首页> 外文会议>2017 IEEE Global Internet of Things Summit >Improving Internet of Things device certification with policy-based management
【24h】

Improving Internet of Things device certification with policy-based management

机译:通过基于策略的管理来改善物联网设备认证

获取原文
获取原文并翻译 | 示例

摘要

The fast growing rate of the IoT systems with strong pressure to put devices on the market as soon as possible makes these systems vulnerable targets for cyber criminals, as recently seen in the Mirai botnet Distributed Denial-of-Service (DDoS) attack. A way to mitigate these threats is to enforce a comprehensive security certification process of IoT devices based on common standards. In this paper, we present an approach to improve certification of IoT devices using a combination of model-based testing and policy-based management in order to detect post certification vulnerabilities and act on them by introducing runtime policy enforcement capabilities. More precisely, we address these attacks using policy enforcement in order to correct vulnerable IoT device behavior and protect users even if security and privacy were not properly addressed by the device manufactures. We describe the details of our approach and, focusing on authorization vulnerabilities, we present a case study for the oneM2M standard showing how our solution can be applied in practice.
机译:物联网系统的快速增长以及尽快将设备投放市场的强大压力,使这些系统成为网络罪犯的攻击目标,最近在Mirai僵尸网络分布式拒绝服务(DDoS)攻击中就可以看出。缓解这些威胁的一种方法是基于通用标准强制执行IoT设备的全面安全认证过程。在本文中,我们提出了一种结合基于模型的测试和基于策略的管理来改进IoT设备认证的方法,以便检测认证后的漏洞并通过引入运行时策略执行功能来对它们采取行动。更准确地说,即使设备制造商未正确解决安全性和隐私问题,我们也会通过策略实施来应对这些攻击,以纠正易受攻击的IoT设备行为并保护用户。我们描述了我们的方法的细节,并针对授权漏洞,我们针对oneM2M标准进行了案例研究,展示了如何在实践中应用我们的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号