首页> 外文会议>IEEE Conference on Communications and Network Security >IoTSAT: A formal framework for security analysis of the internet of things (IoT)
【24h】

IoTSAT: A formal framework for security analysis of the internet of things (IoT)

机译:IoTSAT:物联网(IoT)安全分析的正式框架

获取原文

摘要

The new attack surface being crafted by the huge influx of IoT devices is both formidable and unpredictable, as it introduces a rich set of unexplored attack techniques and unknown vulnerabilities. These new attack techniques are hard to perceive through traditional means, owing to concealed and cascaded inter-device, inter-system and device-environment dependencies. In this paper, we present IoTSAT, a formal framework for security analysis of IoT. IoTSAT formally models the generic behavior of IoT system of systems, based on device configurations, network topologies, user policies and IoT-specific attack surface. The model is then used to measure system's resilience against potential attacks and identify threat vectors and specific attack techniques, which can be used to achieve higher-level adversary's objectives. We evaluate IoTSAT over realistic IoT networks, which concludes that our approach is scalable and highly beneficial for uncovering complex attack vectors of IoT systems.
机译:物联网设备的大量涌入正在制造出新的攻击面,它既强大又不可预测,因为它引入了一系列丰富的未经探索的攻击技术和未知漏洞。由于隐藏的和级联的设备间,系统间和设备环境依赖性,这些新的攻击技术很难通过传统方式来感知。在本文中,我们介绍了IoTSAT,这是用于IoT安全分析的正式框架。 IoTSAT根据设备配置,网络拓扑,用户策略和特定于IoT的攻击面来正式建模系统IoT系统的一般行为。然后,该模型用于测量系统对潜在攻击的恢复力,并确定威胁向量和特定的攻击技术,这些技术可用于实现更高级别的对手的目标。我们通过现实的IoT网络评估IoTSAT,得出的结论是,我们的方法具有可扩展性,对于发现IoT系统的复杂攻击媒介非常有帮助。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号