To Örebro University

oru.seÖrebro universitets publikasjoner
Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Securing the Internet of Things with Security-by-Contract
Örebro universitet, Institutionen för naturvetenskap och teknik.ORCID-id: 0000-0001-9293-7711
2021 (engelsk)Doktoravhandling, med artikler (Annet vitenskapelig)
Abstract [en]

Smart homes, industry, healthcare, robotics; virtually every market has seen the uprising of Internet of Things (IoT) devices with different degrees and nuances. IoT devices embody different desirable characteristics, such as mobility, ubiquity, variety, and affordability. All combined, these features made so that IoT devices reached 35 billion units in the world. However, the sudden uprising of market demand put enormous pressure on manufacturers. The necessity of delivering to customers as many devices as possible, in the shortest time possible, leads manufacturers to overlook features that are not perceived critical by the users, such as resiliency to cyberattacks. This led to severe security issues. The prime example is Mirai, a malware that infected hundreds of thousands of IoT devices in 2016 and used them to strike lethal Distributed Denial of Service (DDoS) attacks.

In the first part of this thesis, we present the state of the art regarding IoT devices security resilience. In particular, we provide relevant examples of breaches, an analysis of the relationship between IoT and Cloud from a security point of view, and an example of an IoT device penetration test. Then, we focus on the usage of IoT devices in DDoS-enabled botnets and we provide an extensive study of DDoS-enabling malwares, discussing their evolution and their capabilities.

In the second part, we contextualise the gathered knowledge and we show that the highlighted problems stem from two main causes: insecure configurations and insufficient secure configurability.We also show that, to address these two issues, it is necessary to equip IoT devices with precise and formal descriptions of their behaviour. Therefore, we propose SC4IoT, a security framework for IoT devices that combines Security-by-Contract (SC) paradigm and Fog Computing paradigm. First, we provide a thorough breakdown of our proposal. We start from high-level lifecycles that describe how devices participate to SC4IoT. Then, we discuss the pillars that compose the framework (e.g., security contracts and security policies), together with their formal descriptions. Last, we provide precise algorithms for achieving security-policy matching capabilities, as well as routines for allowing the framework to deal with dynamic changes while maintaining consistency.

sted, utgiver, år, opplag, sider
Örebro: Örebro University , 2021. , s. 55
Serie
Örebro Studies in Technology, ISSN 1650-8580 ; 90
HSV kategori
Identifikatorer
URN: urn:nbn:se:oru:diva-88151ISBN: 978-91-7529-364-6 (tryckt)OAI: oai:DiVA.org:oru-88151DiVA, id: diva2:1511429
Disputas
2021-01-29, Örebro universitet, Långhuset, Hörsal L2 (and online (zoom)), Fakultetsgatan 1, Örebro, 13:00 (engelsk)
Opponent
Veileder
Tilgjengelig fra: 2020-12-18 Laget: 2020-12-18 Sist oppdatert: 2021-01-08bibliografisk kontrollert
Delarbeid
1. The Internet of Hackable Things
Åpne denne publikasjonen i ny fane eller vindu >>The Internet of Hackable Things
2018 (engelsk)Inngår i: Proceedings of 5th International Conference in Software Engineering for Defence Applications: SEDA 2016 / [ed] Ciancarini, P.; Litvinov, S.; Messina, A.; Sillitti, A.; Succi, G., Cham: Springer, 2018, s. 129-140Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

The Internet of Things makes possible to connect each everyday object to the Internet, making computing pervasive like never before. From a security and privacy perspective, this tsunami of connectivity represents a disaster, which makes each object remotely hackable. We claim that, in order to tackle this issue, we need to address a new challenge in security: education.

sted, utgiver, år, opplag, sider
Cham: Springer, 2018
Serie
Advances in Intelligent Systems and Computing (AISC), ISSN 2194-5357, E-ISSN 2194-5365 ; 717
HSV kategori
Identifikatorer
urn:nbn:se:oru:diva-64664 (URN)10.1007/978-3-319-70578-1_13 (DOI)000434086000013 ()2-s2.0-85041846777 (Scopus ID)978-3-319-70577-4 (ISBN)978-3-319-70578-1 (ISBN)
Konferanse
5th International Conference in Software Engineering for Defence Applications, Rome, Italy, May 10, 2016
Tilgjengelig fra: 2018-01-30 Laget: 2018-01-30 Sist oppdatert: 2021-01-07bibliografisk kontrollert
2. Cyber-Storms Come from Clouds: Security of Cloud Computing in the IoT Era
Åpne denne publikasjonen i ny fane eller vindu >>Cyber-Storms Come from Clouds: Security of Cloud Computing in the IoT Era
Vise andre…
2019 (engelsk)Inngår i: Future Internet, E-ISSN 1999-5903, Vol. 11, nr 6, artikkel-id 127Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

