咨询与建议

看过本文的还看了

相关文献

该作者的其他文献

文献详情 >Towards Threat Modelling of Io... 收藏
arXiv

Towards Threat Modelling of IoT Context-Sharing Platforms

作     者:Goudarzi, Mohammad Shaghaghi, Arash Finn, Simon Stiller, Burkhard Jha, Sanjay 

作者机构:School of Computer Science and Engineering UNSW Sydney Australia  Australia Communication Systems Group Department of Informatics University of Zurich Switzerland Cisco United States 

出 版 物:《arXiv》 (arXiv)

年 卷 期:2024年

核心收录:

主  题:Cloud platforms 

摘      要:The Internet of Things (IoT) involves complex, interconnected systems and devices that depend on context-sharing platforms for interoperability and information exchange. These platforms are, therefore, critical components of real-world IoT deployments, making their security essential to ensure the resilience and reliability of these systems of systems. In this paper, we take the first steps toward systematically and comprehensively addressing the security of IoT context-sharing platforms. We propose a framework for threat modelling and security analysis of a generic IoT context-sharing solution, employing the MITRE ATT&CK framework. Through an evaluation of various industry-funded projects and academic research, we identify significant security challenges in the design of IoT context-sharing platforms. Our threat modelling provides an in-depth analysis of the techniques and sub-techniques adversaries may use to exploit these systems, offering valuable insights for future research aimed at developing resilient solutions. Additionally, we have developed an open-source threat analysis tool that incorporates our detailed threat modelling, which can be used to evaluate and enhance the security of existing context-sharing platforms. Copyright © 2024, The Authors. All rights reserved.

读者评论 与其他读者分享你的观点

用户名:未登录
我的评分