in information systems: An exploration of methods. The Handbook of Information Systems Research, 291–304. doi:10.4018/978-1-59140-144-5.ch016
Jeong, S. H., Lee, S. J., Cho, S. M., & Cho, H. (2020). Systematic Review on the Influencing Factors of Nursesʼ and Nursing Studentsʼ Attitudes Toward Hospice and Palliative Care. Journal of Hospice & Palliative Nursing, 22(2), 130-136. doi:10.1097/njh.0000000000000627
Kamble, A., & Bhutad, S. (2018). Survey on Internet of Things (IoT) security issues & solutions. 2018 2nd International Conference on Inventive Systems and Control (ICISC), Inventive Systems and Control (ICISC), 2018 2nd International Conference On, 307–312. doi:10.1109/ICISC.2018.8399084
Krishna, B V Santhosh, and T Gnanasekaran. "A Systematic Study of Security Issues in Internet-of-Things (IoT)." 2017 International Conference on I-SMAC (IoT in Social, Mobile, Analytics, and Cloud) (I-SMAC), 2017, doi:10.1109/i-smac.2017.8058318.
Lin, H., & Bergmann, N. (2016). IoT Privacy and Security Challenges for Smart Home Environments. Information, 7(3), 44. doi:10.3390/info7030044
Nebbione, G., & Calzarossa, M. C. "2020). Security of IoT Application Layer Protocols: Challenges and Findings. Future Internet, 12(3), 55. doi:10.3390/fi12030055
Razzaq, M. A., Gill, S. H., Qureshi, M. A., & Ullah, S. (2017). Security issues in the Internet of Things (IoT): a comprehensive study. International Journal of Advanced Computer Science and Applications, 8(6), 383
Sanjari, M., Bahramnezhad, F., Fomani, F. K., Shoghi, M., & Cheraghi, M. A. (2014). Ethical challenges of researchers in qualitative studies: the necessity to develop a specific guideline. Journal of medical ethics and history of medicine
Shouran, Ashari & Priyambodo. Internet of Things (IoT) of Smart Home: Privacy and Security. International Journal of Computer Applications, volume 182, no 39, February 2019. doi: 10.5120/ijca2019918450
T. A. Ahanger and A. Aljumah, "Internet of Things: A Comprehensive Study of Security Issues and Defense Mechanisms," in IEEE Access, vol. 7, pp. 11020-11028, 2019, doi:10.1109/ACCESS.2018.2876939.
Usha, D., & Bobby, M (2018). Privacy Issues in Smart Home Professor'sng Internet of Things- A survey. International Journal of Advances ResearStudent's, 566-568. Doi: 21474/ijar01/7839
Varghese, J. & Hayajneh, T. (2018). A Framework to Identify Security and Privacy Issues of Smart Home Devices. 2018 9th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON), 135-143, doi: 10.1109/UEMCON.2018.8796765.
Yoon S., Park H., Yoo H.S. (2015) Security Issues on Smart-home in IoT Environment. In: Park J., Stojmenovic I., Jeong H., Yi G. (eds) Computer Science and its Applications. Lecture Notes in Electrical Engineering, vol 330. Springer, Berlin, Heidelberg
Zahran, S. M., & Galal-Edeen, G. H. (2006). Qualitative Research in Information Systems Engineering: Outline and Applications. Egyptian Society for Information Systems and Computer Technology (ESISACT) Conference, Cairo, 7, 1–12.
Zhang, Z., Cho, M. C., Wang, C., Hsu, C., Chen, C., & Shieh, S. (2014). IoT Security: Ongoing Challenges and Research Opportunities. 2014 IEEE 7th International Conference on Service-Oriented Computing and Applications. doi:10.1109/soca.2014.58
8