【24h】

Penetration Testing Framework for IoT

机译:物联网渗透测试框架

获取原文

摘要

In the Internet of Things (IoT) environment, objects are connected on a network to share data. However, most of the IoT devices are developed and deployed with poor security consideration. As a result, these devices become a target of attacks. A solution for ensuring the safety and security of a network system is Penetration testing. In this study, we propose a framework for automated and flexible penetration testing for IoT network. Most of the available penetration testing methods are experts based, that select tool and process manually. This kind of Pen-test is a costly, time-consuming and inefficient. Also, the existing automated penetration testing doesn't consider the interaction between system components; it works by testing each component of a system separately. Individual component testing can lead to a security gap that makes the Pen-test inefficient since many low severity vulnerabilities on different inter-connected components can lead the system to an insecure state. Moreover, in some cases testing the individual components can claim that the particular component is secure, but if these individual components are connected in one system, it makes this system insecure. Due to such shortages, our framework will test the End-to-End target system (i.e., end devices, wireless communication, the control unit, then communication to the cloud server, and finally communication from the cloud to end user through mobile app or webpage). The proposed framework will automatically gather the information of the target IoT network and then perform various kinds of penetration testing through the network. Then it will summarize the results of Pentest and gives the recommendations to secure the system.
机译:在物联网(IoT)环境中,对象被连接到网络上以共享数据。但是,大多数物联网设备的开发和部署都出于安全考虑。结果,这些设备成为攻击的目标。渗透测试是确保网络系统安全的一种解决方案。在这项研究中,我们提出了一个用于物联网网络的自动化和灵活渗透测试的框架。大多数可用的渗透测试方法都是基于专家的,它们是手动选择工具和过程的。这种笔测试是昂贵,费时且效率低下的。另外,现有的自动渗透测试未考虑系统组件之间的交互;它通过分别测试系统的每个组件来工作。单独的组件测试可能会导致安全漏洞,从而导致Pen-test效率低下,因为不同的相互连接的组件上的许多严重性较低的漏洞可能导致系统进入不安全状态。而且,在某些情况下,测试单个组件可以声称该特定组件是安全的,但是如果这些单个组件连接在一个系统中,则会使该系统不安全。由于这种短缺,我们的框架将测试端到端目标系统(即,终端设备,无线通信,控制单元,然后与云服务器进行通信,最后通过移动应用或网页)。拟议的框架将自动收集目标物联网网络的信息,然后通过网络执行各种渗透测试。然后,它将总结Pentest的结果并给出建议以保护系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号