CYBERSECURITY OF IoT DEVICES IN THE INTERNAL NETWORKS OF MILITARY UNITS AND ORGANIZATIONS

Authors

DOI:

https://doi.org/10.31435/ijitss.3(51).2026.6692

Keywords:

Internet of Things, IoT Device, Military Internal Network, Cybersecurity, Attack Surface, Zero Trust, Microsegmentation, Residual Risk

Abstract

The digital transformation of the defense sector has expanded the use of Internet of Things devices in the internal networks of military units and organizations. These devices include IP cameras, access-control systems, biometric equipment, smart displays, multifunction printers, conferencing systems, building-management systems, environmental sensors, and smart meters. They improve operational efficiency, monitoring, and automation, but they also enlarge the cyberattack surface because of weak credentials, outdated software, vendor-managed cloud services, automatic device-discovery protocols, limited logging, and long service lifecycles. In a military organization, the consequences extend beyond the loss of information confidentiality. A compromised device may disclose the location and layout of facilities, security routines, personnel movements, and logistics patterns; provide a foothold for lateral movement within the internal network; and ultimately disrupt mission continuity.

This study identifies the principal attack surfaces, threats, and vulnerabilities associated with IoT devices in military internal networks and develops a mission-oriented risk-assessment method and a security model based on zero-trust principles. The research comparatively examines Mongolian cybersecurity legislation and authoritative sources, including NIST CSF 2.0, NISTIR 8259A, NIST SP 800-213, NIST SP 800-207, NIST SP 800-82 Rev. 3, ETSI EN 303 645, and MITRE ATT&CK. The findings show that military IoT risk is not confined to technical vulnerabilities at the device level. It also arises from incomplete asset inventories, flat network architectures, uncontrolled vendor remote access, cloud dependency, and weak lifecycle governance. The study proposes a five-zone network architecture, evidence-based risk assessment, and integrated security measures covering the entire lifecycle from procurement to disposal.

References

Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J. A., Invernizzi, L., Kallitsis, M., Kumar, D., Lever, C., Ma, Z., Mason, J., Menscher, D., Seaman, C., Sullivan, N., Thomas, K., & Zhou, Y. (2017). Understanding the mirai botnet. 26th USENIX Security Symposium, 1093-1110. https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-antonakakis.pdf.

Cybersecurity and Infrastructure Security Agency, & National Security Agency. (2023). NSA and CISA red and blue teams share top ten cybersecurity misconfigurations. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a

Department of Defense Chief Information Officer. (2022). Department of Defense zero trust strategy. https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTStrategy.pdf

European Telecommunications Standards Institute. (2024). ETSI EN 303 645 V3.1.3: Cyber security for consumer Internet of Things: Baseline requirements. https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf

Fagan, M., Megas, K. N., Scarfone, K., & Smith, M. (2020). IoT device cybersecurity capability core baseline (NISTIR 8259A). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8259A

Fagan, M., Marron, J., Brady, K. G., Jr., Cuthill, B. B., Megas, K. N., & Herold, R. (2021). IoT device cybersecurity guidance for the federal government: Establishing IoT device cybersecurity requirements (NIST SP 800-213). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-213

Internet Engineering Task Force. (2013). Multicast DNS (RFC 6762). RFC Editor. https://doi.org/10.17487/RFC6762

Internet Engineering Task Force. (2014). The constrained application protocol CoAP (RFC 7252). RFC Editor. https://doi.org/10.17487/RFC7252

MITRE. (2026). MITRE ATT&CK knowledge base. https://attack.mitre.org/

State Great Khural of Mongolia. (2016). Law on State and Official Secrets [In Mongolian]. https://legalinfo.mn/mn/detail/12408

State Great Khural of Mongolia. (2021a). Law on Cybersecurity [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16390365491061

State Great Khural of Mongolia. (2021b). Law on the Protection of Personal Information [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16390288615991

Government of Mongolia. (2022). National Cybersecurity Strategy, Government Resolution No. 493 [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16532522791411

Government of Mongolia. (2023). General Procedure for Ensuring Cybersecurity, Government Resolution No. 224 [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16759862495731

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework 2.0. https://doi.org/10.6028/NIST.CSWP.29

OASIS Open. (2019). MQTT version 5.0. https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html

ONVIF. (2020). ONVIF core specification. https://www.onvif.org/specs/core/ONVIF-Core-Specification-v2006.pdf

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST SP 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

Stouffer, K., Pease, M., Tang, C., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A., & Thompson, M. (2023). Guide to operational technology security (NIST SP 800-82 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-82r3

Minister of Digital Development, Innovation and Communications, & Director General of the General Intelligence Agency. (2024). Procedure and methodology for cybersecurity risk assessment, Joint Orders Nos. A/30 and A/148 [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=17141973551921

Downloads

Published

2026-09-25

How to Cite

Erdenesuvd, U., Bayartogtokh, N., & Densmaa, B. (2026). CYBERSECURITY OF IoT DEVICES IN THE INTERNAL NETWORKS OF MILITARY UNITS AND ORGANIZATIONS. International Journal of Innovative Technologies in Social Science, 5(3(51). https://doi.org/10.31435/ijitss.3(51).2026.6692