Skip to content
CS-801 · Internet of Things/Quick Revision Short Notes

Internet of Things (CS-801) - Unit 5 Short Notes

How unit 5 is examined

This unit covers IoT hardware platforms (Arduino, Raspberry Pi), analytics, cloud, security and the smart home; the marks sit in Attacks and security concerns, Data Analytics, then Cloud, Vulnerabilities and Smart Home.

IoT Platforms

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. An IoT platform is the hardware or software base on which IoT applications are built, connecting devices, collecting their data, processing it and giving users control.

Key points.

  1. Hardware platforms such as Arduino, Raspberry Pi and ESP8266 are the boards that host sensors and actuators.
  2. Software or cloud platforms such as ThingSpeak, IBM Watson IoT, AWS IoT and Azure IoT provide device management, data storage, analytics and dashboards.
  3. A platform hides low-level details, so the developer only writes application logic.
  4. Choose a platform by processing need, power budget, connectivity, cost and community support.

<mark>An IoT platform is the middleware that links devices, network and applications, and provides device management, data processing and visualisation.</mark>

Asked: [? marks] (Dec 2024) Explain any two: (i) Smart Home (ii) Raspberry Pi (iii) IoT platforms

Arduino

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. Arduino is an open-source microcontroller board (for example ATmega328P on the Uno) programmed in C/C++ through the Arduino IDE, used for simple sensing and control.

Key points.

  1. It has no operating system; one program (a sketch with setup() and loop()) runs directly on the chip.
  2. The Uno gives 14 digital pins, 6 analog inputs, a 16 MHz clock, 32 KB flash and 2 KB SRAM.
  3. It is cheap, low power and gives real-time, deterministic control of sensors and motors.
  4. Wi-Fi or Ethernet needs an extra shield or module because the base board has no networking.
Basis Arduino Raspberry Pi
Architecture Microcontroller (CPU, RAM, flash on one chip) Microprocessor SoC (ARM CPU with separate RAM, SD card)
Processing 8-bit, 16 MHz, KB of memory 32/64-bit, GHz quad-core, GB of RAM
OS None, single sketch Full Linux (Raspberry Pi OS)
GPIO and I/O Digital and analog pins (built-in ADC) Digital GPIO only (no ADC), plus USB, HDMI, Ethernet
Power Very low (mA), battery friendly Higher (about 2.5 A supply)
IoT use Sensor node: temperature, soil, relay control Gateway, edge server, camera, web server

Answer frame. Open with one line defining both boards; draw the table above; add one example each (Arduino soil-moisture node, Pi home gateway); close with "Arduino for simple real-time sensing, Pi for computing-heavy IoT".

Asked: [7 marks] (May 2026) Differentiate between Arduino and Raspberry Pi on the basis of architecture, processing capability and IoT applications.

Raspberry Pi Board

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. Raspberry Pi is a credit-card-sized single-board computer that runs Linux and exposes GPIO pins for connecting sensors and actuators.

Key points.

  1. Pi 3 has a 1.2 GHz quad-core 64-bit ARM Cortex-A53, 1 GB RAM, on-board Wi-Fi and Bluetooth, 4 USB ports, HDMI, Ethernet and a 40-pin GPIO header.
  2. Unlike a desktop it boots from an SD card, has an ARM SoC instead of an x86 CPU, draws about 5 V 2.5 A, and costs a few thousand rupees.
  3. A desktop is a general-purpose machine with upgradeable parts, a hard disk and high performance; the Pi is a low-power embedded board meant for projects and IoT gateways.
  4. GPIO pins are programmable general-purpose pins that read sensors (input) or drive LEDs and relays (output).
  5. SPI is a fast 4-wire serial bus (MOSI, MISO, SCLK, CS) with one master and many slaves, used for ADCs (MCP3008), displays and SD-type devices.
  6. I2C is a 2-wire bus (SDA, SCL) where each device has an address; it connects many low-speed sensors such as RTC and temperature chips.

Asked: [7 marks] (May 2022) How Raspberry Pi 3 is different from a desktop computer? Write the use of SPI, I2C interfaces and GPIO pins of Raspberry Pi 3.

Other IoT Platforms

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Other platforms include ESP8266/ESP32, BeagleBone, Intel Galileo and cloud platforms like ThingSpeak.

