Submitted:
30 June 2025
Posted:
16 July 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Literature Review
2.1. Classification of IoT-Based Attacks
2.1.1. Hardware Attacks
A. Fault Injection Attacks
B-Side Channel Attacks
2.1.2. Memory-Based Attacks
2.2. Vulnerability Assessment Frameworks for IoT
2.2.1. CVSS-Based Frameworks
- The Exploitability metrics reflect the ease of exploiting a certain vulnerability. This set of metrics incorporates 4 metrics, namely Attack Vector (AV), Attack Complexity (AC), Privileges Required (PR), User Interaction (UI), and Attack Requirements (AR).
- The impact metrics reflect the impact of exploiting a certain vulnerability. This set of metrics incorporates 6 metrics: Confidentiality, Integrity, Availability, Subsequent System Confidentiality (SC), Subsequent System Integrity (SI), Subsequent System Availability (SA).
2.2.2. Non-CVSS-Based Frameworks
3. COSMIC FSM Background
3.1. COSMIC FSM
3.1.1. Foundational Principles and Objectives
3.2. Foundational Principles and Objectives
3.2.1. Method Architecture and Phases
- Measurement Strategy Phase: This initial phase defines the purpose (e.g., effort estimation, benchmarking) and scope (e.g., single application, system component) of the measurement. It results in a Software Context Model that identifies the software boundary, its functional users (humans, devices, or other software), and its persistent storage components.
- Mapping Phase: In this phase, the Functional User Requirements (FURs) are mapped to COSMIC’s Generic Software Model. Each FUR is decomposed into one or more functional processes, each of which consists of a sequence of data movements (Entries, Exits, Reads, Writes). These data movements reflect the interaction between the software and its users or storage elements.
- Measurement Phase: Finally, each functional process is measured by summing its constituent data movements. The functional size of the software is the total number of data movements across all functional processes. Since each data movement corresponds to one CFP, the resulting size is additive and not limited by predefined categories or thresholds, allowing for precise granularity in complex systems.
3.2.2. Core Measurement Constructs
- a.
- A functional process consists of a set of data movements that represent an elementary component of the software’s functional user requirements (FUR). Each functional process is unique within the overall FUR and can be defined independently of other functional processes.
- b.
- Each functional process is triggered by a single Entry data movement. Processing begins when the functional process receives a data group through the triggering Entry.
- c.
- The complete set of data movements within a functional process includes all those necessary to fulfil its FUR, covering every possible response initiated by its triggering Entry.
- Entry represents the single, distinct flow of data from a functional user across a defined boundary into a functional process.
- Exit represents the single flow of a data group from a functional process across a boundary to a functional user.
- Read represents the movement of a single data group from persistent storage into a functional process.
- Write signifies the movement of a single data group from a functional process into persistent storage.
3.2.3. Domain Applicability and Automation
3.2.4. COSMIC for Treatment of Non-Functional Requirements’ Measurement
3.3. Application Domains of COSMIC FSM
3.3.1. COSMIC FSM in IoT
Mapping COSMIC Rules to IoT
- The study identifies the setup() and loop() functions in Arduino code as functional processes, each associated with a single triggering entry. The setup() function runs at system startup or reset, initializing input/output pins that interact with functional users, such as sensors and actuators in IoT systems. Once setup is complete, the loop() function executes continuously, enabling ongoing data exchange between the system and its functional users according to the specified functional requirements.
- Each function in the Arduino code that utilizes an INPUT pin is treated as a COSMIC Entry, while those involving an OUTPUT pin are categorized as COSMIC Exits. Function calls that retrieve data from EEPROM are identified as COSMIC Reads, and those that store data to EEPROM are considered COSMIC Writes. Each of these Entry, Exit, Read, or Write accounts for one Cosmic Functional Point (CFP).
