{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:42:02Z","timestamp":1785512522555,"version":"3.56.0"},"reference-count":40,"publisher":"MDPI AG","issue":"13","license":[{"start":{"date-parts":[[2021,6,25]],"date-time":"2021-06-25T00:00:00Z","timestamp":1624579200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100013294","name":"Connecting Europe Facility","doi-asserted-by":"publisher","award":["TENtec n. 28263632"],"award-info":[{"award-number":["TENtec n. 28263632"]}],"id":[{"id":"10.13039\/100013294","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Minister of Science and Higher Education","award":["contract No. 5095 \/ CEF \/ 2020\/2"],"award-info":[{"award-number":["contract No. 5095 \/ CEF \/ 2020\/2"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The security of the Internet of Things (IoT) is a very important aspect of everyday life for people and industries, as well as hospitals, military, households and cities. Unfortunately, this topic is still too little researched and developed, which results in exposing users of Internet of Things to possible threats. One of the areas which should be addressed is the creation of a database of information about vulnerabilities and exploits in the Internet of Things; therefore, the goal of our activities under the VARIoT (Vulnerability and Attack Repository for IoT) project is to develop such a database and make it publicly available. The article presents the results of our research aimed at building this database, i.e., how the information about vulnerabilities is obtained, standardized, aggregated and correlated as well as the way of enhancing and selecting IoT related data. We have obtained and proved that existing databases provide various scopes of information and because of that a single and most comprehensive source of information does not exist. In addition, various sources present information about a vulnerability at different times\u2014some of them are faster than others, and the differences in publication dates are significant. The results of our research show that aggregation of information from various sources can be very beneficial and has potential to enhance actionable value of information. We have also shown that introducing more sophisticated concepts, such as trust management and metainformation extraction based on artificial intelligence, could ensure a higher level of completeness of information as well as evaluate the usefulness and reliability of data.<\/jats:p>","DOI":"10.3390\/s21134359","type":"journal-article","created":{"date-parts":[[2021,6,25]],"date-time":"2021-06-25T11:07:40Z","timestamp":1624619260000},"page":"4359","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Automatic Actionable Information Processing and Trust Management towards Safer Internet of Things"],"prefix":"10.3390","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8965-6302","authenticated-orcid":false,"given":"Marek","family":"Janiszewski","sequence":"first","affiliation":[{"name":"Research and Academic Computer Network (NASK), Kolska 12, 01-045 Warsaw, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3813-4840","authenticated-orcid":false,"given":"Anna","family":"Felkner","sequence":"additional","affiliation":[{"name":"Research and Academic Computer Network (NASK), Kolska 12, 01-045 Warsaw, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0964-6812","authenticated-orcid":false,"given":"Piotr","family":"Lewandowski","sequence":"additional","affiliation":[{"name":"Research and Academic Computer Network (NASK), Kolska 12, 01-045 Warsaw, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8590-8565","authenticated-orcid":false,"given":"Marcin","family":"Rytel","sequence":"additional","affiliation":[{"name":"Research and Academic Computer Network (NASK), Kolska 12, 01-045 Warsaw, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8728-0065","authenticated-orcid":false,"given":"Hubert","family":"Romanowski","sequence":"additional","affiliation":[{"name":"Research and Academic Computer Network (NASK), Kolska 12, 01-045 Warsaw, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,6,25]]},"reference":[{"key":"ref_1","unstructured":"(2021, May 05). The Internet of Things. Available online: https:\/\/dictionary.cambridge.org\/dictionary\/english\/internet-of-things."