{"id":"https://openalex.org/W3148356943","doi":"https://doi.org/10.3390/s21072329","title":"The Presence, Trends, and Causes of Security Vulnerabilities in Operating Systems of IoT\u2019s Low-End Devices","display_name":"The Presence, Trends, and Causes of Security Vulnerabilities in Operating Systems of IoT\u2019s Low-End Devices","publication_year":2021,"publication_date":"2021-03-26","ids":{"openalex":"https://openalex.org/W3148356943","doi":"https://doi.org/10.3390/s21072329","mag":"3148356943","pmid":"https://pubmed.ncbi.nlm.nih.gov/33810605"},"language":"en","primary_location":{"id":"doi:10.3390/s21072329","is_oa":true,"landing_page_url":"https://doi.org/10.3390/s21072329","pdf_url":"https://www.mdpi.com/1424-8220/21/7/2329/pdf?version=1617937261","source":{"id":"https://openalex.org/S101949793","display_name":"Sensors","issn_l":"1424-8220","issn":["1424-8220"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj","pubmed"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/1424-8220/21/7/2329/pdf?version=1617937261","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5059350219","display_name":"Abdullah Al-Boghdady","orcid":"https://orcid.org/0000-0002-6378-8363"},"institutions":[{"id":"https://openalex.org/I145487455","display_name":"Cairo University","ror":"https://ror.org/03q21mh05","country_code":"EG","type":"education","lineage":["https://openalex.org/I145487455"]}],"countries":["EG"],"is_corresponding":true,"raw_author_name":"Abdullah Al-Boghdady","raw_affiliation_strings":["Department of Computer Sciences, Faculty of Computers and Artificial Intelligence, Cairo University, 5 Ahmed Zewail Street, Dokki, Giza 12613, Egypt"],"raw_orcid":"https://orcid.org/0000-0002-6378-8363","affiliations":[{"raw_affiliation_string":"Department of Computer Sciences, Faculty of Computers and Artificial Intelligence, Cairo University, 5 Ahmed Zewail Street, Dokki, Giza 12613, Egypt","institution_ids":["https://openalex.org/I145487455"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027622725","display_name":"Khaled Wassif","orcid":"https://orcid.org/0000-0002-7401-5219"},"institutions":[{"id":"https://openalex.org/I145487455","display_name":"Cairo University","ror":"https://ror.org/03q21mh05","country_code":"EG","type":"education","lineage":["https://openalex.org/I145487455"]}],"countries":["EG"],"is_corresponding":false,"raw_author_name":"Khaled Wassif","raw_affiliation_strings":["Department of Computer Sciences, Faculty of Computers and Artificial Intelligence, Cairo University, 5 Ahmed Zewail Street, Dokki, Giza 12613, Egypt"],"raw_orcid":"https://orcid.org/0000-0002-7401-5219","affiliations":[{"raw_affiliation_string":"Department of Computer Sciences, Faculty of Computers and Artificial Intelligence, Cairo University, 5 Ahmed Zewail Street, Dokki, Giza 12613, Egypt","institution_ids":["https://openalex.org/I145487455"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5029231135","display_name":"Mohammad El\u2010Ramly","orcid":"https://orcid.org/0000-0002-5076-3829"},"institutions":[{"id":"https://openalex.org/I145487455","display_name":"Cairo University","ror":"https://ror.org/03q21mh05","country_code":"EG","type":"education","lineage":["https://openalex.org/I145487455"]}],"countries":["EG"],"is_corresponding":false,"raw_author_name":"Mohammad El-Ramly","raw_affiliation_strings":["Department of Computer Sciences, Faculty of Computers and Artificial Intelligence, Cairo University, 5 Ahmed Zewail Street, Dokki, Giza 12613, Egypt"],"raw_orcid":"https://orcid.org/0000-0002-5076-3829","affiliations":[{"raw_affiliation_string":"Department of Computer Sciences, Faculty of Computers and Artificial Intelligence, Cairo University, 5 Ahmed Zewail Street, Dokki, Giza 12613, Egypt","institution_ids":["https://openalex.org/I145487455"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5059350219"],"corresponding_institution_ids":["https://openalex.org/I145487455"],"apc_list":{"value":2400,"currency":"CHF","value_usd":2598},"apc_paid":{"value":2400,"currency":"CHF","value_usd":2598},"fwci":4.0076,"has_fulltext":true,"cited_by_count":37,"citation_normalized_percentile":{"value":0.93749454,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":"21","issue":"7","first_page":"2329","last_page":"2329"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10273","display_name":"IoT