3.3.2. COSMIC FSM in Computer Hardware
Mapping COSMIC Rules to Computer Hardware
- CPU represents the sole functional user
- Each function or subroutine represents a functional process
- Each source register or immediate value in a register represents an Entry
- Each destination register in an instruction represents an Exit (N.B.: same concept holds for Program Counter register (PC) updates due to jump or branch instructions as well, hence, the update of PC due to a jump or branch instruction accounts for 1 Exit )
- Return value after branch and link or jump and link instructions represents an Exit
- Each load instruction represents a Read
- Each store instruction represents a Store
3.3.3. Leveraging COSMIC for Memory Vulnerability Assessment in IoT Edge Systems
4. COSMIC Mapping for Memory-Related Vulnerabilities and Attacks
4.1. ESP Background
4.1.1. Memory Management for Function Calls in the Xtensa ISA

4.2. Proposed Methodology for COSMIC FSM Mapping
4.3. Measurement Example
4.3.1. Exploiting Buffer-Overflow Vulnerability on ESP8266




4.3.2. Measuring the Functional Size of the Attack

4.3.3. Board Security Level Inference Using COSMIC
5. The Prototype Tool Proposed
5.1. Tool Main Components
- Secure code that lacks any unsafe functions, resulting in “No Vulnerability”.
- Code including functions that result in non-null termination of strings, although these functions do not instantly exploit the buffer overflow vulnerability, the vulnerability might be exploited later; this category is assigned the value “Medium Vulnerability”.
- Code including unsafe functions that exploit the buffer overflow vulnerability, assuming the weak security of the board on which the code is deployed, this category is assigned the value “High Vulnerability”.
5.2. Tool Validation
5.2.1. Test Cases Scenarios
- A buffer overflow vulnerability resulted from the unsafe use of the “strcpy” function when the size of the source array exceeds that of the destination buffer.
- Absence of buffer overflow vulnerability when using the same “strcpy” function and validating the size of the source array.
- A buffer overflow vulnerability resulted from the unsafe use of the “strncpy” function when the number of characters to copy is greater than the size of the destination array.
- Absence of buffer overflow vulnerability when using the same “strncpy” function and validating the size of the source array, or when the number of bytes to copy is less than the size of the destination array.
- There is a potential buffer overflow vulnerability when using “strncpy”, and the size of the destination is equal to the number of characters copied; hence, the string is not NULL-terminated.
- The same scenarios were applied to the “memcopy” and “memove” functions.
- Absence of a buffer-overflow vulnerability due to the usage of safe functions such as “strlcpy” or “memcopy_s”, or memmove_s”.
- Code snippets that do not involve any string copying functions.
- “High Vulnerability” for the test cases that result in exploiting the buffer overflow vulnerability.
- “Medium Vulnerability” for the test cases that have a prospective buffer overflow vulnerability.
- “No vulnerability” when safe functions are used or proper input validation is performed. The same applies to code snippets that do not involve any string-copying functions.
5.2.2. Test Cases Output
- The vulnerable code snippet in Listing 2, which was used to exploit the buffer overflow vulnerability, was provided as input to the tool. The tool successfully identified the presence of the vulnerable strcpy() function as well as the line of code where this function was called. Furthermore, the vulnerability level was classified as high. Listing 7 illustrates the output of the tool after the vulnerable code was provided as input.Listing 7. Tool Output

- The same code snippet was provided as input to the tool, with the vulnerable strcpy() function replaced by the safer strlcpy() function. The tool successfully reported ’No Vulnerability’ in this case.
-
The following code snippet, which results in a prospective vulnerability, was fed into the tool, and the tool successfully output “Medium Vulnerability”. Listing 8 shows the vulnerable code snippet fed to the tool.The tool correctly identified the vulnerability alongside the line of code that induced the vulnerability. Listing 9 shows the tool output.Upon replacing the strncpy(dst, src, sizeof(dst)) with strncpy(dst, src, sizeof(dst)-1) and placing NULL in dst[4], the tool has successfully detected “No Vulnerability” as shown in Listing 10.Listing 8. Vulnerable code snippet
Listing 9. Tool output
Listing 10. Updated Output.
- A simple code snippet that prints the word “Hello World” on the serial monitor was fed to the tool. The tool has successfully detected “No Vulnerability” since the code lacks any functions involving the copying of Strings. Listing 11 shows the output of the tool.Listing 11. Tool Output.

