Full text
Contents lists available at ScienceDirect Journal of Information Security and Applications journal homepage: www.elsevier.com/locate/jisa CRASHED: Cyber risk assessment for smart home electronic devices Georgios Paparisa,∗, Apostolis Zarras a,b, Aristeidis Farao a,c, Christos Xenakis a,c aDepartment of Digital Systems, University of Piraeus, Piraeus, Greece bFoundation for Research and Technology – Hellas, Heraklion, Greece cInQbit Innovations SRL, Bucharest, Romania A R T I C L E I N F O Keywords: Cyber risk assessment Risk calculation Smart home MITRE ATT&CK CAPEC A B S T R A C T The rapid proliferation of Internet of Things (IoT) technology has enriched modern households with smart home devices, enhancing convenience, but simultaneously increasing vulnerability to cyber threats. This paper introduces CRASHED, an innovative cyber risk assessment methodology specifically designed for smart home ecosystems. Compared to existing approaches, CRASHED integrates the MITRE ATT&CK and CAPEC frameworks to systematically identify and analyze threats, vulnerabilities, and potential impacts. By employing device-specific profiling, quantitative metrics, and sophisticated weighting mechanisms, it delivers a multilayered assessment of cyber risks that accounts for asset criticality and threat severity, distinguishing it from conventional methods lacking such granularity. The novelty of CRASHED lies in its comprehensive evaluation of systemic vulnerabilities and domestic repercussions. Case studies on various smart home configurations demonstrate its effectiveness in modeling, analyzing, and mitigating risks compared to existing frameworks. This work represents a significant advancement in safeguarding smart home environments, underscoring the urgent need for specialized cyber risk assessment models in our interconnected era. The proposed methodology not only enhances threat detection and response, but also addresses critical gaps in vulnerability databases and risk calculation processes, offering a transformative solution to the evolving challenges of smart home cybersecurity. 1. Introduction The rapid advancement of smart home technologies has fundamentally transformed the way individuals interact with their living spaces, ushering in a new era of convenience, efficiency, and seamless connectivity. These innovations, driven by the Internet of Things (IoT), encompass many devices: smart thermostats that optimize energy consumption, security cameras that provide real-time monitoring, smart locks that enhance home security, and voice-activated assistants that streamline daily tasks. The global smart home market is projected to reach $537.01 billion by 2030, underscoring the growing adoption of these devices [1]. What were once optional upgrades have become indispensable components of modern homes, revolutionizing daily living [2,3]. However, the widespread integration of smart devices also introduces an expanding range of cyber risks. These devices become increasingly interconnected and deeply embedded in critical household functions, creating potential entry points for cybercriminals. The vulnerabilities within these systems can be exploited, leading to severe consequences such as breaches of privacy, compromised safety, and financial losses [4]. ∗Corresponding author. E-mail address: [email protected] (G. Paparis). However, integrating digital technology into households has faced numerous challenges. The likelihood of cyberattacks targeting residential properties has increased with the growing prevalence of electronic gadgets in homes [5]. These attacks range from unauthorized access to personal and financial information to manipulating electronic devices in residential settings. Such activities pose significant threats to individuals’ privacy and safety; these are realistic, not hypothetical, scenarios. For instance, hackers have exploited smart home networks, enabling them to control lighting systems, locks, and security cameras [6]. Another notable instance involved cyberattacks on smart homes that allowed hackers to take control of a baby monitor, using it to spy on the family and even communicate with the child through the device [7,8]. Additionally, a DDoS attack disabled the smart heating system of two housing apartments in Finland, leaving residents in the cold [9]. Furthermore, cybersecurity experts have discovered methods to gain root access to Xiaomi vacuum robots by exploiting their lidar sensors [10,11]—and so on. Several factors significantly contribute to the vulnerabilities of smart homes to cyberattacks, creating a complex landscape of potential risks. One primary issue is that many IoT devices lack robust security https://doi.org/10.1016/j.jisa.2025.104054 Journal of Information Security and Applications 91 (2025) 104054 Available online 18 April 2025 2214-2126/© 2025 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ ).
G. Paparis et al. measures. It is worth mentioning here that in this work, we use the terms IoT devices and smart home devices interchangeably, as both refer to the same concept for this paper. Previous research [12] has shown that cybercriminals can easily target many of these devices due to their marginal security features. Manufacturers often prioritize cost and convenience over robust security protocols, resulting in devices that hackers can easily compromise. Common flaws, such as weak encryption standards, hardcoded passwords, and a lack of regular security updates, expose smart home devices to unauthorized access and manipulation. Beyond these technical shortcomings, user behavior plays a crucial role in smart home security [13,14]. Many users lack sufficient knowledge about the potential dangers associated with smart home technology and often underestimate the importance of cybersecurity. This lack of awareness leads to poor security practices, such as using weak or default passwords, failing to update device firmware regularly, and neglecting to configure security settings appropriately. These oversights make it easier for attackers to breach smart home networks and gain control over connected devices. Given the increasing frequency of cyberattacks targeting smart homes [15] and the potentially severe consequences of these attacks, there is an urgent need for thorough evaluations of the threats posed by cyber vulnerabilities. As smart home adoption continues to grow, the complexity and interconnectivity of devices within these environments present entry points for hackers. Thus, identifying vulnerabilities within smart home networks is a critical first step in fortifying them against potential threats. A comprehensive analysis of the devices, communication protocols, and overall design of the smart home ecosystem is required to identify any security vulnerabilities that could be exploited by malicious actors [16]. Evaluating the potential repercussions of cyber risks is also crucial. A successful cyberattack on a smart home could result in a wide range of adverse outcomes, including unauthorized access to personal data, financial loss, and concerns about physical safety, such as tampering with security systems or remotely manipulating household appliances [17]. Safeguarding smart homes from cyber intrusions is essential due to their growing integration into contemporary life. Cyber risk assessments provide a comprehensive approach to protecting digital homes and their occupants from the potentially catastrophic consequences of cybercrime. Consequently, conducting thorough evaluations of cyber threats is imperative, emphasizing the need for ongoing research and advancement in smart home cybersecurity. Although traditional cyber risk assessment methodologies are effective for conventional IT infrastructure, they often fall short when applied to smart homes. The complexity of IoT devices, their decentralized nature, and the diverse range of protocols and standards they employ present unique challenges that require innovative risk assessment approaches [18]. Furthermore, the security risks associated with smart homes are significant; cyberattacks can lead to privacy breaches, financial losses, and even physical harm. Finally, existing methodologies lack the integration of vulnerability databases in the risk calculation process. Moreover, they fail to incorporate mechanisms for applying weighted adjustments to assess the impact of threats on assets. These significant gaps highlight the urgent need for innovative solutions that specifically address security and privacy concerns in smart homes by leveraging vulnerability databases and incorporating adjustment mechanisms to measure the impact of cyber threats precisely. This article addresses the aforementioned gaps by presenting CRASHED, an innovative cyber risk assessment methodology that transcends traditional approaches, aiming to model and analyze cyber risks in smart homes.1 CRASHED is designed for researchers and analysts interested in smart home systems, aiming to enhance their understanding and reasoning about the cyber threats impacting these systems. 