},{"key":"ref_2","unstructured":"Lueth, K.L. (2021, May 05). State of the IoT 2020: 12 Billion IoT Connections, Surpassing Non-IoT for the First Time. Available online: https:\/\/iot-analytics.com\/state-of-the-iot-2020-12-billion-iot-connections-surpassing-non-iot-for-the-first-time\/."},{"key":"ref_3","unstructured":"(2021, May 19). Input to the Horizon Europe Programme 2021\u20132027. Priorities for the Definition of a Strategic Research and Innovation Agenda in Cybersecurity (2020). Available online: https:\/\/ecs-org.eu\/documents\/publications\/5fdc4c5deb6f9.pdf."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Felkner, A., Kadobayashi, Y., Janiszewski, M., Fantin, S., Ruiz, J.F., Kozakiewicz, A., and Blanc, G. (2021). Cybersecurity Research Analysis Report for Europe and Japan: Cybersecurity and Privacy Dialogue Between Europe and Japan, Springer International Publishing. Studies in Big Data.","DOI":"10.1007\/978-3-030-62312-8"},{"key":"ref_5","first-page":"5","article-title":"A Novel Approach to National-Level Cyber Risk Assessment Based on Vulnerability Management and Threat Intelligence","volume":"2","author":"Janiszewski","year":"2019","journal-title":"J. Telecommun. Inf. Technol."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"329","DOI":"10.1515\/eletel-2017-0044","article-title":"Trust and Risk Assessment Model of Popular Software Based on Known Vulnerabilities","volume":"63","author":"Janiszewski","year":"2017","journal-title":"Int. J. Electron. Telecommun."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Rytel, M., Felkner, A., and Janiszewski, M. (2020). Towards a Safer Internet of Things\u2014A Survey of IoT Vulnerability Data Sources. Sensors, 20.","DOI":"10.3390\/s20215969"},{"key":"ref_8","unstructured":"(2021, May 07). Packet Storm. Available online: https:\/\/packetstormsecurity.com\/."},{"key":"ref_9","unstructured":"(2021, May 07). Offensive Security\u2019s Exploit Database Archive. Available online: https:\/\/www.exploit-db.com\/."},{"key":"ref_10","unstructured":"(2021, May 12). National Vulnerability Database, Available online: https:\/\/nvd.nist.gov\/vuln\/search."},{"key":"ref_11","unstructured":"(2021, May 12). China National Vulnerability Database. Available online: https:\/\/www.cnvd.org.cn\/."},{"key":"ref_12","unstructured":"(2021, May 12). Chinese National Vulnerability Database of Information Security. Available online: http:\/\/www.cnnvd.org.cn\/."},{"key":"ref_13","unstructured":"(2021, May 12). ICS Vulnerability Database. Available online: http:\/\/ivd.winicssec.com\/."},{"key":"ref_14","unstructured":"(2021, May 12). SecutiryFocus Bugtraq Database. Available online: https:\/\/www.securityfocus.com\/bid\/."},{"key":"ref_15","unstructured":"(2021, May 12). Japan Vulnerabilities Notes Database. Available online: https:\/\/jvndb.jvn.jp\/en\/."},{"key":"ref_16","unstructured":"(2021, May 12). Carnegie Mellon University CERT Coordination Center. Available online: https:\/\/www.kb.cert.org\/vuls\/."},{"key":"ref_17","unstructured":"(2021, May 12). VUL-HUB Information Security Vulnerability Portal. Available online: http:\/\/www.cve.scap.org.cn\/."},{"key":"ref_18","unstructured":"(2021, May 12). Vulmon Vulnerability Search Engine. Available online: https:\/\/vulmon.com\/."},{"key":"ref_19","unstructured":"(2021, May 12). Zero Day Initiative. Available online: https:\/\/www.zerodayinitiative.com\/."},{"key":"ref_20","unstructured":"(2021, May 12). Zero Science Lab. Available online: https:\/\/www.zeroscience.mk\/en\/index.php."},{"key":"ref_21","unstructured":"(2021, May 07). Vulners\u2014Vulnerability Data Base. Available online: https:\/\/vulners.com\/."},{"key":"ref_22","unstructured":"Byers, B., and Owen, H. (2021, March 16). Automation Support for CVE Retrieval, Available online: https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/National-Vulnerability-Database\/documents\/web%20service%20documentation\/Automation%20Support%20for%20CVE%20Retrieval.pdf."