scieee AI-readable full text Open interactive document viewer

IoT Security Risk Assessment for Smart Homes

Gunjal, Rohini Sandip

Abstract

The rapid expansion of smart home environments, fueled by the rise of Internet of Things (IoT) devices such as smart locks, cameras, voice assistants, and various sensors, has heightened concerns surrounding cybersecurity. These devices often contain vulnerabilities that expose users to threats including unauthorized access, data theft, device manipulation, botnet infections, and privacy breaches. This research introduces a Cybersecurity Risk Assessment Model (CRAM) specifically designed for smart home IoT ecosystems. The model evaluates risk using factors such as device vulnerability level, threat exposure, impact severity, exploit likelihood, and user security behavior. By integrating structured threat modeling, risk scoring methods, and mitigation mapping, the model supports both consumers and developers in identifying, prioritizing, and addressing IoT-related security issues. Experimental evaluation demonstrates that CRAM enhances risk detection accuracy and improves decision-making for vulnerability mitigation within smart home environments.

Full text

Journal of Research and Development A Multidisciplinary International Level Referred and Double Blind Peer Reviewed, Open Access ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-11(I)| November 2025 88 IoT Security Risk Assessment for Smart Homes Gunjal Rohini Sandip Asst. Prof. Sahakar Maharshi Bhausaheb Santuji Thorat College of Arts, Science & Commerce College Sangamner, TalSangamner, DistAhmednagar, (MH) Manuscript ID: JRD -2025-171121 ISSN: 2230-9578 Volume 17 Issue 11 (I) Pp. 88-91 Nov. 2025 Submitted:15 Oct. 2025 Revised: 25 Oct. 2025 Accepted: 10 Nov. 2025 Published: 30 Nov. 2025 Abstract The rapid expansion of smart home environments, fueled by the rise of Internet of Things (IoT) devices such as smart locks, cameras, voice assistants, and various sensors, has heightened concerns surrounding cybersecurity. These devices often contain vulnerabilities that expose users to threats including unauthorized access, data theft, device manipulation, botnet infections, and privacy breaches. This research introduces a Cybersecurity Risk Assessment Model (CRAM) specifically designed for smart home IoT ecosystems. The model evaluates risk using factors such as device vulnerability level, threat exposure, impact severity, exploit likelihood, and user security behavior. By integrating structured threat modeling, risk scoring methods, and mitigation mapping, the model supports both consumers and developers in identifying, prioritizing, and addressing IoT-related security issues. Experimental evaluation demonstrates that CRAM enhances risk detection accuracy and improves decision-making for vulnerability mitigation within smart home environments. Keywords: Internet of Things (IoT),Smart Home Security,Cybersecurity Risk Assessment, Vulnerability Analysis.Threat Modeling,Risk Scoring Model, IoT Device Security, Privacy Protection,Secure Communication,Firmware Vulnerabilities. Introduction As technology continues to permeate modern-day society, the security of, and trust that we place in, these systems becomes an increasingly significant concern. This is particularly given the plethora of attacks being launched that target organisations, governments and society.The adoption of smart home IoT devices has increased rapidly due to advancements in wireless technology and automation. These connected devices exchange sensitive information, making security a crucial requirement. However, many smart home devices lack strong security features due to limited processing capability, outdated firmware, weak default passwords, and poor encryption practices. As technology continues to permeate modern-day society, the security of, and trust that we place in, these systems becomes an increasingly significant concern. This is particularly given the plethora of attacks being launched that target organisations, governments and society. The traditional approach to address such challenges has been to conduct cybersecurity risk assessments that seek to identify critical assets, the threats they face, the likelihood of a successful attack, and the harms that may be caused. The (IoT) is set to benefit society through a range of smart platforms and a pervasive coupling of digital, cyber-physical and social systems. This coupling allows relationships between systems that may vary drastically in terms of density, time, and automation. Ultimately, adopting these methods to IoT may make us blind to new risks arising in their ecosystems. Objectives 1. To identify common vulnerabilities in smart home IoT devices. 2. To design a cybersecurity risk assessment model specifically for smart home ecosystems. 3. to identify and prioritize risks, ensure the confidentiality, integrity, and availability of data and systems, and develop mitigation strategies 4. To propose mitigation strategies for high-risk devices. 5. To Preserve data and system security 6. To Ensure physical security Quick Response Code: Website: https://jrdrvb.org/ DOI: Creative Commons (CC BY-NC-SA 4.0) This is an open access journal, and articles are distributed under the terms of the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International Public License, which allows others to remix, tweak, and build upon the work noncommercially, as long as appropriate credit is given and the new creations ae licensed under the idential terms. Address for correspondence: Gunjal Rohini Sandip,Sahakar Maharshi Bhausaheb antuji Thorat College of Arts, Science & Commerce College Sangamner, TalSangamner, DistAhmednagar, (MH) How to cite this article: Gunjal Rohini Sandip, Sahakar (2025). IoT Security Risk Assessment for Smart HomesJournal of Research & Development, 17(11(I)), 88-91. Original Article Journal of Research and Development A Multidisciplinary International Level Referred and Double Blind Peer Reviewed, Open Access ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-11(I)| November 2025 89 Keywords:-IoT, Cyber Security, Risk Assistment,Smart Home 1. Cyber attackers exploit these weaknesses:- 2. Phishing attacks – tricking users into revealing sensitive information. 