首页> 外文会议>Asian Conference on Defence Technology >A Mobile Application for Security Assessment Towards the Internet of Thing Devices
【24h】

A Mobile Application for Security Assessment Towards the Internet of Thing Devices

机译:对某物互联网的安全评估移动应用程序

获取原文

摘要

The Internet of Things or IoT is one of the disruptive technologies which has been grown its attention rapidly. However, because of the neglect of security awareness of vendors and users, this technology is vulnerable to be leveraged as a cyber weapon by malicious attackers. Therefore, we develop an IoT security solution, called MASai, which encourages general users who are not expert in cybersecurity to perform penetration testing on their IoT devices so that they can be aware of these problems and gain security awareness. MASai is comprised of MASai application on Android phones, MASai box, and MASai server. MASai application allows users to execute penetration testing on targeted IoT devices and targeted mobile applications controlling the devices throughouta mobile interface. MASai application works along with MASai Box, a Raspberry Pi embedded with Kali Linux distribution, to find vulnerabilities of the targeted IoT devices. Several techniques such as information gathering, wireless attacks, and vulnerability scanning are integrated for the assessment. MASai server allows users to perform Android reverse engineering and static code analysis for the mobile application security assessment. All vulnerability assessments and penetration testing are based on OWASP Top 10 IoT Vulnerabilities and OWASP Mobile Top 10. By using MASai, we expect users to gain security awareness and can prevent the unexpected consequences of IoT technology.
机译:物联网物联网或互联网已迅速增长的关注颠覆性技术之一。然而,由于厂商和用户的安全意识的忽视,这种技术很容易被利用为恶意攻击者的网络武器。因此,我们开发了物联网的安全解决方案,叫马赛,鼓励谁不是在网络安全上的物联网设备进行渗透测试,使他们能够意识到这些问题,并增加安全意识的专家一般用户。马赛人是由Android手机应用马赛,马赛框,马赛服务器。马赛应用程序允许用户在有针对性的物联网设备和有针对性的移动应用控制throughouta移动界面的设备上执行渗透测试。马赛应用与马赛盒,一个树莓派嵌入卡利Linux发行版一起工作,找到目标物联网设备的安全漏洞。一些技术,如信息收集,无线攻击和漏洞扫描都集成了评估。马赛服务器允许用户执行的Android逆向工程和静态代码分析移动应用的安全评估。所有的脆弱性评估和渗透测试是基于OWASP十大物联网的漏洞和OWASP手机前10名。通过使用马赛,我们预计用户获得安全意识,并能防止物联网技术的意想不到的后果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号