1The source code of CRASHED can be found at https://github.com/ UniPiSSL/CRASHED. Our methodology employs the MITRE ATT&CK [19] and CAPEC [20] frameworks to effectively identify threats and vulnerabilities in smart devices within a smart home. By leveraging device profiling, CRASHED rigorously assesses the collective impact of identified threats from both a systemic and domestic perspective, adopting a holistic approach to the smart home environment. The calculation of threat impact is based on multiple factors and the use of quantitative metrics. The novelty of the proposed methodology lies in its ability to calculate the impact of a threat on an asset, factoring in the asset’s criticality and the threat’s weight. These two definitions provide both flexibility and precision in risk calculation, aligning with the unique characteristics of smart homes. To the best of our knowledge, CRASHED is the only methodology that integrates both MITRE ATT&CK and CAPEC. In summary, we make the following main contributions: •We introduce a novel cyber risk assessment methodology, CRASHED, which leverages the MITRE ATT&CK and CAPEC frameworks to address security and privacy issues simultaneously. The methodology grounds risk calculations in vulnerability databases and employs a weighting formula. •We assess the efficacy of our proposed methodology in a smart home environment equipped with twelve smart devices. Additionally, we evaluate two distinct smart home scenarios, each comprising a unique subset of six devices. •We compare CRASHED with existing approaches and frameworks for assessing cybersecurity risks in smart homes. The remainder of the article is structured as follows: Section 2 provides an overview of the background, focusing on embedded devices for smart homes and the associated cybersecurity challenges. In Section 3, we present the stakeholder roles in smart home cybersecurity. Section 4 introduces CRASHED, our proposed cyber risk assessment methodology for smart homes. Section 5 is dedicated to the evaluation of CRASHED, while Section 6 addresses its limitations and suggests directions for future research. In Section 7, we compare CRASHED with related approaches. Finally, Section 8 concludes this article. 2. Background This section provides an analytical overview of the MITRE ATT&CK and CAPEC frameworks, foundational elements of our proposed cyber risk methodology. We then present a catalog of commonly used smart home devices, followed by an examination of the cybersecurity challenges associated with smart home environments. 2.1. MITRE ATT&CK The MITRE ATT&CK framework is a publicly accessible repository of information that outlines the tactics and strategies employed by cyber adversaries. Its purpose is to provide a shared vocabulary among defenders, enabling them to understand and effectively counter evolving threats. The framework details common tactics, techniques, and procedures used by attackers, facilitating the formulation of effective defensive strategies and threat models. This resource is readily accessible to various stakeholders, including the corporate sector, government entities, and the cybersecurity community, thus promoting distinct threat models and approaches. The structured format of MITRE ATT&CK enhances the significance of threat reporting by organizing behaviors beyond conventional indicators. This framework is foundational for creating targeted threat models and methodologies in various sectors, which include industry, government, and the cybersecurity product and service community. As an extensive repository, the MITRE ATT&CK framework represents the tactics and procedures employed by cyber attackers and serves as a unifying framework for defenders to comprehend and address evolving threats, establishing a shared vocabulary. In contrast to other Journal of Information Security and Applications 91 (2025) 104054 2
G. Paparis et al. analogous frameworks, such as the Tactics, Techniques, and Procedures (TTPs) [21], MITRE ATT&CK delineates prevalent tactics, techniques, and procedures employed by cyber attackers, enabling the formulation of effective defensive strategies and threat models. Furthermore, the MITRE ATT&CK is accessible without charge to various entities, including the business sector, government, and the cybersecurity community. This accessibility aids in the advancement of targeted threat models and methods. Unlike other frameworks, such as the Cyber Kill Chain [22], which emphasize overarching tactics and stages of an attack, MITRE ATT&CK offers a comprehensive compilation of techniques categorized by tactics without prescribing a predetermined sequence of actions. This characteristic renders MITRE ATT&CK a more adaptable and extensively employed resource within the cybersecurity domain. In this article, we leverage MITRE ATT&CK by utilizing various procedures to detect and analyze potential threats targeting every smart home component. Specifically, we examine each asset’s classification and use it to identify threats by referencing the techniques and sub-techniques in the associated MITRE ATT&CK matrix (Section 4.2). 2.2. CAPEC The Common Attack Pattern Enumeration and Classification (CAPEC) framework [20] is a fundamental taxonomy in cybersecurity, offering a well-organized and comprehensive collection of common attack patterns adversaries use. Each entry provides a detailed description of specific methodologies, clearly explaining threat actors’ actions, tactics, and strategies. The primary objective of CAPEC is to facilitate a comprehensive understanding of cyber risks by systematically classifying attack patterns. This organized system enables identifying, classifying, and analyzing attack scenarios, significantly contributing to decision-making processes to address evolving cyber threats. The CAPEC framework provides a structured taxonomy of known attack patterns. Each attack pattern is uniquely identified by a CAPEC ID and is accompanied by a detailed name and description. The attributes of a CAPEC attack pattern include: (𝑖) Attack Prerequisites: Specifies the necessary conditions for the attack’s success; (𝑖𝑖) Typical Severity: Indicates the potential impact if the attack is executed; (𝑖𝑖𝑖) Likelihood of Attack: Estimates the frequency of potential attacks; (𝑖𝑣) Execution Flow: Outlines the sequence of actions involved in the attack; (𝑣) Related Weaknesses: References specific software weaknesses through Common Weakness Enumeration (CWE); (𝑣𝑖) Resources: Enumerates the tools, knowledge, and physical resources required for the attack; (𝑣𝑖𝑖) Mitigations: Suggests strategies and tools for preventing, detecting, and mitigating the attack; (𝑣𝑖𝑖𝑖) Example Instances: Provides real-world occurrences of the attack; (𝑖𝑥) Related Attack Patterns: Demonstrates connections to other similar patterns; (𝑥) Taxonomy Mappings: References other relevant frameworks, such as the MITRE ATT&CK framework. In this article, we utilize the taxonomy mappings attribute to establish a correlation between the identified threat on an asset and the related attack pattern of CAPEC. This mapping allows us to determine the likelihood and associated vulnerabilities of the threat, providing valuable insights into calculating the cyber risk for the asset (Section 4.5). 2.3. Embedded devices for smart homes Smart home devices are modern advancements that boost comfort, security, and energy efficiency by using specialized hardware integrated into residential environments. These devices include embedded software designed for specific purposes. Although some categories of these devices may overlap, it is beyond the scope of this paper to classify them into rigid categories. Instead, we aim to assess their cyber risk based on their assigned category. Here is a non-exhaustive list of typical embedded devices someone may encounter in smart homes, illustrating our risk assessment approach. Smart Lighting. These systems are advanced lighting solutions that can be controlled remotely and automatically to improve a home’s ambiance, reduce energy consumption, and increase convenience. Examples include Smart Bulbs and Smart Light Switches. Smart Thermostats. These Internet-connected devices allow remote temperature control through a web interface, voice commands, or a smartphone application. Notable examples include the Nest Thermostat and the Ecobee Smart Thermostat. Smart Security. These systems consist of interconnected devices designed to enhance home protection. They may include Smart Cameras, Smart Doorbells, and Smart Alarms. Smart Appliances. Equipped with advanced sensors, networking capabilities, and interactive control mechanisms, these appliances allow users to manage home environments and optimize energy consumption. Examples include Smart Refrigerators, Smart Ovens, and Smart Washing Machines. Smart Entertainment. These devices offer high-quality media experiences through Internet connectivity and remote or voice control. Common devices in this category include Smart TVs, Smart Speakers, and Smart Projectors. Smart Health. These Internet-connected tools are used to track health metrics, provide medical monitoring, and deliver tailored health insights. Examples include Smart Scales, Smart Blood Pressure Monitors, and Smart Air Purifiers. Smart Pet Care. These devices assist pet owners in managing and monitoring their pets’ health, activity, and safety. Examples include Smart Feeders and Smart Litter Boxes. Smart Cleaning. These innovative gadgets automate and enhance the efficiency of cleaning processes. They can communicate with other smart home systems to provide sophisticated cleaning services, such as Robot Vacuums and Robot Mops. Smart Water Leak and Smoke Detectors. Designed to detect and alert residents to water leaks and smoke, these devices help prevent damage and costly repairs. Examples include the LeakSmart Water Leak Detection Kit, SmartThings Water Leak Sensor, and Google Nest Protect. Smart Gardening. These devices use sensors, automation, and connectivity to help homeowners maintain their gardens efficiently. They monitor soil conditions, control irrigation, and provide care recommendations, contributing to healthy plant growth. Examples include Smart Irrigation Controllers and Smart Moisture Sensors. 2.4. Cybersecurity challenges in smart homes Despite the significant convenience offered by smart homes, characterized by their networked devices and systems, they present numerous cybersecurity challenges. These challenges stem from the complex and interconnected nature of smart home environments, where various devices and systems must work seamlessly together. As the adoption of smart home technology continues to grow, addressing these cybersecurity challenges becomes increasingly critical to ensure the safety and privacy of users. We categorize these challenges as follows. CH1 – Device Proliferation and Interconnectivity. Smart homes, characterized by integrating numerous devices such as thermostats, cameras, door locks, lighting systems, and voice assistants, present substantial cybersecurity challenges. The interconnectivity of these devices increases the potential entry points for malicious attackers. Each device’s unique security protocols and vulnerabilities further complicate the maintenance of a secure network, thereby elevating cyber risk [4, 23]. CH2 – Inconsistent and Inaccessible Cybersecurity Standards. A major obstacle is the lack of standardized cybersecurity measures applicable across various device types and manufacturers [24]. Numerous Journal of Information Security and Applications 91 (2025) 104054 3