Key points.

  1. ESP8266 is a low-cost Wi-Fi microcontroller with built-in TCP/IP, programmable like an Arduino, ideal for Wi-Fi sensor nodes.
  2. BeagleBone Black is a Linux board like the Pi with more real-time I/O.
  3. ThingSpeak stores sensor data through a REST API and plots it with MATLAB analytics.

Data Analytics for IoT

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>

Definition. IoT analytics is the process of examining the large volume of data generated by connected things to extract insight for decisions and automated actions.

Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-01" viewBox="0 0 492.8 80" width="492.8" height="80" role="img" aria-label="Analytics pipeline. T things (sensors), G gateway, C cloud storage, P processing and analytics, I insight and action"><style>#dsfig-u5-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-01 .t{fill:#16181D;font-weight:500}#dsfig-u5-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-01 .dot{fill:#16181D}#dsfig-u5-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-01 .ah{fill:#454C5A}#dsfig-u5-01 .ah.hi{fill:#2340B8}#dsfig-u5-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-01 .e{stroke:#B1B7C3}html.dark #dsfig-u5-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-01 .t{fill:#E6E8ED}html.dark #dsfig-u5-01 .t.inv{fill:#0F1115}html.dark #dsfig-u5-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-01 .dot{fill:#E6E8ED}html.dark #dsfig-u5-01 .ann{fill:#8FA3FF}html.dark #dsfig-u5-01 .lbl{fill:#858D9C}html.dark #dsfig-u5-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-01 .ah{fill:#B1B7C3}html.dark #dsfig-u5-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah16" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh16" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,40 L122.2,40" marker-end="url(#ah16)"/><path class="e" d="M162.2,40 L225.4,40" marker-end="url(#ah16)"/><path class="e" d="M265.4,40 L328.6,40" marker-end="url(#ah16)"/><path class="e" d="M368.6,40 L431.8,40" marker-end="url(#ah16)"/><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">T</text><circle class="n" cx="143.2" cy="40" r="18"/><text class="t" x="143.2" y="40" dy=".35em" text-anchor="middle">G</text><circle class="n" cx="246.4" cy="40" r="18"/><text class="t" x="246.4" y="40" dy=".35em" text-anchor="middle">C</text><circle class="n" cx="349.6" cy="40" r="18"/><text class="t" x="349.6" y="40" dy=".35em" text-anchor="middle">P</text><circle class="n" cx="452.8" cy="40" r="18"/><text class="t" x="452.8" y="40" dy=".35em" text-anchor="middle">I</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Analytics pipeline. T things (sensors), G gateway, C cloud storage, P processing and analytics, I insight and action</figcaption></figure>

Key points.

  1. Things sense the environment, actuate on commands and generate the raw data; without them there is nothing to analyse.
  2. The Internet connects things to the gateway and cloud, transports data, and integrates it with storage, analytics and applications.
  3. The pipeline runs collection, transmission, storage, processing and visualisation, ending in insight or action.
  4. Descriptive analytics tells what happened, using summaries and dashboards.
  5. Predictive analytics tells what will happen, using machine learning, for example predictive maintenance and forecasting.
  6. Prescriptive analytics tells what to do, for example an optimised schedule or an automatic valve command.
  7. Analytics can be real time (stream, at the edge) or historical (batch, in the cloud); IoT data is big, fast and varied.
  8. Use cases: anomaly detection in factories, smart-meter demand forecasting, patient monitoring, and traffic control.

Example. A smart-farm soil sensor (thing) sends moisture over Wi-Fi (Internet) to the cloud, where analytics predicts dryness and switches the pump on.

Answer frame. Open with the definition; draw the pipeline; develop points 1-3, then the three analytics types, then use cases; close with "analytics turns raw IoT data into decisions". For the things-and-Internet question, give points 1-2 first, then the example.

<mark>IoT analytics converts the raw data from things, carried over the Internet, into descriptive, predictive and prescriptive insight.</mark>

Asked: [7 marks] (May 2023, May 2024, Dec 2024) Discuss the role of Data Analytics in Internet of Things (IoT). Asked: [7 marks] (May 2024) What is IoT Analytics? What is the role of things and Internet in IoT?

