07. References & Further Reading
To continue your journey into IoT and Hardware Security, consult the following industry standards, frameworks, and tooling documentation.
📚 Industry Standards & Guidelines
-
OWASP Internet of Things Project
- The OWASP IoT Top 10 provides a baseline of the most critical vulnerabilities in the IoT ecosystem, from weak passwords to insecure network services.
- OWASP IoT Top 10
-
ETSI EN 303 645 (Cyber Security for Consumer Internet of Things)
- The globally recognized standard for consumer IoT security. It outlines baseline requirements such as "No universal default passwords" and "Implement a means to manage reports of vulnerabilities."
- ETSI EN 303 645 Specification (PDF)
-
NIST IoT Cybersecurity Program
- Provides comprehensive guidance for manufacturers on securing IoT devices and integrating them into federal networks (NISTIR 8259 series).
- NIST IoT Cybersecurity
🛠️ Security Tooling & Firmware Analysis
-
Binwalk
- The definitive tool for searching binary images for embedded files and executable code. Essential for firmware reverse engineering.
- Binwalk GitHub Repository
-
Firmadyne
- An automated and scalable system for performing emulation and dynamic analysis of Linux-based embedded firmware.
- Firmadyne GitHub Repository
-
OpenOCD (Open On-Chip Debugger)
- Used for hardware-level debugging, in-system programming, and boundary-scan testing via JTAG.
- OpenOCD Official Site
📖 Deep Dives & Literature
- Practical IoT Hacking (Book by Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou)
- A highly recommended practical guide covering threat modeling, firmware analysis, and radio hacking (BLE, Zigbee, SDR).
- Hardware Hacker (Book by Andrew "bunnie" Huang)
- Excellent context on hardware manufacturing, supply chains, and low-level reverse engineering.