G. Paparis et al. companies produce smart home devices with varying levels of commitment to data protection, leading to weak links within the smart home ecosystem. Insufficient cybersecurity measures, such as default passwords or inadequate data encryption, can render devices vulnerable to cyberattacks, jeopardizing the entire network. Furthermore, a significant obstacle to enhancing smart home cybersecurity is the academic community’s lack of free access to relevant cybersecurity standards documents [25]. Some of the most important standards are only accessible under certain restrictions, such as payment, making it challenging to access them for research projects. CH3 – Data Privacy Concerns. Smart home devices collect substantial amounts of private and sensitive data, including daily routines, preferences, security codes, and camera footage [26]. Protecting this data from unauthorized access and maintaining its confidentiality is crucial, as data breaches or unauthorized data collection can lead to severe privacy violations [27–29]. The cybersecurity of smart homes largely depends on the users who maintain them. However, many users are unaware of best practices for securing their smart homes, often using weak passwords, failing to change default settings, and neglecting software updates. CH4 – Integration with Legacy Systems. Smart homes frequently incorporate new devices into pre-existing network infrastructures not originally designed to meet contemporary cybersecurity standards. This integration process can inadvertently introduce security vulnerabilities. Developed before modern cybersecurity practices, legacy systems are particularly susceptible to cyberattacks when interfaced with new, potentially insecure devices. Consequently, the amalgamation of old and new technologies can create a heterogeneous network environment where outdated protocols and insufficient security measures open the system to various cyber threats, such as unauthorized access, data breaches, and malware infections [30,31]. This highlights the critical need for a comprehensive review and upgrade of cybersecurity measures to ensure smart home ecosystems’ safe and secure operation. CH5 – Physical Security Threats. Physical security, often overlooked, is equally essential in maintaining the integrity of smart home systems [32,33]. Severe cybersecurity breaches can occur if unauthorized individuals gain physical access to smart home technology. For instance, intruders can control various connected devices or disable critical security features if they access a smart home’s router. This could lead to significant security risks, including unauthorized surveillance, data theft, and the disruption of essential services. Therefore, ensuring robust physical security measures, such as secure housing for network equipment and controlled access to key components, is crucial in safeguarding the overall cybersecurity of smart home environments. CH6 – Network Security. The home network is a critical component of a smart home security system, interconnecting all smart devices within the household. Vulnerabilities within the home network, such as insecure Wi-Fi configurations or susceptible routers, can expose the entire smart home ecosystem to cyberattacks [28,34]. These vulnerabilities can be exploited to gain unauthorized access, potentially compromising the security and privacy of all connected devices. Consequently, ensuring a secure home network setup, including strong encryption, regular firmware updates, and robust passwords, is vital to protect the smart home ecosystem from potential cyber threats and attacks. 3. Different roles in smart home cybersecurity The cyber risk assessment of a smart home involves two primary actors, each with a distinct role. The first is the cybersecurity professionals who utilize the CRASHED methodology to protect and fortify smart homes against cyber threats, ensuring privacy, safety, and functionality. The second is the cyber attackers who exploit vulnerabilities for malicious purposes, posing significant risks to homeowners. The following sections analyze the assumptions and constraints of these actors in the application of the CRASHED methodology. 3.1. Cybersecurity professionals Cybersecurity professionals are assumed to have compiled a comprehensive and accurate inventory of all smart home devices. Precise threat identification and mitigation require access to up-to-date databases of known vulnerabilities and Common Vulnerabilities and Exposures (CVEs) specific to these devices. Standardized frameworks such as MITRE ATT&CK, CAPEC, and CWE are effective tools for identifying and analyzing threats and vulnerabilities, providing a structured approach to understanding the techniques and methods adversaries might employ against smart home devices. Furthermore, these devices are assumed to operate within typical smart home environments, adhering to common usage patterns, homeowner behaviors, and network configurations. This assumption facilitates the creation of realistic threat scenarios. The connectivity and interoperability of smart home devices, forming an integrated network that communicates through standard protocols, are also assumed, as this interconnectedness is vital for the effective management and security of the smart home ecosystem. Within these assumptions, the scope of CRASHED is restricted to smart devices commonly found in residential settings, excluding specialized or commercial smart devices installed in industrial or enterprise environments. The proposed cyber risk assessment methodology also relies on publicly available data regarding vulnerabilities and attack patterns, excluding proprietary or undisclosed vulnerabilities from this evaluation. Homeowners are assumed to comply with recommended cybersecurity practices, such as regular updates and proper device configuration; however, the model accounts for non-compliance, which could introduce additional cyber risks. Finally, CRASHED primarily focuses on cyber threats, deliberately excluding physical security measures, as malicious actors’ physical access to smart devices is considered an external factor beyond the scope of this assessment. 3.2. Adversary It is assumed that adversaries have access to a wide range of resources and tools, including advanced hacking utilities, malware, and exploit kits, which are often obtainable via the dark web or through open-source penetration testing frameworks like Metasploit [35] and Nmap [36]. These resources enable attackers to conduct highly sophisticated and targeted cyber operations. Furthermore, these attackers possess high technical expertise, including a deep understanding of networking protocols, encryption techniques, and software vulnerabilities. Such expertise allows them to reverse-engineer firmware, bypass security mechanisms, and develop custom exploits. Additionally, adversaries are presumed to be persistent and adaptable, capable of executing prolonged campaigns and employing advanced tactics such as spearphishing, social engineering, and leveraging zero-day vulnerabilities. They are also assumed to possess an in-depth knowledge of smart home architectures, including device interconnectivity, common communication protocols (e.g., Zigbee, Z-Wave, Wi-Fi), and typical user configurations. This knowledge assists them in identifying critical vulnerabilities and potential entry points within the smart home ecosystem. Under these assumptions, adversaries have limited physical access to smart home devices and, therefore, rely primarily on remote exploitation techniques. They must also contend with advanced detection and response mechanisms, including intrusion detection systems (IDS), anomaly detection, and automated security updates, which can rapidly identify and neutralize malicious activities. The swift deployment of cybersecurity patches and updates by manufacturers further constrains the window of opportunity for exploiting known vulnerabilities. Finally, resource limitations, particularly regarding the time and computing power available to cyber attackers, impose constraints that render complex, resource-intensive attacks less feasible. Journal of Information Security and Applications 91 (2025) 104054 4
