The Internet of Things (IoT) has evolved through the interconnection of edge devices, enabling seamless data exchange across networks. With IoT adoption expanding into various sectors, the massive growth of generated data has raised concerns about the security of edge devices tasked with processing this information. While several metrics exist to assess vulnerability severity and support risk management, many fail to account for the distinct characteristics of IoT environments and lack precision in evaluating hardware-specific vulnerabilities. This paper provides a comprehensive review of current vulnerability metrics and frameworks and introduces a novel method for analyzing memory-related vulnerabilities in IoT edge devices. The proposed approach leverages functional size measurement through COSMIC (ISO 19761), a standardized measurement method for quantifying software functionality. By applying COSMIC, memory-related vulnerabilities can be assessed from a functional perspective. Additionally, a prototype tool is presented that automates the evaluation of memory vulnerabilities on ESP boards using COSMIC-based measurements. Findings highlight the potential of incorporating functional sizing into IoT security assessment practices.
Salem et al. (Mon,) studied this question.