Towards Threat Modelling of IoT Context-Sharing Platforms

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Goudarzi, Mohammad, Shaghaghi, Arash, Finn, Simon, Stiller, Burkhard, Jha, Sanjay
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911999240175616
author Goudarzi, Mohammad
Shaghaghi, Arash
Finn, Simon
Stiller, Burkhard
Jha, Sanjay
author_facet Goudarzi, Mohammad
Shaghaghi, Arash
Finn, Simon
Stiller, Burkhard
Jha, Sanjay
contents The Internet of Things (IoT) involves complex, interconnected systems and devices that depend on context-sharing platforms for interoperability and information exchange. These platforms are, therefore, critical components of real-world IoT deployments, making their security essential to ensure the resilience and reliability of these 'systems of systems'. In this paper, we take the first steps toward systematically and comprehensively addressing the security of IoT context-sharing platforms. We propose a framework for threat modelling and security analysis of a generic IoT context-sharing solution, employing the MITRE ATT&CK framework. Through an evaluation of various industry-funded projects and academic research, we identify significant security challenges in the design of IoT context-sharing platforms. Our threat modelling provides an in-depth analysis of the techniques and sub-techniques adversaries may use to exploit these systems, offering valuable insights for future research aimed at developing resilient solutions. Additionally, we have developed an open-source threat analysis tool that incorporates our detailed threat modelling, which can be used to evaluate and enhance the security of existing context-sharing platforms.
format Preprint
id arxiv_https___arxiv_org_abs_2408_12081
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Towards Threat Modelling of IoT Context-Sharing Platforms
Goudarzi, Mohammad
Shaghaghi, Arash
Finn, Simon
Stiller, Burkhard
Jha, Sanjay
Cryptography and Security
The Internet of Things (IoT) involves complex, interconnected systems and devices that depend on context-sharing platforms for interoperability and information exchange. These platforms are, therefore, critical components of real-world IoT deployments, making their security essential to ensure the resilience and reliability of these 'systems of systems'. In this paper, we take the first steps toward systematically and comprehensively addressing the security of IoT context-sharing platforms. We propose a framework for threat modelling and security analysis of a generic IoT context-sharing solution, employing the MITRE ATT&CK framework. Through an evaluation of various industry-funded projects and academic research, we identify significant security challenges in the design of IoT context-sharing platforms. Our threat modelling provides an in-depth analysis of the techniques and sub-techniques adversaries may use to exploit these systems, offering valuable insights for future research aimed at developing resilient solutions. Additionally, we have developed an open-source threat analysis tool that incorporates our detailed threat modelling, which can be used to evaluate and enhance the security of existing context-sharing platforms.
title Towards Threat Modelling of IoT Context-Sharing Platforms
topic Cryptography and Security
url https://arxiv.org/abs/2408.12081