G. Paparis et al. Fig. 1. CRASHED methodology. 3.3. A not so hypothetical scenario Suppose an adversary gains unauthorized access to a smart home’s integrated system by exploiting network vulnerabilities to orchestrate a coordinated attack. The adversary begins by disabling the smart smoke detectors, rendering them unable to detect smoke or fire. Concurrently, the adversary deactivates the smart alarm system, ensuring the homeowner remains unaware of any impending danger. With these critical safety systems compromised, the adversary remotely activates the smart oven, deliberately setting it to an extremely high temperature, potentially causing a fire. In this scenario, the smart home — once heralded as the epitome of modern convenience and security — becomes a serious safety risk under the control of a malicious entity. While such a scenario might have seemed like science fiction just a few years ago, today it represents a genuine threat, underscoring the urgent need for a comprehensive cyber risk assessment methodology specifically tailored for smart homes [37–40]. Therefore, we propose CRASHED as a cyber risk assessment tool that adopts a holistic approach, considering the smart nature of devices and the potential impacts of a breach on the entire home environment. 4. Methodology In this section, we present CRASHED, a cyber risk assessment methodology, which consists of five steps: (𝑖) Asset Identification, (𝑖𝑖) Threat Identification and Analysis, (𝑖𝑖𝑖) Vulnerability Assessment, (𝑖𝑣) Impact Assessment, and (𝑣) Risk Measurement and Analysis. Fig. 1 illustrates the steps of the proposed methodology, as well as the inputs and outputs associated with each step. CRASHED offers significant advantages over existing cyber risk assessment methodologies, such as OCTAVE [41]. Firstly, it provides a more granular and tailored approach to the unique environment of smart homes by categorizing assets into classes, each with distinct threat profiles and vulnerabilities. This classification facilitates a more precise threat identification and mapping process using the MITRE ATT&CK framework [19], which is more current and comprehensive compared to OCTAVE’s broader, less specific threat modeling. Furthermore, the proposed methodology integrates the CAPEC [20] and CWE [42] frameworks for a detailed weakness analysis, enhancing the accuracy of vulnerability assessments. The methodology also employs quantitative risk calculation measures, incorporating specific likelihood and impact metrics. This ensures a rigorous and systematic risk measurement process, significantly improving OCTAVE’s more qualitative, subjective risk assessment approach. By leveraging real-world data from top-selling smart home devices and their known vulnerabilities, the proposed methodology provides a realistic and practical assessment that aligns closely with the dynamic nature of smart home environments. This alignment results in a more effective and actionable risk mitigation strategy. Lastly, the CRASHED methodology effectively addresses the multifaceted cybersecurity challenges in smart homes (as discussed in Section 2.4). The proliferation of devices and their interconnectivity (CH1) are managed by toolname’s systematic threat assessment across a wide range of smart devices, leveraging the MITRE ATT&CK and CAPEC frameworks to ensure that vulnerabilities unique to highly interconnected environments are thoroughly identified. CRASHED also addresses inconsistent cybersecurity standards (CH2) by applying a unified approach to threat identification and vulnerability assessment, irrespective of the manufacturer or device-specific security protocols, thereby bridging security gaps across various products. Data privacy concerns (CH3) are mitigated by focusing on threats that could compromise sensitive personal information, ensuring secure data flow across smart devices. Additionally, CRASHED accounts for the integration of legacy systems (CH4), which often lack modern cybersecurity features, by incorporating adaptive risk assessments that consider the vulnerabilities of older technologies. Physical security considerations (CH5) are also included, recognizing that cyber threats can emerge from physical access to smart devices. Moreover, toolname’s comprehensive network security analysis ensures that weaknesses in device communications and network protocols (CH6) are promptly identified. This multi-layered approach enables CRASHED to provide a robust framework that addresses the complex and evolving cybersecurity challenges in smart home environments. A cybersecurity risk assessment methodology for smart homes, such as the CRASHED, that handles sensitive user data must adhere to the following key privacy requirements to safeguard the homeowner’s identity: S1. Data Minimization: The methodology should collect and utilize only the minimal amount of information necessary to compute the overall risk. This approach reduces the likelihood of privacy violations that could expose sensitive homeowner data (e.g., CVEs associated with specific smart-home devices), potentially enabling targeted cyberattacks. Minimizing data also limits the risk that the methodology’s users (e.g., cyber-insurance underwriters) may themselves become targets of cyberattacks. S2. Data Sharing: The data employed in the cybersecurity risk assessment should not be disseminated to third parties, even those within the cybersecurity risk ecosystem, thereby preserving confidentiality and preventing unauthorized use. S3. User Anonymity in Device Usage: The device-level cybersecurity risk analysis should be performed under conditions that approximate pseudonymity. Such measures reduce the likelihood that the homeowner can be identified through the device’s associated CVEs or usage patterns. S4. Data Origin Verification: The methodology must verify that all data utilized in the cybersecurity risk assessment is sourced from a trusted and validated environment. This ensures the methodology’s integrity and protects against malfunction or misbehavior arising from spoofed or malicious inputs designed to mislead the analysis. Journal of Information Security and Applications 91 (2025) 104054 5
G. Paparis et al. 4.1. Asset identification and classification The proposed cyber risk assessment methodology for smart homes begins with a critical first phase: identifying and classifying assets. This phase involves a thorough inventory of all assets within a smart home environment and then categorizing them into distinct groups based on their functions and roles. This structured approach ensures a comprehensive understanding of the components of a smart home, which is essential for effective threat detection, vulnerability assessment, and risk evaluation. The categorization process delineates three primary classes: (𝑖) Electronics & Controllers, (𝑖𝑖) Sensors, and (𝑖𝑖𝑖) Gadgets & Appliances. The Electronics & Controllers class encompasses the core components that form the backbone of a smart home network. These assets are vital for seamless integration, efficient management, and effective communication among the various smart devices. Key components in this class include network routers and gateways, such as home routers and Wi-Fi extenders, which are crucial for managing internet connectivity and enabling communication between smart devices. Smart hubs and controllers act as central units that oversee and regulate various smart home gadgets, facilitating seamless communication and automation. Additionally, smart cameras are pivotal in this category, serving as essential surveillance and security monitoring tools, providing both live and recorded video feeds. Smart doorbells with video and audio capabilities enhance security by allowing residents to monitor and communicate with visitors remotely. This class also includes smart TVs, which offer internet access and advanced features such as streaming services, voice control, and integration with home automation systems. Moreover, smart home assistants like Amazon Echo or Google Home use voice commands to control other smart devices, respond to queries, and provide information. Finally, smartphones and tablets are personal interfaces for controlling and monitoring smart home systems. The Sensors class includes all devices capable of detecting and reporting on various environmental conditions. These technologies enable the automation and optimization of a smart home’s environment. A key asset in this category is smart lighting, which includes intelligent lighting systems that can be remotely controlled and programmed for energy efficiency and convenience. Additionally, smart thermostats are devices that regulate heating and cooling systems, optimizing energy usage based on occupancy levels and individual user preferences. Another critical device in this category is the smart water leak sensor, which detects water leaks and potential flooding risks, thereby preventing damage. Moreover, intelligent irrigation controllers manage watering schedules for lawns and gardens, ensuring efficient water use. Finally, smart homes could use intelligent moisture sensors to monitor soil moisture levels, maintaining optimal soil conditions. The Gadgets & Appliances class comprises a diverse range of smart devices designed to enhance lifestyle, convenience, and entertainment within a smart home. These devices often serve as interfaces with other smart home systems to provide a seamless user experience. Critical assets in this class include smart appliances, such as smart refrigerators, smart washing machines, and smart ovens, which offer advanced features like remote control, diagnostics, and energy management. Smart speakers and voice assistants are also important, providing households access to information, music, and home automation features through voice commands. For enhanced entertainment, smart projectors can be paired with other smart home devices to project video content. Another notable device in this class is the smart pet care system, which includes smart feeders and pet cameras that allow for the monitoring and care of pets. By categorizing smart home assets into these classes, we establish a clear framework for analyzing the potential cyber risks associated with each type of device. This classification not only aids in identifying and understanding the unique characteristics and functions of each asset but also facilitates targeted threat identification, vulnerability assessment, and risk analysis in subsequent steps of the methodology. The outcome of the asset identification and classification phase in the proposed cyber risk assessment