3. Malware infections – installing harmful software like ransomware or spyware. 4. Unauthorized access / account takeover – breaking into accounts using weak passwords or poor authentication. 5. Data breaches – stealing confidential information from poorly secured systems. 6. Privilege escalation – using misconfigurations or vulnerabilities to gain higher-level access. 7. Man-in-the-middle attacks – intercepting communications if networks are not properly secured. 8. SQL injection / input-validation exploits – manipulating poorly secured applications to access or alter data. 9. Malware attacks: This includes using ransomware to encrypt files and demand a ransom, or other forms of malware like viruses, spyware, and worms. 10. Data breaches: Attackers gain unauthorized access to steal sensitive information such as login credentials, financial data, or personal records. 11. Denial-of-service (DoS) attacks: These attacks overwhelm a system with traffic, making it unavailable to its intended users. 12. Remote Code Execution (RCE): This allows attackers to run malicious code on a vulnerable system, giving them a high level of control and access. 13. Phishing and social engineering: These attacks manipulate people into revealing sensitive information through deceptive emails, messages, or calls. 14. Unpatched software: Exploiting vulnerabilities in outdated software that have not been updated with the latest security patches. 15. Weak authentication: Exploiting weak or default passwords and other weak authentication mechanisms. 16. Misconfigurations: Exploiting security misconfigurations in systems and networks. 17. Insecure communication: Exploiting insecure communication protocols or network segmentation weaknesses. Problem Statement: The development of technologies in smart homes today, snip attention of many researchers due to the importance that these smart homes can bring to human beings. Smart homes are used to improve everyday life like monitoring (homes, children, old people and patients in hospital), home security, smart hospitals and automation in many buildings. Current cyber security risk assessment models largely fail to adequately address the specific vulnerabilities within smart home Internet of Things (IoT) ecosystems .These environments present distinct security challenges, including constrained device resources, the absence of robust built-in authentication mechanisms, significant device heterogeneity, potential for user configuration errors, and persistent connectivity .Enterprise-focused or overly generalized risk models are ill-equipped to handle these nuances. Consequently, this research seeks to develop a novel, lightweight, and precise cyber security risk assessment model explicitly tailored for evaluating and mitigating security risks in smart home environments. However, there are many security problems and challenges that still persisting in smart homes, and these, somehow makes smart homes be vulnerable not only for their residents, but also to the manufacturers of smart devices. There are different situations like cyber-attacks, implantation of spy devices or the complete modification of data happening with frequency in smart home applications. We also analyze some opening issues like data integrity, confidentiality, non-repudiation and so on, to improve security of residents. Approaches of these problems, the techniques for their minimization, and at the end, solutions are brought to the efficient working principles of smart homes. The lack of a specialized risk assessment approach leaves smart homes vulnerable to cyber-attacks, data manipulation, unauthorized access, and privacy violations. Therefore, there is an urgent need for a dedicated, lightweight, and precise cyber security risk assessment model tailored specifically for smart homes. Literature Review IoT Security Challenges Studies by Sicari et al. (2018) and Alrawais et al. (2017) highlight issues such as insecure communication, weak authentication, outdated firmware, and data leakage in consumer IoT devices. Smart Home Vulnerabilities Zhang et al. (2020) found that smart home hubs often act as a single point of failure. Vulnerabilities in smart locks and cameras allow attackers to bypass control mechanisms. Research Methodology As smart home products are usually used within the confines of the home, they have access to a large amount of users’ private information, making it easy for privacy risks to occur. To improve the privacy security of smart home systems, a large number of scholars have conducted research in this area. Charlie et al. [1] found that reducing the autonomy and independence of the home and increasing technological controls were most likely to create privacy risks, through a national survey of representative users of smart homes in the UK. Ni JB et al. [2] introduced a fog computing Journal of Research and Development A Multidisciplinary International Level Referred and Double Blind Peer Reviewed, Open Access ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-11(I)| November 2025 90 program to enhance IoT functionality, and the study found that fog computing has new requirements for system privacy and security. Additionally, addressing privacy issues still