Cloud for IoT

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. Cloud computing gives IoT applications on-demand, scalable storage, computing and services over the Internet, on a pay-per-use basis.

Key points.

  1. The cloud offloads storage and heavy processing from constrained devices.
  2. It scales automatically as the number of devices and the data volume grow.
  3. It gives remote access, device management and analytics anywhere.
  4. Service models differ in how much the provider manages.
Model What is provided User manages Example
IaaS Virtual machines, storage, network OS, middleware, apps AWS EC2, Azure VMs
PaaS Platform to build and deploy apps Only the application and data Google App Engine, AWS IoT Core, Heroku
SaaS Ready-to-use software Nothing, only use it Gmail, ThingSpeak dashboards, Salesforce
  1. Deployment can be public, private or hybrid cloud.
  2. Difficult cloud-IoT integration, as an answer: a device fleet with mixed protocols was connected by an MQTT broker (interoperability), edge filtering cut latency and bandwidth, TLS with per-device certificates solved security, and autoscaling handled load; the lesson is to design for scale and security from the start.

Answer frame. For service models: define the cloud, draw the layered IaaS-PaaS-SaaS stack or the table, one example each, close with the comparison of control. For the experience question: state the scenario, the issues (scalability, interoperability, latency, security), the fixes and the outcome.

Asked: [7 marks] (May 2023) Describe different Cloud Service Models. Asked: [7 marks] (Jun 2025) Give an example of a particularly difficult cloud IoT integration you have worked on and how you overcame it.

Cloud storage models & communication APIs

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. Cloud storage holds IoT data in remote servers; communication APIs are the interfaces devices and applications use to exchange data with the cloud.

Key points.

  1. Cloud helps IoT through scalability, large storage and processing, remote management, and reduced load on edge devices.
  2. Storage models are object storage (files, images), block storage (VM disks), file storage and database storage (SQL, NoSQL time series).
  3. REST API uses HTTP GET, POST, PUT, DELETE on resources and is simple, stateless and widely used.
  4. MQTT is a lightweight publish-subscribe protocol for constrained devices; CoAP is a light UDP-based REST-like protocol.
  5. Providers include Amazon AWS IoT, Google Cloud IoT and Microsoft Azure IoT, which also give analytics, ML and visualisation.

Asked: [? marks] (Dec 2024) How cloud useful for IoT? Explain cloud communication APIs.

Attacks in IoT system

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>

Definition. An IoT attack is any attempt to steal, alter or block IoT data, or to take control of devices, networks or services; security means keeping confidentiality, integrity and availability (CIA).

Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-02" viewBox="0 0 1057 194" width="1057" height="194" role="img" aria-label="Attacks classified by layer"><style>#dsfig-u5-02 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-02 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-02 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-02 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-02 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-02 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-02 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-02 .t{fill:#16181D;font-weight:500}#dsfig-u5-02 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-02 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-02 .dot{fill:#16181D}#dsfig-u5-02 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-02 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-02 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-02 .ah{fill:#454C5A}#dsfig-u5-02 .ah.hi{fill:#2340B8}#dsfig-u5-02 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-02 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-02 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-02 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-02 .e{stroke:#B1B7C3}html.dark #dsfig-u5-02 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-02 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-02 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-02 .t{fill:#E6E8ED}html.dark #dsfig-u5-02 .t.inv{fill:#0F1115}html.dark #dsfig-u5-02 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-02 .dot{fill:#E6E8ED}html.dark #dsfig-u5-02 .ann{fill:#8FA3FF}html.dark #dsfig-u5-02 .lbl{fill:#858D9C}html.dark #dsfig-u5-02 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-02 .ah{fill:#B1B7C3}html.dark #dsfig-u5-02 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-02 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-02 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-02 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah17" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh17" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><line class="e" x1="536.1" y1="37" x2="183.8" y2="101"/><line class="e" x1="536.1" y1="37" x2="542" y2="101"/><line class="e" x1="536.1" y1="37" x2="888.5" y2="101"/><line class="e" x1="183.8" y1="101" x2="59.5" y2="165"/><line class="e" x1="183.8" y1="101" x2="178" y2="165"/><line class="e" x1="183.8" y1="101" x2="308" y2="165"/><line class="e" x1="542" y1="101" x2="407" y2="165"/><line class="e" x1="542" y1="101" x2="475" y2="165"/><line class="e" x1="542" y1="101" x2="558.5" y2="165"/><line class="e" x1="542" y1="101" x2="677" y2="165"/><line class="e" x1="888.5" y1="101" x2="791.5" y2="165"/><line class="e" x1="888.5" y1="101" x2="890.5" y2="165"/><line class="e" x1="888.5" y1="101" x2="985.5" y2="165"/><rect class="n" x="483.1" y="22" width="106" height="30" rx="8"/><text class="t" x="536.1" y="37" dy=".35em" text-anchor="middle">IoT attacks</text><rect class="n" x="142.3" y="86" width="83" height="30" rx="8"/><text class="t" x="183.8" y="101" dy=".35em" text-anchor="middle">Physical</text><rect class="n" x="14" y="150" width="91" height="30" rx="8"/><text class="t" x="59.5" y="165" dy=".35em" text-anchor="middle">Tampering</text><rect class="n" x="121" y="150" width="114" height="30" rx="8"/><text class="t" x="178" y="165" dy=".35em" text-anchor="middle">Side channel</text><rect class="n" x="251" y="150" width="114" height="30" rx="8"/><text class="t" x="308" y="165" dy=".35em" text-anchor="middle">Node capture</text><rect class="n" x="504.5" y="86" width="75" height="30" rx="8"/><text class="t" x="542" y="101" dy=".35em" text-anchor="middle">Network</text><rect class="n" x="381" y="150" width="52" height="30" rx="8"/><text class="t" x="407" y="165" dy=".35em" text-anchor="middle">DDoS</text><rect class="n" x="449" y="150" width="52" height="30" rx="8"/><text class="t" x="475" y="165" dy=".35em" text-anchor="middle">MITM</text><rect class="n" x="517" y="150" width="83" height="30" rx="8"/><text class="t" x="558.5" y="165" dy=".35em" text-anchor="middle">Spoofing</text><rect class="n" x="616" y="150" width="122" height="30" rx="8"/><text class="t" x="677" y="165" dy=".35em" text-anchor="middle">Eavesdropping</text><rect class="n" x="835.5" y="86" width="106" height="30" rx="8"/><text class="t" x="888.5" y="101" dy=".35em" text-anchor="middle">Application</text><rect class="n" x="754" y="150" width="75" height="30" rx="8"/><text class="t" x="791.5" y="165" dy=".35em" text-anchor="middle">Malware</text><rect class="n" x="845" y="150" width="91" height="30" rx="8"/><text class="t" x="890.5" y="165" dy=".35em" text-anchor="middle">Injection</text><rect class="n" x="952" y="150" width="67" height="30" rx="8"/><text class="t" x="985.5" y="165" dy=".35em" text-anchor="middle">Botnet</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Attacks classified by layer</figcaption></figure>

Key points.

  1. Why security is needed: devices are constrained in CPU, memory and battery, so heavy encryption is hard; they are deployed at huge scale; they hold private data; and a compromised device can cause physical harm.
  2. Device (physical) layer attacks include tampering, node capture, side-channel attacks (power or timing analysis) and firmware extraction.
  3. Network layer attacks include eavesdropping, man-in-the-middle, spoofing (fake identity), replay, and DDoS that floods a target with traffic.
  4. Application layer attacks include malware, botnets (Mirai infected cameras to launch DDoS), SQL injection and data theft.
  5. Privacy loss, weak authentication, data tampering and loss of availability are the main issues.
  6. Heterogeneity and lack of standards make one common defence hard.
  7. Countermeasures: strong unique passwords, encryption (AES, TLS/DTLS), authentication and access control, secure boot, signed firmware updates, network segmentation and firewalls.
  8. Security monitoring (IDS, logs, anomaly detection) detects threats early, and prevention (patching, rate limiting) stops them.
  9. Security models: layered security, end-to-end encryption, and cloud-centric trust with certificates.

Answer frame. Open with the CIA definition and why IoT is weak; draw the layered attack tree; develop points 2-4 layer by layer with one example each, then countermeasures; close with "defence must be layered and continuous". For security concerns, stress issues (point 5) and challenges (point 6) before mitigation.

