Abstract
Public-source evidence is widely used to assess exposed IoT and IIoT systems, yet its survival across successive stages of non-intrusive inference is rarely measured. This study examines how far an observer confined to public data can follow an evidence chain from a reachable host toward vulnerability and adversary-technique interpretation without privileged access, exploitation, or direct target interaction. Using a fixed, non-representative population of 227 public hosts constructed from IoT-23 network traffic, we measured evidence survival from surface observability through service and product evidence, CPE acceptance, and CVE resolution. The reported figures describe this constructed population rather than internet-facing IoT systems at large. The largest loss came first: only 58 hosts were externally observable, making observability the dominant constraint within this setting. A second source mainly deepened evidence for already visible hosts rather than recovering the blind region. Severity and exploitation-likelihood evidence survived at the CVE level, but technique-level interpretation was not pursued beyond the predefined external-observer model. We conclude that, within this measurement setting, external evidence-to-risk inference is bounded chiefly by observability and that distinct evidence layers should be measured separately rather than merged into a single risk signal.
IPC Classification
Keywords
€ 4.00