for smart homes is an Assets Inventory, which includes all smart home assets categorized into one of the aforementioned classes. This inventory serves as a foundational element for the next step. 4.2. Threat identification and analysis The primary objective of this step is to systematically identify potential threats targeting the various smart devices within a smart home and to assess the likelihood of each threat. By utilizing the structured threat modeling frameworks of MITRE ATT&CK matrices and CAPEC, this step ensures a comprehensive and rigorous approach to threat detection. This process begins with the Assets Inventory generated during the Asset Identification and Classification step, where each asset is classified into one of three aforementioned classes: (𝑖) Electronics & Controllers, (𝑖𝑖) Sensors, and (𝑖𝑖𝑖) Gadgets & Appliances. Classifying assets into these classes is pivotal, as it determines the relevant MITRE ATT&CK matrix for threat identification and analysis. Each class of assets is mapped to a specific MITRE ATT&CK matrix, which provides a detailed list of adversarial techniques relevant to that category. Our model equates the techniques listed in the MITRE ATT&CK matrices to potential threats. For assets categorized under the Electronics & Controllers class, relevant threats are derived from the Enterprise Matrix of MITRE ATT&CK. Notice that there may be corner cases in which the aforementioned statement does not hold. However, for the majority of the cases this statement is true. This matrix addresses threats associated with enterprise environments, which apply to devices forming the core infrastructure of a smart home network. For assets in the Sensors class, threats are mapped from the ICS Matrix of MITRE ATT&CK, which focuses on threats specific to industrial control environments, aligning well with the operational technologies and environmental monitoring functions of smart sensors. Finally, for assets within the Gadgets & Appliances class, the Mobile Matrix of MITRE ATT&CK is utilized, identifying threats related to personal gadgets and appliances that often interface with mobile technologies. In this step, each smart device in the Assets Inventory is thoroughly analyzed against the corresponding MITRE ATT&CK matrix based on its classification. Potential threats are identified by mapping each device to the relevant adversarial techniques within the appropriate matrix. For instance, a smart camera from the Electronics & Controllers class is evaluated against threats from the Enterprise Matrix, identifying risks such as unauthorized access, data exfiltration, or firmware manipulation. Next, we leverage the CAPEC database by selecting relevant attack patterns for each identified threat using the Taxonomy Mapping attribute. Specifically, for each threat to each asset, we select the attack patterns (CAPEC-ID) whose Taxonomy Mapping attribute includes the identified threat. In CAPEC, each attack pattern is associated with a likelihood attribute, which indicates the probability of the attack occurring, with possible values of n/a, low, medium, and high. These values are mapped to corresponding scores: 0 for n/a, 0.25 for low, 0.5 for medium, and 0.75 for high. The likelihood of each identified threat to an asset, denoted as 𝐿threat, is then calculated as the median of the likelihoods from its related attack patterns. Mathematically, this is expressed as: 𝐿threat =med(𝐿attack pattern 1,…, 𝐿attack pattern n)(1) where 𝐿threat is the likelihood of the threat to the asset, 𝐿attack pattern 1,…, 𝐿attack pattern n are the likelihoods of the related attack patterns, and 𝑛 is the total number of corresponding attack patterns for the threat. The output of the Threat Identification and Analysis step is a comprehensive list of potential threats for each smart device, along with the calculated likelihood of each threat and the corresponding attack patterns. This detailed threat profile provides a foundational understanding of each asset’s cybersecurity challenges, enabling subsequent steps to focus on vulnerability assessment and risk analysis with a well-defined understanding of the threat landscape. Journal of Information Security and Applications 91 (2025) 104054 6
G. Paparis et al. Table 1 Factors and subfactors of impact on systems (Heartfield et al. [43]). Factor Subfactor Cyber (C) Confidentiality (C-C) Integrity (C-I) Availability (C-A) Non-requdiation (C-NP) Physical (P) Breach of physical privacy (P-BPP) Unauthorized Actuation (P-UA) Incorrect Actuation (P-IA) Delayed Actuation (P-DA) Prevented Actuation (P-PA) 4.3. Vulnerability assessment The Vulnerability Assessment step constitutes the third critical step in the cyber risk assessment methodology for smart homes. The primary goal of this phase is to identify the vulnerabilities corresponding to each threat associated with an asset. This is facilitated by leveraging the CAPEC. Specifically, from the preceding step of Threat Identification and Analysis, it is established that each identified threat to an asset is associated with a set of attack patterns. In CAPEC, each attack pattern is linked to a set of weaknesses, which, in our model, are considered potential vulnerabilities. We define the set of vulnerabilities for each threat to an asset as the discrete union of the vulnerabilities associated with its attack patterns. Mathematically, this relationship is represented as: 𝑉(𝑇𝑖) = ⋃ 𝑗 𝑉(𝑃𝑖,𝑗 )(2) where 𝑇𝑖 denotes each threat to an asset, 𝑃𝑖,𝑗 represents the set of attack patterns corresponding to each threat 𝑇𝑖, 𝑉(𝑃𝑖,𝑗 ) denotes the set of vulnerabilities for each attack pattern 𝑃𝑖,𝑗 , and 𝑉(𝑇𝑖) is the set of vulnerabilities associated with each threat, defined as the union of the vulnerabilities of its attack patterns. The output of the Vulnerability Assessment phase is a detailed profile of each threat to an asset. This profile enumerates all identified vulnerabilities related to the threat, thereby providing a comprehensive understanding of the potential security gaps that require mitigation. 4.4. Impact assessment The Impact Assessment constitutes the fourth step of the proposed Cyber Risk Assessment Methodology. The primary objective of this step is to ascertain the potential impact of an identified threat on an asset. The impact of a threat on an asset is determined by factors. Our methodology leverages the taxonomy classification of threats proposed by Heartfield et al. [43], estimating the impacts of these threats based on two primary impact areas of factors: Impact on Systems and Impact on Domestic Life. The Impact on Systems is divided into two factors. The first is the Cyber (C), which refers to the outcomes and implications arising from occurrences or events in the digital realm. This factor is further subdivided into the following subfactors: Confidentiality (C-C), Integrity (C-I), Availability (C-A), and Non-repudiation (C-NP). The second is the (𝑖𝑖) Physical (P), which pertains to the concrete effects or consequences impacting the physical environment, objects, infrastructure, or humans due to specific events, situations, or actions. This factor is subdivided into the following subfactors: Breach of Physical Privacy (P-BPP), Unauthorized Actuation (P-UA), Incorrect Actuation (P-IA), Delayed Actuation (P-DA), and Prevented Actuation (P-PA). Table 1 presents the subfactors associated with each factor under Impact on Systems. In turn, the Impact on Domestic Life is divided into three factors. The first is the Direct Consequences (DC), which refers to the consequences that affect the financial aspects, productivity, physical Table 2 Factors and subfactors of impact on domestic life. Factor Subfactor Direct Consequences (DC) Financial (DC-F) Vocational (DC-V) Invasion of privacy (DC-P) Loss of Control (DC-LC) Inconvenience (DC-I) User Experience (UX) Instantly Noticeable (UX-N1) Noticeable over time (UX-N2) Not noticeable (UX-NN) Emotional (E) Appraisal (E-A) Action Tendencies (E-AT) Bodily Symptoms (E-B) Expression (E-E) Subjective feeling (E-SF) health, privacy, or control of smart home devices for residents. This factor is subdivided into the following subfactors: Financial (DC-F), Vocational (DC-V), Invasion of Privacy (DC-P), Loss of Control (DCLC), and Inconvenience (DC-I). The second is the User Experience (UX), which refers to the immediate or long-term impact of a threat on the user experience of the affected systems. This factor is subdivided into the following subfactors: Instantly Noticeable (UX-N1), Noticeable Over Time (UX-N2), and Not Noticeable (UX-NN). The third is the Emotional (E), which refers to consequences affecting bodily symptoms or emotional distress (e.g., the resident’s perception of losing control and privacy or reduced capacity to carry out daily personal or professional activities). This factor is subdivided into the following subfactors: Appraisal (E-A), Action Tendencies (E-AT), Bodily Symptoms (E-B), Expression (E-E), and Subjective Feeling (E-SF). Table 2 presents the subfactors associated with each factor under Impact on Domestic Life. Each factor has a corresponding criticality metric for each asset. The criticality of a factor to an asset (𝐶factor𝑖𝑘 ) measures how essential a specific factor is for the given asset. This measure is determined by considering the subfactors associated with the factor and evaluating how many of these subfactors are critical to the asset. To calculate the criticality of a factor to an asset, we use the following equation: 𝐶factor𝑖𝑘 = 𝑚critical subfactors𝑖𝑘 𝑛total subfactors𝑖𝑘 (3) where 𝐶factor𝑖𝑘 is the criticality of factor 𝑘 to asset 𝑖. Similarly, 𝑚critical subfactors𝑖𝑘 is the number of subfactors of factor 𝑘 that are critical for asset 𝑖, and 𝑛total subfactors𝑖𝑘 is the total number of subfactors of factor 𝑘. The impact of a threat on an asset due to a specific factor (𝐼factor𝑖𝑗𝑘 ) quantifies how much a particular factor influences the overall impact of the threat on the asset. This impact is determined by considering three elements: the weight of the threat to the factor, the existence of the threat to the factor, and the criticality of the factor to the asset. To calculate the impact of a threat on an asset due to a factor, we use the following equation: 𝐼factor𝑖𝑗𝑘 =𝑊factor𝑖𝑗𝑘 ×𝐸factor𝑖𝑗𝑘 ×𝐶factor𝑖𝑘 (4) where 𝐼factor𝑖𝑗𝑘 is the impact of threat 𝑗 on asset 𝑖 due to factor 𝑘, 𝑊factor𝑖𝑗𝑘 is the weight of threat 𝑗 to factor 𝑘 for asset 𝑖 (representing the relative importance or severity of the threat concerning the factor, with values ranging from 0 to 1), 𝐸factor𝑖𝑗𝑘 is the existence of threat 𝑗 to factor 𝑘 for asset 𝑖 (indicating whether the threat is present or applicable to the factor, with values of 0 or 1), and 𝐶factor𝑖𝑘 is the criticality of factor 𝑘 to asset 𝑖 (quantifying how essential the factor is to the asset, based on the ratio of critical subfactors to the total subfactors of the factor). The impact of a threat on an asset (𝐼threat𝑖𝑗 ) represents the total effect that a specific threat has on the asset. This impact is determined by considering the influences of all factors associated with the threat. Journal of Information Security and Applications 91 (2025) 104054 7