6. Discussion
7. Conclusions
Author Contributions
Funding
Acknowledgments
Conflicts of Interest
Abbreviations
| IoT | Internet of Things |
| IIoT | Industrial IoT |
| DoS | Denial of Service |
| DDoS | Distributed Denial of Service |
| CVSS | Common Vulnerability Scoring System |
| COSMIC | Common Software Measurement International Consortium |
| FSM | Functional Size Measurement |
| CFP | COSMIC Function Points |
| ISA | Instruction Set Architecture |
| RPL | Routing Protocol for Low-Power and Lossy Networks |
| MQTT | Message Queuing Telemetry Transport |
| APT | Advanced Persistent Threat |
| IC | Integrated Circuit |
| TRNG | True Random Number Generator |
| OTP | One-Time Programmable |
| SE | Secure Element |
| TEE | Trusted Execution Environment |
| EM | Electromagnetic |
| DFA | Differential Fault Analysis |
| PC | Program Counter |
| SPA | Simple Power Analysis |
| DPA | Differential Power Analysis |
| CPU | Central Processing Unit |
| ROP | Return-Oriented Programming |
| OTA | Over-The-Air |
| AV | Attack Vector |
| AC | Attack Complexity |
| PR | Privileges Required |
| UI | User Interaction |
| AR | Attack Requirements |
| SC | Subsequent System Confidentiality |
| SI | Subsequent System Integrity |
| SA | Subsequent System Availability |
| NIST | National Institute of Standards and Technology |
| CVE | Common Vulnerabilities and Exposures |
| SVM | Support Vector Machine |
| SOA | Service-Oriented Architectures |
| FUR | Functional User Requirement |
| ECU | Electronic Control Unit |
| NFR | Non-Functional Requirements |
| NLP | Natural Language Processing |
References
- Tyagi, N.; Bhushan, B. Demystifying the Role of Natural Language Processing (NLP) in Smart City Applications: Background, Motivation, Recent Advances, and Future Research Directions. Wireless Pers. Commun. 2023, 130, 857–908. [Google Scholar] [CrossRef] [PubMed]
- Ali, A.-e.A.; Mashhour, M.; Salama, A.S.; Shoitan, R.; Shaban, H. Development of an Intelligent Personal Assistant System Based on IoT for People with Disabilities. Sustainability 2023, 15, 5166. [Google Scholar] [CrossRef]
- Alshdadi, A.A. Cyber-physical system with IoT-based smart vehicles. Soft Comput. 2021, 25, 12261–12273. [Google Scholar] [CrossRef]
- Calderón, D.; Folgado, F.J.; González, I.; Calderón, A.J. Implementation and Experimental Application of Industrial IoT Architecture Using Automation and IoT Hardware/Software. Sensors 2024, 24, 8074. [Google Scholar] [CrossRef]
- Surantha, N.; Atmaja, P.; David, M.; Wicaksono, M. A Review of Wearable Internet-of-Things Device for Healthcare. Procedia Comput. Sci. 2021, 179, 936–943. [Google Scholar] [CrossRef]
- Dell Technologies. Internet of Things and Data Placement. 2024. Available online: https://infohub.delltechnologies.com/en-us/l/edge-to-core-and-the-internet-of-things-2/internet-of-things-and-data-placement/ (accessed on 11 June 2025).
- Rehman, S.; Manickam, S.; Firdous, N. Impact of DoS/DDoS Attacks in IoT Environment: A Study. In AIP Conference Proceedings, 2023, 020020. [Google Scholar] [CrossRef]
- Caballero-Gil, C.; Álvarez, R.; Hernández-Goya, C.; Pérez, D. Research on Smart-Lock Cybersecurity and Vulnerabilities. Wirel. Netw. 2024, 30, 5905–5917. [Google Scholar] [CrossRef]
- Cloudflare. Mirai Botnet. Available online: https://www.cloudflare.com/en-gb/learning/ddos/glossary/mirai-botnet/ (accessed on 11 June 2025).
- NHS Digital. Cyber Alert—CC-2557. 2018. Available online: https://digital.nhs.uk/cyber-alerts/2018/cc-2557 (accessed on 11 June 2025).
- Bellay, J.; Forte, D.; Martin, R.; Taylor, C. Hardware Vulnerability Description, Sharing and Reporting: Challenges and Opportunities. GOMACTech, 2020. Available online: https://par.nsf.gov/biblio/10237521 (accessed on 20 June 2025).
