首页> 外文期刊>Computer networks >Cyber-physical systems information gathering: A smart home case study
【24h】

Cyber-physical systems information gathering: A smart home case study

机译:网络物理系统信息收集:智能家居案例研究

获取原文
获取原文并翻译 | 示例

摘要

With the growth in the use of Cyber-Physical Systems, such as Internet of Things (IoT) devices, there is a corresponding increase in the potential attack footprint of personal and corporate users. In this paper, we explore the potential for exploiting information retrieved from two IoT devices which, seemingly, are unlikely to store substantial amounts of data. We specifically focus on prominent smart home devices for the purpose of obtaining compromising information. We undertake a collection and analysis process, constrained by the limitations placed upon three types of adversaries, namely: forensic passive, forensic active and real-time active. The former two adversaries aim to comply with the requirements of forensic soundness, whereas the real-time active adversary does not have these constraints and therefore more closely models a malicious real-world attacker. The findings show that a variety of device data is available to even the passive adversary, and this data can be used to determine the actions and/or presence of an individual at a given time based on their interactions with the IoT device. These interactions can be both user initiated (e.g. powering on or off a switch or light) and device initiated (e.g. background polling). (C) 2018 Elsevier B.V. All rights reserved.
机译:随着诸如物联网(IoT)设备之类的网络物理系统的使用不断增长,个人和企业用户的潜在攻击范围也相应增加。在本文中,我们探索了利用从两个物联网设备中检索的信息的潜力,这些物联网设备似乎不太可能存储大量数据。我们特别专注于杰出的智能家居设备,以获取破坏性信息。我们进行收集和分析过程,但受到三种类型对手的限制,即:取证被动,取证主动和实时主动。前两个对手旨在符合法证健全性的要求,而实时活动对手则没有这些限制,因此可以更紧密地模拟恶意的现实世界攻击者。研究结果表明,即使被动对手也可以使用各种设备数据,并且该数据可用于基于个体与IoT设备的交互来确定给定时间的个体行为和/或存在。这些交互既可以由用户启动(例如,打开或关闭开关或灯的电源),也可以由设备启动(例如,背景轮询)。 (C)2018 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号