G. Paparis et al. To calculate the impact of a threat on an asset, we use the following equation: 𝐼threat𝑖𝑗 = 𝑃𝑖𝑗 ∑ 𝑘=1 𝐼factor𝑖𝑗𝑘 (5) where 𝐼threat𝑖𝑗 is the impact of threat 𝑗 on asset 𝑖, 𝑃𝑖𝑗 is the number of factors influencing the impact of threat 𝑗 on asset 𝑖, and 𝐼factor𝑖𝑗𝑘 is the impact of threat 𝑗 on asset 𝑖 due to factor 𝑘. Additionally, the sum of the weights of the threat to the asset’s factors (𝑊factor𝑖𝑗𝑘 ) represents the total contribution of all individual factors influencing the impact of a threat on an asset. This sum must equal 1, ensuring that the weights are normalized and collectively account for the entire impact of the threat. The following equation expresses this: 𝑃𝑖𝑗 ∑ 𝑘=1 𝑊factor𝑖𝑗𝑘 = 1 (6) where 𝑃𝑖𝑗 is the number of factors influencing the impact of threat 𝑗 on asset 𝑖, and 𝑊factor𝑖𝑗𝑘 is the weight of threat 𝑗 to factor 𝑘 for asset 𝑖. 4.5. Risk measurement and analysis Risk measurement and analysis is the final step in our methodology. After identifying assets, along with their corresponding threats and vulnerabilities, this step is dedicated to quantitative measurement and risk analysis. Threat to Asset Risk. The risk associated with a threat to an asset (𝑅threat𝑖𝑗 ) quantifies the potential loss or damage that a specific threat could inflict on the asset. This risk is calculated by considering both the likelihood of the threat occurring and its impact on the asset. The risk due to a threat to an asset is determined using the following equation: 𝑅threat𝑖𝑗 =𝐿threat𝑖𝑗 ×𝐼threat𝑖𝑗 (7) where 𝑅threat𝑖𝑗 represents the risk posed by threat 𝑗 to asset 𝑖, 𝐿threat𝑖𝑗 denotes the likelihood of threat 𝑗 occurring for asset 𝑖 — this term captures the probability or frequency of the threat occurring — and 𝐼threat𝑖𝑗 signifies the impact of threat 𝑗 on asset 𝑖, quantifying the potential damage or loss that could result if the threat materializes. Asset’s Risk. The risk of an asset (𝑅asset𝑖) encapsulates the total potential loss or damage that the asset might incur due to various threats. This overall risk is determined by summing the risks posed by all individual threats to the asset. The risk of an asset is computed using the equation: 𝑅asset𝑖= 𝑀𝑖 ∑ 𝑗=1 𝑅threat𝑖𝑗 (8) where 𝑅asset𝑖 is the risk of asset 𝑖, 𝑀𝑖 is the number of threats to asset 𝑖, and 𝑅threat𝑖𝑗 is the risk posed to asset 𝑖 by threat 𝑗. To normalize the risk of an asset, we first calculate the maximum possible risk that the asset could face if all threats were at their highest possible impact. This maximum risk is calculated using the equation: 𝑅max asset =𝑁×𝑅max threat (9) where 𝑅max asset represents the maximum possible risk of an asset, 𝑁 is the maximum number of threats, and 𝑅max threat is the maximum possible risk to an asset due to a threat. The risk of an asset is then normalized to a scale of 0 to 100 using the following equation: 𝑅normalized asset𝑖=𝑅asset𝑖 𝑅max asset𝑖 × 100 (10) where 𝑅normalized asset𝑖 is the normalized risk of asset 𝑖, 𝑅asset𝑖 is the risk of asset 𝑖, and 𝑅max asset𝑖 is the maximum possible risk of asset 𝑖. A normalized risk closer to 0 indicates a low risk, whereas a value closer to 100 indicates a high risk. Smart Home Risk. The risk of a smart home (𝑅SmartHome) represents the total potential loss or damage that the smart home might experience Table 3 Risk level form. Risk level 𝑅NormalizedSmartHome LOW 0–25 MEDIUM 26–50 HIGH 51–75 CRITICAL 76–100 due to the risks associated with its assets. This overall risk is determined by summing the normalized risks of all individual assets within the smart home. The risk of a smart home is calculated using the equation: 𝑅SmartHome = 𝑁 ∑ 𝑖=1 𝑅normalized asset𝑖(11) where 𝑅SmartHome denotes the total risk of the smart home, 𝑁 is the number of assets in the smart home, and 𝑅normalized asset𝑖 is the normalized risk of asset 𝑖. To normalize the risk of a smart home, we must first compute the maximum possible risk for the smart home, assuming all assets are at their highest possible risk. This is calculated using the equation: 𝑅MaxSmartHome =𝑁×𝑅max asset (12) where 𝑁 represents the total number of assets in the smart home, and 𝑅max asset is the maximum possible risk of an asset within the smart home. The risk of the smart home is then normalized to a scale of 0 to 100 using the following equation: 𝑅NormalizedSmartHome =𝑅SmartHome 𝑅MaxSmartHome × 100 (13) where 𝑅NormalizedSmartHome denotes the normalized risk of the smart home, 𝑅SmartHome is the risk of the smart home, and 𝑅MaxSmartHome is the maximum possible risk for the smart home. A normalized risk closer to 0 indicates low risk, while a value closer to 100 indicates high risk. The normalized risk of smart home can also be translated with the following qualitative form: 0 – 25 [LOW]; 26 – 50 [MEDIUM]; 51 – 75 [HIGH]; 76 – 100 [CRITICAL] (see Table 3). Additionally, an algorithm has been developed to facilitate the risk calculation for each asset, as detailed in Algorithm 1. This algorithm systematically computes the risk associated with each asset within a defined set (Line 1), iterating through each asset to identify potential threats (Lines 2–10). Initially, each asset is classified (Line 3), followed by identifying associated threats (Line 4). Subsequently, the likelihood of each identified threat is calculated using the CAPEC methodology (Line 6). Concurrently, the impact of each threat is assessed (Line 7). The overall risk for each threat is then computed by multiplying the likelihood and impact scores (Line 8). Algorithm 1 CRASHED’s risk calculation 1: procedure RiskCalculate(assets, CAPEC) 2: for each asset in assets do 3: 𝑎𝑠𝑠𝑒𝑡 ←Classify(𝑎𝑠𝑠𝑒𝑡) 4: 𝑡ℎ𝑟𝑒𝑎𝑡𝑠_𝑜𝑓_𝑎𝑠𝑠𝑒𝑡 ←IdentifyThreats(𝑎𝑠𝑠𝑒𝑡) 5: for each threat in threats_of_asset do 6: 𝐿𝑖𝑘𝑒𝑙𝑖ℎ𝑜𝑜𝑑 ←CalculateLikelihood(𝑡ℎ𝑟𝑒𝑎𝑡, 𝐶𝐴𝑃 𝐸𝐶) 7: 𝐼𝑚𝑝𝑎𝑐𝑡 ←CalculateImpact(𝑡ℎ𝑟𝑒𝑎𝑡) 8: 𝑅𝑖𝑠𝑘 ←𝐿𝑖𝑘𝑒𝑙𝑖ℎ𝑜𝑜𝑑 ×𝐼𝑚𝑝𝑎𝑐𝑡 9: end for 10: end for 11: end procedure In a nutshell, the proposed methodology is intended to guide cybersecurity professionals through its defined steps and leverage its outcomes to determine whether a smart home is sufficiently exposed to a given risk. If the aggregated risk assessment result falls into the high or critical risk category, the expert can decompose it by each Journal of Information Security and Applications 91 (2025) 104054 8
G. Paparis et al. Fig. 2. Smart home and indicative CVEs. asset, review the individual risks, and prioritize mitigation efforts accordingly. Essentially, the cybersecurity professional employs the Risk Measurement step to determine the normalized risk of the smart home and classify the total risk level as critical, high, medium, or low. In cases where the overall risk is identified as critical or high, the professional returns to the normalized risk values of individual assets and mitigates the highest risks first, thereby reducing the overall risk of the system. 5. Evaluation In this section, we apply our proposed cyber risk assessment methodology to a case study involving a smart home equipped with commonlyused smart devices. The primary objective is to evaluate the risks posed by cyber threats in a smart home environment, with the ultimate goal of supporting efforts to manage these risks. 5.1. Asset identification and classification A typical smart home setup was considered for the evaluation, comprising devices from three primary categories: (𝑖) Electronics & Controllers, (𝑖𝑖) Sensors, and (𝑖𝑖𝑖) Gadgets & Appliances. The Electronics & Controllers category includes smart cameras, smart doorbells, smart alarms, and smart TVs. The Sensors category includes smart light switches, smart water leak sensors, smart irrigation controllers, and smart moisture sensors. The Gadgets & Appliances category includes smart refrigerators, smart washing machines, smart speakers, and smart ovens. To ensure a realistic evaluation scenario, top-selling brands of smart devices were chosen within each category. These devices inherit the vulnerabilities and CVEs associated with their respective brands and models, offering a comprehensive basis for assessing the cyber risks inherent in modern smart home environments, as illustrated in Fig. 2. The Assets Inventory serves as the foundation for the subsequent steps of CRASHED. Using this inventory, we can identify the threats and vulnerabilities associated with each asset and ultimately determine the total risk for the smart home. As mentioned in Section 4, the total risk is calculated as the normalized sum of the individual risks for each asset listed in the Assets Inventory. Inside View: It is worth to be mentioned here that given the space constraints and the primary focus of this article on demonstrating Table 4 Top-5 threats of the selected smart camera. Threat CAPEC-IDs Likelihood Dynamic Linker Hijacking 13, 640 0.50 Impair Command History Logging 13 0.75 Brute Force 49 0.50 Process Discovery 573 0.25 Rootkit 552 0.50 Table 5 CWEs of the selected smart camera. Threat CWEs Dynamic Linker Hikacking 15, 20, 73, 74, 114, 200, 285, 302, 353, 829 Impair Command History Logging 15, 20, 73, 74, 200, 285, 302, 353 Brute Force 262, 263, 257, 654, 307, 308, 309, 521 Process Discovery 200 Rootkit 284 our methodology rather than exhaustively listing all vulnerabilities for every device, we will narrow our focus to a single device (i.e., a smart camera) for the purpose of illustrating our examples. However, it is important to note that the risk assessment calculations will still encompass all devices within the smart home setup. This approach allows us to effectively showcase the application of our methodology without overwhelming the reader with extensive details on each individual device. 