- National Vulnerability Database (NVD). CVSS Metrics. Available online: https://nvd.nist.gov/vuln-metrics/cvss (accessed on 11 June 2025).
- Anand, P.; Singh, Y.; Selwal, A.; Singh, P.K.; Ghafoor, K.Z. ivqfiot: An Intelligent Vulnerability Quantification Framework for Scoring Internet of Things Vulnerabilities. Expert Syst. 2021, 39, e12829. [Google Scholar] [CrossRef]
- Massaro, V.G.; Capacci, L.; Montanari, R. Towards Context-Aware Risk Assessment Scoring System for IoT/IIoT Devices. In Proceedings of the ITASEC; 2023. [Google Scholar]
- Ur-Rehman, A.; Gondal, I.; Kamruzzaman, J.; Jolfaei, A. Vulnerability Modelling for Hybrid IT Systems. In Proceedings of the 2019 IEEE International Conference on Industrial Technology (ICIT); 2019. [Google Scholar] [CrossRef]
- COSMIC. Functional Size Measurement—Method Overview. Available online: https://cosmic-sizing.org/ (accessed on 11 June 2025).
- Salem, S.; Soubra, H. Functional Size Measurement Automation for IoT Edge Devices. In Proceedings of the IWSM-Mensura 2024; CEUR Workshop Proceedings, Volume 3543; CEUR-WS.org: Aachen, Germany; paper 13. Available online: https: //ceur-ws.org/Vol-/paper13.pdf (accessed on 11 June 2025), 2024. Available online: https://ceur-ws.org/Vol-3543/paper13.pdf (accessed on 11 June 2025).
- Salem, S.; Soubra, H. Using NLP for Functional Size Measurement of IoT Devices. In *Proceedings of the 2023 Eleventh International Conference on Intelligent Computing and Information Systems (ICICIS)*, Cairo, Egypt, ; pp. 321–327. 16–18 December. [CrossRef]
- Soubra, H.; Jacot, L.; Lemaire, S. Manual and Automated Functional Size Measurement of an Aerospace Realtime Embedded System: A Case Study Based on SCADE and on COSMIC ISO 19761. 2015.
- Soubra, H.; Abran, A.; Sehit, M. Functional Size Measurement for Processor Load Estimation in AUTOSAR. In Lecture Notes in Business Information Processing; Springer: Cham, Switzerland, 2015; Volume 230, pp. 1–16. [Google Scholar]
- Soubra, H.; Abufrikha, Y.; Abran, A. Towards Universal COSMIC Size Measurement Automation. In Proceedings of the IWSM-Mensura; 2020. [Google Scholar]
- Darwish, A.; Soubra, H. COSMIC Functional Size of ARM Assembly Programs. In Proceedings of the IWSM-Mensura; 2020. [Google Scholar]
- Krishna, R.R.; Priyadarshini, A.; Jha, A.V.; Appasani, B.; Srinivasulu, A.; Bizon, N. State-of-the-Art Review on IoT Threats and Attacks: Taxonomy, Challenges and Solutions. Sustainability 2021, 13, 9463. [Google Scholar] [CrossRef]
- Mishra, J.; Sahay, S. Modern Hardware Security: A Review of Attacks and Countermeasures. 2025. Available online: https://arxiv.org/abs/2501.04394 (accessed on 11 June 2025).
- Zhu, W.T.; Zhou, J.; Deng, R.H.; Bao, F. Detecting Node Replication Attacks in Wireless Sensor Networks: A Survey. J. Netw. Comput. Appl. 2012, 35, 1022–1034. [Google Scholar] [CrossRef]
- Makhdoom, I.; Abolhasan, M.; Lipman, J.; Liu, R.P.; Ni, W. Anatomy of Threats to the Internet of Things. IEEE Commun. Surv. Tutor. 2018, 21, 1636–1675. [Google Scholar] [CrossRef]
- Khanam, S.; Ahmedy, I.B.; Idris, M.Y.I.; Jaward, M.H.; Sabri, A.Q.B.M. A Survey of Security Challenges, Attacks Taxonomy and Advanced Countermeasures in the Internet of Things. IEEE Access 2020, 8, 219709–219743. [Google Scholar] [CrossRef]
- Mauro, C.; Pallavi, K.; Rabbani, M.M.; Ranise, S. Attestation-Enabled Secure and Scalable Routing Protocol for IoT Networks. Ad Hoc Netw. 2020, 98, 102054. [Google Scholar]
- OWASP. Session Hijacking Attack. Available online: https://owasp.org/www-community/attacks/Session_hijacking_attack (accessed on 11 June 2025).