Pitfall: Listing attack names without stating the layer or a countermeasure loses marks.

<mark>IoT attacks fall into physical, network and application layers, and each needs its own layered defence.</mark>

Asked: [7 marks] (May 2022, May 2024, Jun 2025) Explain various security concerns related to IoT. Discuss in detail. Why security is required in IoT? Explain the security models. Asked: [7 marks] (May 2023, Dec 2024, May 2026) Explain different types of attacks in IoT systems. Discuss the security in IoT; explain the role of security monitoring and threat prevention.

Vulnerability analysis in IoT

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. A vulnerability is a weakness in a device, protocol or software that an attacker can exploit; vulnerability analysis finds and rates these weaknesses before attackers do.

Key points.

  1. Observed vulnerabilities are weak or default passwords, insecure web, mobile or cloud interfaces, and lack of secure updates.
  2. Others are unencrypted data in transit or at rest, insecure network services, poor physical protection, and insecure default settings.
  3. Application/service layer flaws include weak authentication, missing input validation and insecure APIs.
  4. Attacks that exploit them are SQL or command injection, cross-site scripting (XSS), DoS, malware and data theft.
  5. Security protects data and devices (CIA); privacy controls who may collect and use personal data.
  6. Privacy risks include data leakage, location and habit tracking, and profiling from sensor data.
  7. Mitigation: change default credentials, validate input, use HTTPS and OAuth tokens, encrypt data, update firmware, minimise data collected and get consent.

Answer frame. List vulnerability types first, then the application-layer attacks with how each exploits a flaw; close with countermeasures. For security and privacy, define both, then authentication, confidentiality and tracking issues, then mitigation.

Asked: [7 marks] (May 2022, May 2024) Which kinds of vulnerability have been observed in IoT? Which attacks can exploit the vulnerabilities in Application/Service layer? Asked: [7 marks] (May 2023) Discuss security and privacy issues in IoT systems.

IoT case studies: Smart Home

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. A smart home is a home whose lights, appliances, climate and security are connected to sensors and a controller, so they are monitored and controlled automatically or remotely.

Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-03" viewBox="0 0 424 295" width="424" height="295" role="img" aria-label="Smart home. S temperature and light sensors, M motion or PIR sensor, Pi Raspberry Pi controller, R relay board to lights and fan, A alarm buzzer, C cloud and mobile app"><style>#dsfig-u5-03 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-03 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-03 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-03 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-03 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-03 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-03 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-03 .t{fill:#16181D;font-weight:500}#dsfig-u5-03 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-03 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-03 .dot{fill:#16181D}#dsfig-u5-03 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-03 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-03 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-03 .ah{fill:#454C5A}#dsfig-u5-03 .ah.hi{fill:#2340B8}#dsfig-u5-03 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-03 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-03 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-03 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-03 .e{stroke:#B1B7C3}html.dark #dsfig-u5-03 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-03 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-03 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-03 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-03 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-03 .t{fill:#E6E8ED}html.dark #dsfig-u5-03 .t.inv{fill:#0F1115}html.dark #dsfig-u5-03 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-03 .dot{fill:#E6E8ED}html.dark #dsfig-u5-03 .ann{fill:#8FA3FF}html.dark #dsfig-u5-03 .lbl{fill:#858D9C}html.dark #dsfig-u5-03 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-03 .ah{fill:#B1B7C3}html.dark #dsfig-u5-03 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-03 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-03 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-03 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah18" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh18" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M57.6,47.1 L192.5,101" marker-end="url(#ah18)"/><path class="e" d="M57.9,162.7 L192.2,115.7" marker-end="url(#ah18)"/><path class="e" d="M229.6,101.7 L364.5,47.8" marker-end="url(#ah18)"/><path class="e" d="M229.9,115.1 L364.2,162.1" marker-end="url(#ah18)"/><path class="e" d="M212,129.8 L212,234" marker-end="url(#ah18)" marker-start="url(#ah18)"/><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">S</text><circle class="n" cx="40" cy="169" r="18"/><text class="t" x="40" y="169" dy=".35em" text-anchor="middle">M</text><circle class="n" cx="212" cy="108.8" r="18"/><text class="t" x="212" y="108.8" dy=".35em" text-anchor="middle">Pi</text><circle class="n" cx="384" cy="40" r="18"/><text class="t" x="384" y="40" dy=".35em" text-anchor="middle">R</text><circle class="n" cx="384" cy="169" r="18"/><text class="t" x="384" y="169" dy=".35em" text-anchor="middle">A</text><circle class="n" cx="212" cy="255" r="18"/><text class="t" x="212" y="255" dy=".35em" text-anchor="middle">C</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Smart home. S temperature and light sensors, M motion or PIR sensor, Pi Raspberry Pi controller, R relay board to lights and fan, A alarm buzzer, C cloud and mobile app</figcaption></figure>