5.2. Threat identification and analysis After identifying and classifying the assets of the smart home and recording them in the Assets Inventory, the next step is to identify the threats associated with each asset and calculate the likelihood of these threats. Following the methodology outlined in Section 4.2, we first identify the threats based on the classification of each asset. For assets classified under Electronics & Controllers all threats from the Enterprise Matrix of MITRE ATT&CK are inherited. Similarly, assets classified under Sensors inherit all threats from the ICS Matrix of MITRE ATT&CK. In the same way, assets classified under Gadgets & Appliances inherit all threats from the Mobile Matrix of MITRE ATT&CK. Next, for each identified threat associated with the assets, we select the relevant attack patterns (CAPEC-ID) whose Taxonomy Mappings attribute contains the identified threat. Finally, the likelihood of each identified threat is calculated according to the methodology described in Section 4.2. To provide an inside view, we utilize a specific device: a smart camera associated with several distinct threats. While a similar analysis has been conducted for all individual devices, as mentioned in Section 5.1, we present only the smart camera analysis due to space constraints. By examining Table 4, we find that the Rootkit threat is mapped to the Install Rootkit attack pattern (CAPEC-ID 552) in the Taxonomy Mapping attribute, which has a likelihood of ‘‘Medium’’, corresponding to a likelihood score of 0.5. Consequently, the likelihood of the Rootkit threat is determined to be 0.5. Similarly, the Dynamic Linker Hijacking threat is mapped to two attack patterns in the Taxonomy Mapping attribute: (𝑖) the Subverting Environment Variable Values attack pattern (CAPEC-ID 13), which has a ‘‘High’’ likelihood (i.e., 0.75), and (𝑖𝑖) the Inclusion of Code in Existing Process attack pattern (CAPEC-ID 640), which has a ‘‘Low’’ likelihood (i.e., 0.25). Therefore, the likelihood of the Dynamic Linker Hijacking threat is calculated as 0.5, which is the median of the likelihood scores of the two aforementioned attack patterns. 5.3. Vulnerability assessment After identifying the comprehensive set of threats to the smart home, the next step involves determining the specific vulnerabilities Journal of Information Security and Applications 91 (2025) 104054 9
G. Paparis et al. Table 13 Comparison of different approaches. Works Contribution Security issues Privacy issues Vulnerabilities databases @ Risk calculation Weighted formulas @ Risk calculation Methodologies Bugeja et al. [46] Framework 73 3 7DREAD Flores et al. [47] Model 3737Bayesian Pturgess et al. [48] Model 737 7 n/a Wang et al. [49] Method 737 7 STPA-FMEA Park et al. [50] Framework 73 3 7FAIR Arat and Akleylek [51] Method 3737n/a Collen and Nijdam [52] Framework 3 3 73n/a Alalade et al. [53] Methodology 737 7 LINDDUN PRO Parsons et al. [54] Model 3 3 7 7 n/a Pandey et al. [55] Model 37 7 7 Negative to Positive Wongvises et al. [56] Method 3737n/a Jacobsson et al. [57] Empirical evaluation 3 3 3 7ISRA Ali and Awad [33] Methodology 3737OCTAVE Allegro CRASHED Methodology 3 3 3 3 MITRE ATT&CK study, highlighting the significance of user education, awareness, and proactive action in the risk mitigation process. Pandey et al. [55] provide a risk assessment model generated from the Negative to Positive method. Automating the process of threatbased risk assessment, specifically tailored to the configurations of smart homes, is the objective of the model to achieve this goal. Using threat-triggered evaluation scenarios that have been built, the utilization of the calculation model is explained and demonstrated. The construction of these scenarios was accomplished by utilizing a technology that consisted of analyzing historical evidence of data exchange within the framework of smart homes. Wongvises et al. [56] propose a method for quantifying security risks that establishes a certain smart house’s security by evaluating smart home devices. In turn, this makes it possible to assess a smart house’s security level. Fault Tree Analysis (FTA), which is the methodology that is typically applied in systems that are regarded to be mission-critical, serves as the foundation for their method. After developing a vulnerability tree of a smart home, the authors applied the inclusion-exclusion law of probability to it in order to ascertain the amount of risk. This work employs the CVSS, NVD, and CVE vulnerability databases in the risk calculation phase. A detailed risk assessment of a smart home automation system was carried out by Jacobsson et al. [57]. The findings of this study highlighted the importance of incorporating security and privacy concerns into the design phase of a smart home automation system. The Information Security Risk Analysis (ISRA) method is utilized to assess the vulnerabilities and threats associated with the system, the likelihood that they will occur, and the potential consequences they may have. The results indicate that the high risks are associated with either the human factor or the software components of the system, pointing out that the risks derived from the human factor would require additional consideration. In the risk calculation phase, this work employs the CVE Vulnerability database. Ali and Awad [33] discuss the importance of conducting a comprehensive security risk assessment for IoT-based smart homes, highlighting the need to consider both cyber and physical security aspects. They made use of the OCTAVE Allegro approach, and they suggested a number of different countermeasures in order to reduce the detected security risks and threats. Table 13 compares the related work with the CRASHED. Works that have a checkmark in the Security Issues column indicate that their proposed risk assessments include the detection of weaknesses in the smart home, prospective threats (such as hackers or malware), and the impact of these threats making their way into the smart home. Works that have a checkmark in the Privacy Issues column indicate that their proposed risk assessment includes the analysis of data life cycle management techniques, permission processes, and data minimization practices. Works with checkmarks in both columns, Security Issues and Privacy Issues, including the set of them. The third and fourth columns pertain to the characteristics involved in calculating risk. Works with checkmarks in the Vulnerability Databases @ Risk Calculation column demonstrate their use of vulnerability databases for risk calculation, while those with checkmarks in the Weighted Formulas @ Risk Calculation demonstrate their use of weights for risk measurement. Based on the Table 13, a significant gap exists in the cyber risk assessment for smart homes, as the majority of works do not utilize these characteristics. Lastly, the Methodologies/Frameworks column indicates risk methodologies or frameworks that contributed to the process of the proposed risk assessment. Consequently, CRASHED is the sole cyber risk assessment methodology that leverages MITRE ATT&CK and CAPEC frameworks and addresses security and privacy issues by basing the risk calculation on vulnerability bases and using a weighting formula. 8. Conclusion The increasing integration of smart home devices into daily life has brought about unparalleled convenience, yet it has also introduced significant cybersecurity challenges that demand immediate attention. This article introduced CRASHED, a comprehensive cyber risk assessment methodology specifically designed to address the unique vulnerabilities of smart home environments. By integrating the MITRE ATT&CK and CAPEC frameworks, CRASHED provides a robust mechanism for identifying, analyzing, and quantifying the risks posed by cyber threats. The methodology’s emphasis on device profiling and the holistic assessment of threats and vulnerabilities offers a more precise evaluation of potential risks than traditional approaches. The case study presented validates the effectiveness of CRASHED in identifying critical threats and formulating strategies to mitigate potential impacts on smart homes. As smart home adoption grows, the need for tailored cybersecurity solutions becomes increasingly critical. CRASHED fills this gap and sets a new standard for cyber risk assessment in smart home ecosystems, paving the way for more secure and resilient digital living environments. CRediT authorship contribution statement Georgios Paparis: Writing – review & editing, Writing – original draft, Visualization, Validation, Supervision, Software, Resources, Project administration, Methodology, Investigation, Funding acquisition, Formal analysis, Data curation, Conceptualization. Apostolis Zarras: Writing – review & editing, Writing – original draft, Visualization, Validation, Supervision, Software, Resources, Project administration, Methodology, Investigation, Funding acquisition, Formal analysis, Data curation, Conceptualization. Aristeidis Farao: Writing – review & editing, Writing – original draft, Visualization, Validation, Supervision, Software, Resources, Project administration, Methodology, Investigation, Funding acquisition, Formal analysis, Data curation, Journal of Information Security and Applications 91 (2025) 104054 16