- IBM. SYN Flood Attack Detection and Prevention. Available online: https://www.ibm.com/support/pages/syn-flood-attack-detection-and-prevention (accessed on 11 June 2025).
- Roldán-Gómez, J.; Carrillo-Mondéjar, J.; Castelo Gómez, J.M.; Ruiz-Villafranca, S. Security Analysis of the MQTT-SN Protocol for the Internet of Things. Appl. Sci. 2022, 12, 10991. [Google Scholar] [CrossRef]
- Jayasinghe, K.; Poravi, G. A Survey of Attack Instances of Cryptojacking Targeting Cloud Infrastructure. In Proceedings of the 2020 2nd Asia Pacific Information Technology Conference (APIT ’20), ACM, New York, NY, USA; 2020; pp. 100–107. [Google Scholar] [CrossRef]
- Rocha, B.; Melo, L.; de Sousa Junior, R. A Study on APT in IoT Networks. In Proceedings of the 2021 International Conference on Security and Cryptography (SECRYPT); pp. 160–164. [CrossRef]
- Rehman, I.U. Facebook-Cambridge Analytica Data Harvesting: What You Need to Know. Library Philosophy and Practice (e-journal), 2019, 249.
- Noman, H.A.; Abu-Sharkh, O.M.F. Code Injection Attacks in Wireless-Based Internet of Things (IoT): A Comprehensive Review and Practical Implementations. Sensors 2023, 23, 6067. [Google Scholar] [CrossRef]
- Wang, D.; Zhang, X.; Ming, J.; Chen, T.; Wang, C.; Niu, W. Resetting Your Password Is Vulnerable: A Security Study of Common SMS-Based Authentication in IoT Devices. Wirel. Commun. Mob. Comput. 2018, 2018, 7849065. [Google Scholar] [CrossRef]
- Sasi, T.; Lashkari, A.H.; Lu, R.; Xiong, P.; Iqbal, S. A Comprehensive Survey on IoT Attacks: Taxonomy, Detection Mechanisms and Challenges. J. Inf. Intell. 2024, 2, 455–513. [Google Scholar] [CrossRef]
- Sengupta, J.; Ruj, S.; Das Bit, S. A Comprehensive Survey on Attacks, Security Issues and Blockchain Solutions for IoT and IIoT. J. Netw. Comput. Appl. 2020, 149, 102481. [Google Scholar] [CrossRef]
- Shah, Y.; Sengupta, S. A Survey on Classification of Cyber-Attacks on IoT and IIoT Devices. In Proceedings of the 2020 11th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON), New York, NY, USA; 2020; pp. 406–413. [Google Scholar]
- Victor, P.; Lashkari, A.H.; Lu, R.; Sasi, T.; Xiong, P.; Iqbal, S. IoT Malware: An Attribute-Based Taxonomy, Detection Mechanisms and Challenges. Peer-to-Peer Netw. Appl. 2023, 16, 1380–1431. [Google Scholar] [CrossRef]
- OWASP. Buffer Overflow Attack. Available online: https://owasp.org/www-community/attacks/Buffer_overflow_attack (accessed on 11 June 2025).
- IBM. What is Encryption? Available online: https://www.ibm.com/think/topics/encryption (accessed on 11 June 2025).
- OWASP. Cryptanalysis. Available online: https://owasp.org/www-community/attacks/Cryptanalysis (accessed on 11 June 2025).
- Ling, Z.; Luo, J.; Xu, Y.; Gao, C.; Wu, K.; Fu, X. Security Vulnerabilities of Internet of Things: A Case Study of the Smart Plug System. IEEE Internet Things J. 2017, 4, 1899–1909. [Google Scholar] [CrossRef]
- Cirne, A.; Sousa, P.R.; Resende, J.S.; Antunes, L. Hardware Security for Internet of Things Identity Assurance. IEEE Commun. Surv. Tutor. 2024, 26, 1041–1079. [Google Scholar] [CrossRef]
- Rekoff, M.G. On Reverse Engineering. IEEE Trans. Syst. Man Cybern. 1985, SMC-15, 244–252.