},{"key":"ref_23","unstructured":"Richardson, L. (2021, May 07). Beautiful Soup. Available online: https:\/\/www.crummy.com\/software\/BeautifulSoup\/."},{"key":"ref_24","unstructured":"(2021, May 11). Selenium. Available online: https:\/\/www.selenium.dev\/."},{"key":"ref_25","unstructured":"(2021, May 11). Google Translate API. Available online: https:\/\/cloud.google.com\/translate\/docs\/reference\/rest\/."},{"key":"ref_26","unstructured":"Kusner, M., Sun, Y., Kolkin, N., and Weinberger, K. (2015, January 6\u201311). From Word Embeddings to Document Distances. Proceedings of the International Conference on Machine Learning, Lille, France."},{"key":"ref_27","unstructured":"\u0158eh\u016f\u0159ek, R., and Sojka, P. (2010, January 22). Software Framework for Topic Modelling with Large Corpora. Proceedings of the LREC 2010 Workshop on New Challenges for NLP Frameworks, Valletta, Malta."},{"key":"ref_28","unstructured":"Mikolov, T., Grave, E., Bojanowski, P., Puhrsch, C., and Joulin, A. (2017). Advances in Pre-Training Distributed Word Representations. arXiv."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Cheikes, B.A., Waltermire, D., and Scarfone, K. (2011). Common Platform Enumeration: Naming Specification Version 2.3, National Institute of Standards and Technology. Technical Report NIST IR 7695.","DOI":"10.6028\/NIST.IR.7695"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Franklin, J., Wergin, C., and Booth, H. (2014). CVSS Implementation Guidance, National Institute of Standards and Technology. Technical Report NIST IR 7946.","DOI":"10.6028\/NIST.IR.7946"},{"key":"ref_31","unstructured":"Maris, A., Kundu, A., Yoon, A., Manion, A., Lowenthal, B., Monroe, B., Wergin, C., Turner, C., Clark, C., and Rich, D. (2021, May 05). CVSS v3.1 Specification Document. Available online: https:\/\/www.first.org\/cvss\/v3.1\/specification-document."},{"key":"ref_32","unstructured":"(2021, May 07). Gensim\u2014Keywords for TextRank. Available online: https:\/\/radimrehurek.com\/gensim_3.8.3\/summarization\/keywords.html."},{"key":"ref_33","unstructured":"(2021, May 07). Gensim\u2014TextRank Summariser. Available online: https:\/\/radimrehurek.com\/gensim_3.8.3\/summarization\/summariser.html."},{"key":"ref_34","unstructured":"(2021, May 07). Training spaCy\u2019s Statistical Models \u00b7 spaCy Usage Documentation (Legacy). Available online: https:\/\/v2.spacy.io\/usage\/training."},{"key":"ref_35","unstructured":"(2021, May 07). Rule-Based Matching \u00b7 spaCy Usage Documentation (Legacy). Available online: https:\/\/v2.spacy.io\/usage\/rule-based-matching."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"411","DOI":"10.1515\/eletel-2017-0058","article-title":"Towards an Evaluation Model of Trust and Reputation Management Systems","volume":"63","author":"Janiszewski","year":"2017","journal-title":"Int. J. Electron. Telecommun."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Janiszewski, M. (2020, January 11\u201314). TRM-EAT\u2013A New Tool for Reliability Evaluation of Trust and Reputation Management Systems in Mobile Environments. Proceedings of the 2020 20th IEEE\/ACM International Symposium on Cluster, Cloud and Internet Computing (CCGRID), Melbourne, Australia.","DOI":"10.1109\/CCGrid49817.2020.00-18"},{"key":"ref_38","unstructured":"Moriuchi, P., and Ladd, B. (2018). China Altered Public Vulnerability Data to Conceal MSS Influence, Recorded Future. Technical Report CTA-2018-0309."},{"key":"ref_39","unstructured":"(2021, May 19). Vulnerability and Attack Repository for IoT Project. Available online: https:\/\/www.variot.eu."},{"key":"ref_40","unstructured":"(2021, May 21). Poland\u2019s Open Data Portal, Available online: https:\/\/dane.gov.pl\/en."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/13\/4359\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:24:17Z","timestamp":1760163857000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/13\/4359"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,25]]},"references-count":40,"journal-issue":{"issue":"13","published-online":{"date-parts":[[2021,7]]}},"alternative-id":["s21134359"],"URL":"https:\/\/doi.org\/10.3390\/s21134359","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,6,25]]}}}