首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >On the Security and Data Integrity of Low-Cost Sensor Networks for Air Quality Monitoring
【2h】

On the Security and Data Integrity of Low-Cost Sensor Networks for Air Quality Monitoring

机译:用于空气质量监测的低成本传感器网络的安全性和数据完整性

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The emerging connected, low-cost, and easy-to-use air quality monitoring systems have enabled a paradigm shift in the field of air pollution monitoring. These systems are increasingly being used by local government and non-profit organizations to inform the public, and to support decision making related to air quality. However, data integrity and system security are rarely considered during the design and deployment of such monitoring systems, and such ignorance leaves tremendous room for undesired and damaging cyber intrusions. The collected measurement data, if polluted, could misinform the public and mislead policy makers. In this paper, we demonstrate such issues by using a.com, a popular low-cost air quality monitoring system that provides an affordable and continuous air quality monitoring capability to broad communities. To protect the air quality monitoring network under this investigation, we denote the company of interest as a.com. Through a series of probing, we are able to identify multiple security vulnerabilities in the system, including unencrypted message communication, incompetent authentication mechanisms, and lack of data integrity verification. By exploiting these vulnerabilities, we have the ability of “impersonating” any victim sensor in the a.com system and polluting its data using fabricated data. To the best of our knowledge, this is the first security analysis of low-cost and connected air quality monitoring systems. Our results highlight the urgent need in improving the security and data integrity design in these systems.
机译:新兴的互联,低成本且易于使用的空气质量监测系统已使空气污染监测领域发生了范式转变。地方政府和非营利组织越来越多地使用这些系统来通知公众,并支持与空气质量有关的决策。但是,在此类监视系统的设计和部署过程中,很少考虑数据完整性和系统安全性,而这种无知为不希望的和破坏性的网络入侵留下了巨大的空间。所收集的测量数据如果受到污染,可能会误导公众并误导决策者。在本文中,我们通过使用a.com来演示此类问题,a.com是一种流行的低成本空气质量监测系统,可为广大社区提供负担得起的连续空气质量监测功能。为了保护此次调查中的空气质量监测网络,我们将感兴趣的公司表示为a.com。通过一系列的探查,我们能够识别系统中的多个安全漏洞,包括未加密的消息通信,不称职的身份验证机制和缺乏数据完整性验证。通过利用这些漏洞,我们能够“模拟” a.com系统中的任何受害者传感器,并使用虚构数据污染其数据。据我们所知,这是低成本和互联空气质量监测系统的首次安全分析。我们的结果表明,迫切需要改进这些系统的安全性和数据完整性设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号