and Edge/Fog Computing","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10273","display_name":"IoT and Edge/Fog Computing","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.771193265914917},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6192916631698608},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5214728116989136},{"id":"https://openalex.org/keywords/source-code","display_name":"Source code","score":0.513076901435852},{"id":"https://openalex.org/keywords/open-source","display_name":"Open source","score":0.45592477917671204},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.42601048946380615},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.20046457648277283},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.1162620484828949}],"concepts":[{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.771193265914917},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6192916631698608},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5214728116989136},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.513076901435852},{"id":"https://openalex.org/C3018397939","wikidata":"https://www.wikidata.org/wiki/Q3644502","display_name":"Open source","level":3,"score":0.45592477917671204},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.42601048946380615},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.20046457648277283},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.1162620484828949},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0}],"mesh":[],"locations_count":5,"locations":[{"id":"doi:10.3390/s21072329","is_oa":true,"landing_page_url":"https://doi.org/10.3390/s21072329","pdf_url":"https://www.mdpi.com/1424-8220/21/7/2329/pdf?version=1617937261","source":{"id":"https://openalex.org/S101949793","display_name":"Sensors","issn_l":"1424-8220","issn":["1424-8220"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors","raw_type":"journal-article"},{"id":"pmid:33810605","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/33810605","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors (Basel, Switzerland)","raw_type":null},{"id":"pmh:oai:doaj.org/article:6bcf1e586d014bd2a4f6a2c74026e2c2","is_oa":true,"landing_page_url":"https://doaj.org/article/6bcf1e586d014bd2a4f6a2c74026e2c2","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Sensors, Vol 21, Iss 7, p 2329 (2021)","raw_type":"article"},{"id":"pmh:oai:mdpi.com:/1424-8220/21/7/2329/","is_oa":true,"landing_page_url":"https://dx.doi.org/10.3390/s21072329","pdf_url":null,"source":{"id":"https://openalex.org/S4306400947","display_name":"MDPI (MDPI AG)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210097602","host_organization_name":"Multidisciplinary Digital Publishing Institute (Switzerland)","host_organization_lineage":["https://openalex.org/I4210097602"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Sensors; Volume 21; Issue 7; Pages: 2329","raw_type":"Text"},{"id":"pmh:oai:pubmedcentral.nih.gov:8037610","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/8037610","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Sensors (Basel)","raw_type":"Text"}],"best_oa_location":{"id":"doi:10.3390/s21072329","is_oa":true,"landing_page_url":"https://doi.org/10.3390/s21072329","pdf_url":"https://www.mdpi.com/1424-8220/21/7/2329/pdf?version=1617937261","source":{"id":"https://openalex.org/S101949793","display_name":"Sensors","issn_l":"1424-8220","issn":["1424-8220"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.7599999904632568,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320321148","display_name":"Cairo