G. Paparis et al. Conceptualization. Christos Xenakis: Writing – review & editing, Writing – original draft, Visualization, Validation, Supervision, Software, Resources, Project administration, Methodology, Investigation, Funding acquisition, Formal analysis, Data curation, Conceptualization. Research data/code availability The source code is available at https://github.com/UniPiSSL/CRAS HED. Compliance with ethical standards This article does not contain any studies with human participants or animals performed by any of the authors. Declaration of Generative AI and AI-assisted technologies in the writing process During the preparation of this work the authors used Grammarly in order to improve language and readability. After using this tool/service, the authors reviewed and edited the content as needed and take full responsibility for the content of the publication. Declaration of competing interest The authors declare no conflict of interest. Acknowledgments This research has received funding from European Commission’s Horizon Europe and Horizon 2020 research and innovation programs under grant agreements No. 101082440 (CHRISS); No. 101095634 (ENTRUST); No. 101092702 (OASEES); No. 101120962 (RESCALE). Source code availability The source code is available at https://github.com/UniPiSSL/CRAS HED. References [1] Grand View Research. Smart home market size & trends. 2023, https://rb.gy/ w6xtl8. [2] Kor A-L, Pattinson C, Yanovsky M, Kharchenko V. IoT-enabled smart living. Technol Smart Futur 2018;3–28. [3] Marques G, Saini J, Dutta M. IoT enabled computer-aided systems for smart buildings. Springer; 2023. [4] Hammi B, Zeadally S, Khatoun R, Nebhen J. Survey on smart homes: Vulnerabilities, risks, and countermeasures. Comput Secur 2022;117:102677. [5] Report ZE. 65% of US households impacted by cybersecurity in the home security industry statistics. 2024, https://rb.gy/yphuhw. [6] New York Times. Somebody’s watching: Hackers breach ring home security cameras. 2024, https://rb.gy/o1ajl0. [7] News N. Stranger hacks into baby monitor, tells child, ‘I love you’. 2019, https://rb.gy/arfaem. [8] Nord VPN. Hacker terrorizes family by hijacking baby monitor. 2018, https: //rb.gy/vts680. [9] Forbes. Hackers use ddos attack to cut heat to apartments. 2026, https://rb.gy/ 8vtmdw. [10] Pami S, Dai Y, Tan SRX, Roy N, Han J. Spying with your robot vacuum cleaner: Eavesdropping via lidar sensors. In: Proceedings of the 18th conference on embedded networked sensor systems. 2020, p. 354–67. [11] Kaspersky. Xiaomi mi robot vacuum cleaner hacked. 2018, https://rb.gy/gfeaka. [12] Görmüş S, Aydın H, Ulutaş G. Security for the internet of things: A survey of existing mechanisms, protocols and open research issues. J Fac Eng Archit Gazi Univ 2018;33(4):1247–72. [13] Yamauchi M, Ohsita Y, Murata M, Ueda K, Kato Y. Anomaly detection for smart home based on user behavior. In: 2019 IEEE international conference on consumer electronics. ICCE, IEEE; 2019, p. 1–6. [14] Ur B, McManus E, Pak Yong Ho M, Littman ML. Practical trigger-action programming in the smart home. In: Proceedings of the SIGCHI conference on human factors in computing systems. 2014, p. 803–12. [15] Bitdefender. The 2024 IoT security landscape report. 2024, https://rb.gy/ 7h95ho. [16] Boeckl K, Boeckl K, Fagan M, Fisher W, Lefkovitz N, Megas KN, Nadeau E, O’Rourke DG, Piccarreta B, Scarfone K. Considerations for managing internet of things (IoT) cybersecurity and privacy risks. US Department of Commerce, National Institute of Standards and Technology; 2019. [17] Bugeja J, Jacobsson A, Davidsson P. On privacy and security challenges in smart connected homes. In: 2016 European intelligence and security informatics conference. EISIC, IEEE; 2016, p. 172–5. [18] Kolias C, Kambourakis G, Stavrou A, Voas J. DDoS in the IoT: Mirai and other botnets. Computer 2017;50(7):80–4. [19] MITRE. MITRE ATT & CK, https://attack.mitre.org/. [20] MITRE. CAPEC, https://capec.mitre.org/index.html. [21] NIST. Tactics, Techniques, and Procedures (TTPs), https://rb.gy/2umu8q. [22] Martin L. The Cyber Kill Chain, https://lmt.co/46AXLdz. [23] Abiodun OI, Abiodun EO, Alawida M, Alkhawaldeh RS, Arshad H. A review on the security of the internet of things: Challenges and solutions. Wirel Pers Commun 2021;119:2603–37. [24] Bipartisan Policy Center. Smart homes and policy: Cybersecurity risks and tradeoffs. 2022, https://rb.gy/f43z37. [25] Wendzel S. How to increase the security of smart buildings? Commun ACM 2016;59(5):47–9. [26] Guhr N, Werth O, Blacha PPH, Breitner MH. Privacy concerns in the smart home context. SN Appl Sci 2020;2:1–12. [27] Hall F, Maglaras L, Aivaliotis T, Xagoraris L, Kantzavelou I. Smart homes: Security challenges and privacy concerns. 2020, arXiv preprint arXiv:2010. 15394. [28] Kuyucu MK, Bahtiyar Ş, İnce G. Security and privacy in the smart home: A survey of issues and mitigation strategies. In: 2019 4th international conference on computer science and engineering. UBMK, IEEE; 2019, p. 113–8. [29] Zimmermann V, Gerber P, Marky K, Böck L, Kirchbuchner F. Assessing users’ privacy and security concerns of smart home technologies. ICom 2019;18(3):197–216. [30] Ansari AM, Nazir M, Mustafa K. Smart homes app vulnerabilities, threats, and solutions: A systematic literature review. J Netw Syst Manage 2024;32(2):29. [31] IoT cybersecurity: strengthening defenses against threats. American Public University, https://rb.gy/t9xam0. [32] Alshboul Y, Bsoul AAR, Al Zamil M, Samarah S. Cybersecurity of smart home systems: Sensor identity protection. J Netw Syst Manage 2021;29(3):22. [33] Ali B, Awad AI. Cyber and physical security vulnerability assessment for IoT-based smart homes. Sensors 2018;18(3):817. [34] Touqeer H, Zaman S, Amin R, Hussain M, Al-Turjman F, Bilal M. Smart home security: Challenges, issues and solutions at different IoT layers. J Supercomput 2021;77(12):14053–89. [35] Rapid7. Metasploit, https://www.metasploit.com. [36] Nmap ORG. Nmap, https://nmap.org. [37] IoTAC. 8 attacks against a smart home every 24 h. 2023, https://rb.gy/acooq4. [38] Micro T. Inside the smart home: IoT device threats and attack scenarios. 2019, https://rb.gy/1z6x5q. [39] Andrade RO, Ortiz-Garcés I, Cazares M. Cybersecurity attacks on smart home during Covid-19 pandemic. In: 2020 fourth world conference on smart trends in systems, security and sustainability (worldS4). IEEE; 2020, p. 398–404. [40] Apthorpe N, Reisman D, Sundaresan S, Narayanan A, Feamster N. Spying on the smart home: Privacy attacks and defenses on encrypted IoT traffic. 2017, arXiv preprint arXiv:1708.05044. [41] Alberts C, Dorofee A, Stevens J, Woody C. Introduction to the OCTAVE approach. Pittsburgh, PA: Carnegie Mellon University; 2003, p. 72–4. [42] MITRE. Common weakness enumeration. 2024, https://cwe.mitre.org/. [43] Heartfield R, Loukas G, Budimir S, Bezemskij A, Fontaine JR, Filippoupolitis A, Roesch E. A taxonomy of cyber-physical threats and impact in the smart home. Comput Secur 2018;78:398–428. [44] Akpan F, Bendiab G, Shiaeles S, Karamperidis S, Michaloliakos M. Cybersecurity challenges in the maritime sector. Network 2022;2(1):123–38. [45] Schinas O, Metzger D. Cyber-seaworthiness: A critical review of the literature. Mar Policy 2023;151:105592. [46] Bugeja J, Jacobsson A, Davidsson P. PRASH: A framework for privacy risk analysis of smart homes. Sensors 2021;21(19):6399. [47] Flores M, Heredia D, Andrade R, Ibrahim M. Smart home IoT network risk assessment using Bayesian networks. Entropy 2022;24(5):668. [48] Pturgess J, Nurse JR, Zhao J. A capability-oriented approach to assessing privacy risk in smart home ecosystems. In: Living in the internet of things: cybersecurity of the ioT-2018. IET; 2018, p. 1–8. [49] Wang Y, Zhang R, Zhang X, Zhang Y. Privacy risk assessment of smart home system based on a STPA–FMEA method. Sensors 2023;23(10):4664. [50] Park M, Oh H, Lee K. Security risk measurement for information leakage in IoT-based smart homes from a situational awareness perspective. Sensors 2019;19(9):2148. [51] Arat F, Akleylek S. A new method for vulnerability and risk assessment of IoT. Comput Netw 2023;237:110046. Journal of Information Security and Applications 91 (2025) 104054 17
G. Paparis et al. [52] Collen A, Nijdam NA. Can I sleep safely in my smarthome? A novel framework on automating dynamic risk assessment in IoT environments. Electronics 2022;11(7):1123. [53] Alalade ED, Mahyoub M, Matrawy A. Privacy engineering in smart home (SH) systems: A comprehensive privacy threat analysis and risk management approach. 2024, arXiv preprint arXiv:2401.09519. [54] Parsons EK, Panaousis E, Loukas G. How secure is home: Assessing human susceptibility to IoT threats. In: Proceedings of the 24th pan-hellenic conference on informatics. 2020, p. 64–71. [55] Pandey P, Collen A, Nijdam N, Anagnostopoulos M, Katsikas S, Konstantas D. Towards automated threat-based risk assessment for cyber security in smarthomes. In: Proceedings of the 18th European conference on cyber warfare and security (ECCWS 2019), Coimbra, Portugal. 2019, p. 4–5. [56] Wongvises C, Khurat A, Fall D, Kashihara S. Fault tree analysis-based risk quantification of smart homes. In: 2017 2nd international conference on information technology. INCIT, IEEE; 2017, p. 1–6. [57] Jacobsson A, Boldt M, Carlsson B. A risk analysis of a smart home automation system. Future Gener Comput Syst 2016;56:719–33. Journal of Information Security and Applications 91 (2025) 104054 18