Key points.

  1. Sensors (temperature, LDR light, PIR motion, gas) feed the Raspberry Pi through its GPIO pins.
  2. The Pi runs the control logic in Python and drives relays that switch lamps, fans and appliances.
  3. Wi-Fi links the Pi to the cloud and a mobile app for remote monitoring and control (MQTT or HTTP).
  4. Applications: lighting control, HVAC (thermostat), security (cameras, door locks, alarms), and energy management.
  5. Control flow: sensor reads, Pi compares with a threshold, the relay switches, and the status goes to the app.
  6. Benefits are comfort, energy savings, safety and remote access; examples are the Nest thermostat and smart locks.

Answer frame. Open with the definition; draw the diagram; list components then applications; explain the control flow in three lines; close with benefits. For "any one case study", use this smart home: problem (manual, wasteful control), architecture, devices, protocols, data flow, outcome.

Asked: [7 marks] (May 2022, Jun 2025) Explain the applications of IoT in home automation systems. Construct the design of a smart home with Raspberry Pi and other hardware devices with a neat sketch. Asked: [7 marks] (May 2023) Discuss any one case study of IoT in detail.

Smart farming etc.

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Smart farming uses IoT sensors, drones and analytics to monitor crops, soil and livestock, so that farming inputs are used precisely.

Key points.

  1. Soil moisture, temperature and humidity sensors send data to a cloud platform.
  2. Analytics decides irrigation, and actuators switch pumps automatically.
  3. It saves water, raises yield and reduces labour and cost.
  4. Other case studies are smart city, smart health and smart grid.

Last-minute revision

  • IoT platform: middleware for device management, data processing and applications.
  • Arduino: microcontroller, no OS, 16 MHz Uno; Raspberry Pi: SoC computer with Linux, GHz-class.
  • Pi 3: 1.2 GHz quad-core Cortex-A53, 1 GB RAM, 40-pin GPIO, Wi-Fi and Bluetooth.
  • SPI: 4 wires (MOSI, MISO, SCLK, CS); I2C: 2 wires (SDA, SCL) with addresses.
  • Analytics types: descriptive (what happened), predictive (what will), prescriptive (what to do).
  • Pipeline: collect, transmit, store, process, visualise, act.
  • IaaS gives infrastructure, PaaS a platform, SaaS software.
  • Cloud APIs: REST (HTTP), MQTT (pub-sub), CoAP (UDP).
  • Attacks by layer: physical (tampering, side channel), network (DDoS, MITM, spoofing), application (malware, injection).
  • Security is CIA; privacy is control over personal data.
  • Smart home: sensors, Pi, relays, Wi-Fi, cloud app.

Memory hooks

  • "ARM vs AVR": Arduino has no OS; Pi runs Linux.
  • I2C has two wires, SPI has four.
  • I-P-S: IaaS infrastructure, PaaS platform, SaaS software.
  • D-P-P: Describe, Predict, Prescribe.
  • Attack layers: Physical touch, Network tap, Application trick.

Coverage checklist

  • IoT Platforms: Q14.
  • Arduino: Q1.
  • Raspberry Pi Board: Q10.
  • Other IoT Platforms: unasked, covered.
  • Data Analytics for IoT: Q6, Q7.
  • Cloud for IoT: Q4, Q5.
  • Cloud storage models & communication APIs: Q13.
  • Attacks in IoT system: Q2, Q3.
  • vulnerability analysis in IoT: Q11, Q12.
  • IoT case studies: Smart Home: Q8, Q9.
  • Smart framing etc.: unasked, covered.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in