Internet Service Providers (ISPs) and individual users of Internet of Things (IoT) play a vital role in securing IoT. However, encouraging them to do so is hard. Our study investigates ISPs' and individuals' attitudes towards the security of IoT, the obstacles they face, and their incentives to keep IoT secure, drawing evidence from Japan. Due to the complex interactions of the stakeholders, we follow an iterative methodology where we present issues and potential solutions to our stakeholders in turn. For ISPs, we survey 27 ISPs in Japan, followed by a workshop with representatives from government and 5 ISPs. Based on the findings from this, we conduct semi-structured interviews with 20 participants followed by a more quantitative survey with 328 participants. We review these results in a second workshop with representatives from government and 7 ISPs. The appreciation of challenges by each party has lead to findings that are supported by all stakeholders. Securing IoT devices is neither users' nor ISPs' priority. Individuals are keen on more interventions both from the government as part of regulation and from ISPs in terms of filtering malicious traffic. Participants are willing to pay for enhanced monitoring and filtering. While ISPs do want to help users, there appears to be a lack of effective technology to aid them. ISPs would like to see more public recognition for their efforts, but internally they struggle with executive buy-in and effective means to communicate with their customers. The majority of barriers and incentives are external to ISPs and individuals, demonstrating the complexity of keeping IoT secure and emphasizing the need for relevant stakeholders in the IoT ecosystem to work in tandem.
翻译:互联网服务提供商(ISPs)和互联网信息服务供应商(IoT)个人用户(IoT)在确保IoT方面发挥着至关重要的作用。然而,鼓励他们这样做是困难的。我们的研究调查了ISP和个人对IoT安全的态度、他们所面临的障碍以及他们保持IoT安全的激励因素,从日本收集证据。由于利益攸关方之间的复杂互动,我们采用了一种迭接方法,我们反过来向我们的利益攸关方提出问题和潜在解决方案。对于ISPs而言,我们调查了27个日本的ISP,随后与来自政府和5 ISP的代表举行了一次讲习班。根据调查结果,我们与20名参与者进行了半结构化的访谈,随后与328名参与者进行了更多的定量调查。我们在与政府代表和7 IoSP的代表举行的第二次讲习班上审查了这些结果,从日本收集了证据。由于每一方对挑战的理解,结果得到了所有利益攸关方的支持。确保IoT设备既不是用户,也不是ISP的优先事项。 个人希望政府采取更多的干预措施,而ISP在过滤恶意交易方面则需要更贴切。 参与者愿意向ISP用户支付更多的资金。