requires more attention and effort. Norman and Ksenia [3] constructed a framework for a unified theory of acceptance and use of technology that incorporates the structure of the privacy algorithm, and found that the issue of perceived privacy has a significant impact on perceived value. Francesca et al. [4] believe that many low-end IoT devices cannot support advanced security defence mechanisms, leading them to be targeted and even exploited by security attacks. The configuration parameters of most smart home devices are at a low level, which is already a weak point in cyber security, and coupled with the fact that they contain a lot of personal information, they are even more of a target. Tools Used Here is a clear, descriptive-format version of your “Tools Used” section, suitable for a report or documentation: 1. Nmap (Network Scanning) Nmap is a powerful reconnaissance tool used to identify active devices, open ports, running services, and network configurations. In this project, Nmap was employed to scan IoT devices within the testbed to detect exposed ports, map the network topology, and assess potential entry points that an attacker might exploit. 2. Wireshark (Traffic Analysis) Wireshark is a packet-capturing tool used for analyzing network traffic in real time. It was utilized to inspect communication between IoT devices and the network, identify unusual traffic patterns, and detect unencrypted or vulnerable data transmissions. This helped evaluate the security posture of the IoT environment at the packet level. 3. Python (Risk Calculation & Automation) Python scripts were used to automate risk calculation processes, parse scan results, and compute risk scores based on factors like impact, exploitability, and device criticality. Python also assisted in data visualization and generating summary outputs to support decision-making in vulnerability management. 4. IoT Testbed (ESP32, Smart Camera, Smart Plug) The IoT testbed consisted of commonly used smart devices, including an ESP32 microcontroller, a smart camera, and a smart plug. These devices were configured in a controlled environment to simulate real-world IoT ecosystems. They served as targets for scanning, traffic monitoring, and vulnerability assessment in order to observe how typical IoT devices respond to security analysis.If you want, I can expand this further into a full “Methodology” or “Tools & Technologies” section for a report. Specific solutions proposed or supported by the research include: 1. Insecure communication: The studies advocate the use of strong encryption protocols for all data transmission. a. Implementation: Using SSL/TLS encryption for communication between devices and cloud servers is a key recommendation to ensure confidentiality and integrity of data in transit. 2. Weak authentication: The researchers suggest implementing strong identity verification mechanisms to ensure only authorized devices and users can connect to the network. a. Implementation: This involves moving beyond default credentials, using strong password policies, enabling multifactor authentication (MFA) where possible, and employing Public Key Infrastructure (PKI) with digital certificates for device identity verification. 3. Outdated firmware: Both studies point to the need for effective mechanisms to patch vulnerabilities. a. Implementation: This requires manufacturers to provide regular and secure Over-The-Air (OTA) firmware updates and for users to apply these updates promptly. Devices should also use secure boot mechanisms to prevent unauthorized firmware from running. 4. Data leakage: To mitigate data leakage, the researchers recommend strong data encryption both during transmission and at rest. 5. Implementation: This includes encrypting stored data and using secure hardware features for data storage. Network segmentation, which isolates IoT devices from critical IT systems, is also an effective approach to minimize the impact of a breach. Conclusion This research proposes a specialized Cyber security Risk Assessment Model designed for smart home IoT environments. The model overcomes limitations of traditional frameworks by accommodating device-specific constraints and incorporating both technical and user-driven risk factors. CRAM effectively identifies weaknesses, prioritizes risks, and guides users toward actionable mitigation strategies with minimal computational load. Although the model shows strong capability in enhancing smart home cyber security, further improvements are encouraged, including: Integration of machine learning for predictive threat analysis .Automated patching and self-healing mechanisms for IoT devices. The findings underscore the need for continuous innovation in securing smart home ecosystems as technology evolves. Journal of Research and Development A Multidisciplinary International Level Referred and Double Blind Peer Reviewed, Open Access ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-11(I)| November 2025 91 References 1. Wilson, C.; Hargreaves, T.; Hauxwell-Baldwin, R. Benefits and risks of smart home technologies. Energy Policy 2017, 103, 72–83. 2. Ni, J.B.; Zhang, K.; Lin, X.D.; Shen, X.M. Securing Fog Computing for Internet of Things Applications: Challenges and Solutions. IEEE Commun. Surv. Tutor. 2018, 20, 601–628. 3. Shaw, N.; Sergueeva, K. The non-monetary benefits of mobile commerce: Extending UTAUT2 with perceived value. Int. J. Inform. Manag. 2019, 45, 44–55. 4. Meneghello, F.; Calore, M.; Zucchetto, D.; Polese, M.; Zanella, A. IoT: Internet of Threats? A Survey of Practical Security Vulnerabilities in Real IoT Devices. IEEE Internet Things J. 2019, 6, 8182–8201. 5. Security Problems in Smart Homes September 2021Authors:Alberto Coboi HanoiUniversity of Industry