Analysis of vulnerability databases for wireless networks in the Internet of Things for threat modelling
DOI:
https://doi.org/10.65890/dmp-lncse.ICICCS26.190Keywords:
IoT security, CVE database, NVD database, ICS Advisories, vulnerability analysis, threat modelling in IoT systemsAbstract
The development of technologies such as digitalisation, the Internet of Things (IoT), cloud computing, big data, and communication networks has led to the emergence of “smart” cities. The number of IoT devices connected to urban infrastructure is steadily increasing, increasing exposure to potential cyberattacks. Therefore, analysing vulnerabilities in IoT devices used in smart city infrastructure remains a key research challenge. This study compares three widely used vulnerability sources for IoT systems-CVE, NVD, and ICS Advisories-using criteria such as data structure, machine readability, product identification, and risk metrics. The advantages and limitations of existing databases are identified in terms of their applicability for threat modelling. We propose a structured integration approach that combines CVE, NVD, and ICS Advisories into a unified dataset. In addition, a generalised schema for describing vulnerabilities of IoT devices is developed, taking into account their type and application context. The results enable the construction of a unified vulnerability dataset suitable for threat modelling and risk assessment in smart city environments.
Downloads
Published
Conference Proceedings Volume
Section
License
Copyright (c) 2026 DMPedia Lecture Notes in Computer Science & Engineering

This work is licensed under a Creative Commons Attribution 4.0 International License.