- Torrance, R.; James, D. The State-of-the-Art in IC Reverse Engineering. In *Cryptographic Hardware and Embedded Systems—CHES 2009*; Clavier, C., Gaj, K., Eds.; Springer: Berlin/Heidelberg, Germany, 2009; pp. 363–381. [Google Scholar]
- Boneh, D.; DeMillo, R.A.; Lipton, R.J. On the Importance of Checking Cryptographic Protocols for Faults. In *Proceedings of the 1997 International Conference on the Theory and Applications of Cryptographic Techniques*; Springer: Berlin/Heidelberg, Germany, 1997; pp. 37–51. [Google Scholar]
- Biham, E.; Shamir, A. Differential Fault Analysis of Secret Key Cryptosystems. In *Advances in Cryptology—CRYPTO’97*; Koblitz, N., Ed.; Springer: Berlin/Heidelberg, Germany, 1997; Volume 1294, pp. 513–525. [Google Scholar]
- Yarom, Y.; Falkner, K. Flush+Reload: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. *IACR Cryptol. ePrint Arch.* 2014, 2013, 448. [Google Scholar]
- Bernstein, D.J. Cache-Timing Attacks on AES. *University of Illinois at Chicago*, 2005. Available online: https://cr.yp.to/antiforgery/cachetiming-20050414.pdf (accessed on 11 June 2025).
- Kocher, P.; Horn, J.; Fogh, A.; Genkin, D.; Gruss, D.; Haas, W.; Hamburg, M.; Lipp, M.; Mangard, S.; Prescher, T.; Schwarz, M.; Yarom, Y. Spectre Attacks: Exploiting Speculative Execution. *Commun. ACM* 2020, 63, 93–101. [Google Scholar] [CrossRef]
- Delvaux, J.; Mune, C.; Romero, M.; Timmers, N. Breaking Espressif ESP32 V3: Program Counter Control with Computed Values Using Fault Injection. In *Proceedings of the 18th USENIX Workshop on Offensive Technologies (WOOT ’24)*; USENIX Association: Boston, MA, USA, 2024. [Google Scholar]
- Courk. ESP32-C3/C6 Fault Injection. 2024. Available online: https://courk.cc/esp32-c3-c6-fault-injection (accessed on 11 June 2025).
- Kocher, P.; Jaffe, J.; Jun, B. Differential Power Analysis. In *Advances in Cryptology – CRYPTO’99*; Wiener, M., Ed.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1999; Volume 1666, pp. 388–397. [Google Scholar]
- Dhem, J.F.; Koeune, F.; Leroux, P.A.; Mestre, P.; Quisquater, J.J.; Willems, J.L. A.; Mestre, P.; Quisquater, J.J.; Willems, J.L. A Practical Implementation of the Timing Attack. In *Smart Card Research and Advanced Applications*; Gollmann, D., Ed.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1998; Quisquater, J.J.; pp. 167–182. [Google Scholar]
- Bernstein, D.J. Cache-Timing Attacks on AES; University of Illinois at Chicago: Chicago, IL, USA, 2005; Available online: https://cr.yp.to/antiforgery/cachetiming-20050414.pdf (accessed on 11 June 2025).