University","ror":"https://ror.org/03q21mh05"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3148356943.pdf","grobid_xml":"https://content.openalex.org/works/W3148356943.grobid-xml"},"referenced_works_count":25,"referenced_works":["https://openalex.org/W2004685423","https://openalex.org/W2032897247","https://openalex.org/W2083795504","https://openalex.org/W2125555950","https://openalex.org/W2343874908","https://openalex.org/W2586432806","https://openalex.org/W2587026909","https://openalex.org/W2733765803","https://openalex.org/W2765188650","https://openalex.org/W2791403216","https://openalex.org/W2794385060","https://openalex.org/W2883458659","https://openalex.org/W2884009065","https://openalex.org/W2887360891","https://openalex.org/W2902215642","https://openalex.org/W2932658615","https://openalex.org/W2935818565","https://openalex.org/W2962887681","https://openalex.org/W2999115679","https://openalex.org/W3011558368","https://openalex.org/W3020687048","https://openalex.org/W3033053557","https://openalex.org/W3093700956","https://openalex.org/W6732924242","https://openalex.org/W6744902427"],"related_works":["https://openalex.org/W4245926026","https://openalex.org/W4311097251","https://openalex.org/W2586548817","https://openalex.org/W2113128227","https://openalex.org/W632256878","https://openalex.org/W2491403535","https://openalex.org/W3081644756","https://openalex.org/W2479811461","https://openalex.org/W2104915799","https://openalex.org/W4311938462"],"abstract_inverted_index":{"Internet":[0],"of":[1,45,48,55,62,87,91,103,131,137,156,160,215,219,230,243,261,284,287,312,315],"Things":[2],"Operating":[3],"Systems":[4],"(IoT":[5],"OSs)":[6],"run,":[7],"manage":[8],"and":[9,36,52,79,127,185,192,197,200,222,227,249,264,281,290,303],"control":[10],"IoT":[11,23,68,95,115,140,168,178,220,231,247,317],"devices.":[12],"Therefore,":[13],"it":[14],"is":[15,142,163,309],"important":[16],"to":[17,83,124,146,188,195,203,211],"secure":[18],"the":[19,43,49,53,59,63,85,101,106,129,147,206,213,216,223,228,240,258,282,304,313,316],"source":[20,60,67,180],"code":[21,61,86,117,181,288,291],"for":[22,33,166],"OSs,":[24,96],"especially":[25],"if":[26],"they":[27],"are":[28],"deployed":[29],"on":[30],"devices":[31],"used":[32,82,210],"human":[34],"care":[35],"safety.":[37],"In":[38],"this":[39,71],"paper,":[40],"we":[41],"report":[42],"results":[44],"our":[46],"investigations":[47],"security":[50,56,125,132,244,262,274,300],"status":[51],"presence":[54,102,229,283],"vulnerabilities":[57,104,126,176],"in":[58,139,177],"most":[64,174],"popular":[65],"open":[66],"OSs.":[69],"Through":[70],"research,":[72],"three":[73],"Static":[74],"Analysis":[75],"Tools":[76],"(Cppcheck,":[77],"Flawfinder":[78],"RATS)":[80],"were":[81,182],"examine":[84],"sixteen":[88],"different":[89,93],"releases":[90],"four":[92],"C/C++":[94],"with":[97,170],"48":[98],"examinations,":[99],"regarding":[100],"from":[105,120,144],"Common":[107],"Weakness":[108],"Enumeration":[109],"(CWE).":[110],"The":[111,134,173],"examination":[112],"reveals":[113,235],"that":[114,122],"OS":[116,179,232,318],"still":[118],"suffers":[119],"errors":[121,138,153,245,263],"lead":[123],"increase":[128],"opportunity":[130],"breaches.":[133],"total":[135,241,259],"number":[136,242,260],"OSs":[141,221,248],"increasing":[143],"version":[145],"next,":[148],"while":[149],"error":[150,275,301],"density,":[151],"i.e.,":[152],"per":[154,278],"1K":[155,279],"physical":[157],"Source":[158],"Lines":[159],"Code":[161,265],"(SLOC)":[162],"decreasing":[164],"chronologically":[165],"all":[167],"Oss,":[169],"few":[171],"exceptions.":[172],"prevalent":[175],"CWE-561,":[183],"CWE-398":[184],"CWE-563":[186],"according":[187,194,202],"Cppcheck,":[189],"(CWE-119!/CWE-120),":[190],"CWE-120":[191,199],"CWE-126":[193],"Flawfinder,":[196],"CWE-119,":[198],"CWE-134":[201],"RATS.":[204],"Additionally,":[205],"CodeScene":[207,234,267],"tool":[208],"was":[209],"investigate":[212],"development":[214],"evolutionary":[217],"properties":[218],"relationship":[224],"between":[225,239,257,273,299],"them":[226],"vulnerabilities.":[233],"strong":[236,254,270,296],"positive":[237,271],"correlation":[238,256,272,298],"within":[246],"SLOC,":[250],"as":[251,253,293,295],"well":[252,294],"negative":[255,297],"Health.":[266],"also":[268],"indicates":[269],"density":[276,302],"(errors":[277],"SLOC)":[280],"hotspots":[285],"(frequency":[286],"changes":[289],"complexity),":[292],"Qualitative":[305],"Team":[306],"Experience,":[307],"which":[308],"a":[310],"measure":[311],"experience":[314],"developers.":[319]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":9},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":9},{"year":2022,"cited_by_count":5},{"year":2021,"cited_by_count":2}],"updated_date":"2026-06-10T14:10:52.464848","created_date":"2025-10-10T00:00:00"}