- Ronen, E.; Shamir, A.; Weingarten, A.O.; O’Flynn, C. IoT Goes Nuclear: Creating a ZigBee Chain Reaction. In *Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP)*, San Jose, CA, USA, 22–26 May 2017; IEEE: Piscataway, NJ, USA, 2017; pp. 195–212. [Google Scholar]
- Van Bulck, J.; Piessens, F.; Strackx, R. Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt Logic. In *Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS ’18)*; ACM: New York, NY, USA, 2018; pp. 178–195. [Google Scholar] [CrossRef]
- Salehi, M.; De Borger, G.; Hughes, D.; Crispo, B. NemesisGuard: Mitigating Interrupt Latency Side Channel Attacks with Static Binary Rewriting. *Computer Networks* **2022**, *205*, 108744. [CrossRef]
- Watts, K.; Oman, P. Stack-Based Buffer Overflows in Harvard Class Embedded Systems. In *Critical Infrastructure Protection III*; Palmer, C., Shenoi, S., Eds.; IFIP Advances in Information and Communication Technology; Springer: Berlin, Heidelberg, 2009; Volume 311, pp. 187–200. [Google Scholar] [CrossRef]
- Lehniger, K.; Aftowicz, M.; Langendoerfer, P.; Dyka, Z. Challenges of Return-Oriented-Programming on the Xtensa Hardware Architecture. 2022; arXiv:2201.06785. [Google Scholar] [CrossRef]
- Lehniger, K.; Langendörfer, P. Through the Window: Exploitation and Countermeasures of the ESP32 Register Window Overflow. *Future Internet* **2023**, *15*, 217. [CrossRef]
- Lehniger, K.; Saad, A.; Langendoerfer, P. Finding Gadgets in Incremental Code Updates for Return-Oriented Programming Attacks on Resource-Constrained Devices. *Ann. Telecommun.* **2022**, *78*. [CrossRef]
- Sarker, A.; Islam, M.K.; Tian, Y.; Fox, G. MVAM: Multi-Variant Attacks on Memory for IoT Trust Computing. In *Proceedings of the 2023 ACM International Conference*; ACM: New York, NY, USA, 2023; pp. 13–18. [Google Scholar] [CrossRef]
- NIST. Measuring the Common Vulnerability Scoring System Base Score Equation: NIST IR 8409. National Institute of Standards and Technology, 2021. Available online. [CrossRef]
- Ur-Rehman, A.; Gondal, I.; Kamruzzaman, J.; Jolfaei, A. Vulnerability Modelling for Hybrid Industrial Control System Networks. *J. Grid Comput.* **2020**, *18*, 10.1007/s10723-020-09528-w. [CrossRef]
- Blinowski, G.; Piotrowski, P. CVE-Based Classification of Vulnerable IoT Systems. arXiv arXiv:2006.16640, 2020. [CrossRef]
- Abdalmagid, A.; Shukry, S.; Soubra, H. Towards Universal Metrics for Hardware Cybersecurity Assessment. In *Proceedings of the 2023 Eleventh International Conference on Intelligent Computing and Information Systems (ICICIS)*, Cairo, Egypt, ; pp. 225–232. 16–18 December. [CrossRef]
- Rostami, M.; Koushanfar, F.; Karri, R. A Primer on Hardware Security: Models, Methods, and Metrics. *Proc. IEEE* **2014**, *102*, 1283–1295. [CrossRef]
- ISO 19761:2011; Software Engineering—COSMIC: A Functional Size Measurement Method. ISO: Geneva, Switzerland, 2011.
- International Function Point Users Group (IFPUG). Available online: https://ifpug.org/ (accessed on 11 June 2025).
- Early Function Point Analysis. Available online: https://nesma.org/freedocs/early-function-point-analysis/ (accessed on 11 June 2025).
- Lind, K.; Heldal, R. A Model-Based and Automated Approach to Size Estimation of Embedded Software Components. In: Whittle, J.; Clark, T.; Kühne, T. (Eds.) Model Driven Engineering Languages and Systems. MODELS 2011; Lecture Notes in Computer Science, vol. 6981; Springer, Berlin, Heidelberg, 2011; pp. 356–370.
- Oriou, A.; Bronca, E.; Bouzid, B.; Guetta, O.; Guillard, K. Manage the Automotive Embedded Software Development Cost & Productivity with the Automation of a Functional Size Measurement Method (COSMIC). In Proceedings of the 2014 Joint Conference of the International Workshop on Software Measurement and the International Conference on Software Process and Product Measurement, Rotterdam, Netherlands; 2014; pp. 1–4. [Google Scholar] [CrossRef]
- Desharnais, J.M.; Buglione, L.; Kocatürk, B. Using the COSMIC method to estimate Agile user stories. *ACM Int. Conf. Proc. Ser. 2011. [Google Scholar] [CrossRef]
- Trudel, S.; Buglione, L. Guideline for Sizing Agile Projects with COSMIC. *COSMIC* **2010**.
- Soubra, H.; Elsayed, H.; Elbrolosy, Y.; Adel, Y.; Attia, Z. Comprehensive Review of Metrics and Measurements of Quantum Systems. *Preprints* **2025**, 10.20944/preprints202504.0503.v1.
- Khattab, K.; Elsayed, H.; Soubra, H. Functional Size Measurement of Quantum Computers Software. In Proceedings of the 31st IWSM-Mensura, Izmir, Turkey; 2022. [Google Scholar]
- Elbrolosy, Y.; Adel, Y.; Attia, Z.; Elsayed, H.; Soubra, H. Quantum Software Functional Size Measurement Approaches based on COSMIC ISO 19761. 2024. [Google Scholar] [CrossRef]
- Abran, A.; Al-Sarayreh, K.; Lesterhuis, A. (Eds.) *Non-Functional Requirements and COSMIC Sizing: Practitioner’s Guide (Minor Update)*; COSMIC – Common Software Measurement International Consortium: 20. 20 December.
- Soubra, H.; Abran, A. Functional Size Measurement for the Internet of Things (IoT): An Example Using COSMIC and the Arduino Open-Source Platform. In *Proceedings of the 27th International Workshop on Software Measurement and 12th International Conference on Software Process and Product Measurement*, Gothenburg, Sweden, 25–27 October.
- Arduino. Arduino Language Reference. Available online: https://www.arduino.cc/reference/tr/ (accessed on 11 June 2025).
- Abdullah, S.; Salem, S.; Ghantous, M.; Soubra, H. COSMIC-REC: A Recursive COSMIC Functional Size Measurement Tool for Arduino IoT Edge Devices. In *Advances in Software Engineering, Education, and e-Learning*; Springer: Cham, Switzerland, 2025; pp. 384–397. [Google Scholar] [CrossRef]
- Bishay, M.; Salem, S.; Ghantous, M.; Soubra, H. CosmiCode: Automated COSMIC Measurement Tool for Arduino Using RegEx and NLP. In *Advances in Software Engineering, Education, and e-Learning*; Springer: Cham, Switzerland, 2025; pp. 301–315. [Google Scholar] [CrossRef]
- Moulla, D.K.; Kitikil, A.; Mnkandla, E.; Soubra, H.; Abran, A. Functional Size Measurement for X86 Assembly Programs. Proceedings of a Conference (Title Not Specified), November 2023. [Google Scholar]
- Cadence. Instruction Set Architecture (ISA) Summary; Cadence: San Jose, CA, USA, 2013; Available online: https://www.cadence.com/content/dam/cadence-www/global/en_US/documents/tools/silicon-solutions/compute-ip/isa-summary.pdf (accessed on 11 June 2025).



| Study Reviewed | IoT Relevance | CVSS-based | HW vulnerability metrics proposal | Memory-related attack coverage | Practical application of the proposed assessment |
|---|---|---|---|---|---|
| [13] | • | • | |||
| [14] | • | • | • | ||
| [15] | • | • | • | ||
| [68] | • | ||||
| [69] | • | • | • | ||
| [70] | • | • |
| Data group movement | Mapping to COSMIC |
|---|---|
| digitalRead(); | Entry |
| digitalWrite(); | Exit |
| EEPROM.read(); | Read |
| EEPROM.write(); | Write |
| Instruction | Entry | Exit | Read | Write |
|---|---|---|---|---|
| l32r a3, 4020101c <core_version+0x4> | 1 | 1 | 1 | |
| l32r a2, 40201020 <core_version+0x8> | 1 | 1 | 1 | |
| l32r a9, 40201024 <core_version+0xc> | 1 | 1 | 1 | |
| jx a9 | 1 | 1 | ||
| bany a7, a13, 40201036 <_Z1hv+0xe> | 3 | 1 | ||
| l32i.n a2, a0 | 2 | 1 | 1 | |
| Total | 9 | 6 | 4 |
| Code snippet Listing Number | Source Code Classification | Tool Output |
|---|---|---|
| 2 | Use of unsafe functions without proper input validation | “High Vulnerability” |
| 10-11 | Use of safe functions, or input validation applied to unsafe functions | “No Vulnerability” |
| 8 | The destination buffer lacks a null terminator | “Medium Vulnerability” |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).