The Internet of Things (IoT) is rapidly changing our society to a world where every thing is connected to the Internet, making computing pervasive like never before. This tsunami of connectivity and data collection relies more and more on the Cloud, where data analytics and intelligence actually reside. Cloud computing has indeed revolutionized the way computational resources and services can be used and accessed, implementing the concept of utility computing whose advantages are undeniable for every business. However, despite the benefits in terms of flexibility, economic savings, and support of new services, its widespread adoption is hindered by the security issues arising with its usage. From a security perspective, the technological revolution introduced by IoT and Cloud computing can represent a disaster, as each object might become inherently remotely hackable and, as a consequence, controllable by malicious actors. While the literature mostly focuses on the security of IoT and Cloud computing as separate entities, in this article we provide an up-to-date and well-structured survey of the security issues of cloud computing in the IoT era. We give a clear picture of where security issues occur and what their potential impact is. As a result, we claim that it is not enough to secure IoT devices, as cyber-storms come from Clouds.

sted, utgiver, år, opplag, sider
MDPI, 2019
Emneord
security, Internet of Things, Cloud computing
HSV kategori
Identifikatorer
urn:nbn:se:oru:diva-75237 (URN)10.3390/fi11060127 (DOI)000473805800007 ()2-s2.0-85067464961 (Scopus ID)
Tilgjengelig fra: 2019-07-25 Laget: 2019-07-25 Sist oppdatert: 2023-08-03bibliografisk kontrollert
3. Adding Salt to Pepper: A Structured Security Assessment over a Humanoid Robot
Åpne denne publikasjonen i ny fane eller vindu >>Adding Salt to Pepper: A Structured Security Assessment over a Humanoid Robot
2018 (engelsk)Inngår i: Proceedings of the 13th International Conference on Availability, Reliability and Security, ACM , 2018, artikkel-id 22Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

The rise of connectivity, digitalization, robotics, and artificial intelligence (AI) is rapidly changing our society and shaping its future development. During this technological and societal revolution, security has been persistently neglected, yet a hacked robot can act as an insider threat in organizations, industries, public spaces, and private homes. In this paper, we perform a structured security assessment of Pepper, a commercial humanoid robot. Our analysis, composed by an automated and a manual part, points out a relevant number of security flaws that can be used to take over and command the robot. Furthermore, we suggest how these issues could be fixed, thus, avoided in the future. The very final aim of this work is to push the rise of the security level of IoT products before they are sold on the public market.

sted, utgiver, år, opplag, sider
ACM, 2018
Serie
ACM International Conference Proceeding Series
Emneord
Internet of Things (IoT), Penetration Testing, Pepper, Robot, Security
HSV kategori
Identifikatorer
urn:nbn:se:oru:diva-71106 (URN)10.1145/3230833.3232807 (DOI)000477981800043 ()2-s2.0-85055287152 (Scopus ID)978-1-4503-6448-5 (ISBN)
Konferanse
13th International Conference on Availability, Reliability and Security (ARES 2018), Hamburg, Germany, August 27-30, 2018
Tilgjengelig fra: 2019-01-04 Laget: 2019-01-04 Sist oppdatert: 2025-02-05bibliografisk kontrollert
4. Analysis of DDoS-Capable IoT Malwares
Åpne denne publikasjonen i ny fane eller vindu >>Analysis of DDoS-Capable IoT Malwares
2017 (engelsk)Inngår i: Proceedings of the 2017 Federated Conference on Computer Science and Information Systems / [ed] M. Ganzha, L. Maciaszek, M. Paprzycki, Institute of Electrical and Electronics Engineers (IEEE), 2017, s. 807-816Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

The Internet of Things (IoT) revolution promises to make our lives easier by providing cheap and always connected smart embedded devices, which can interact on the Internet and create added values for human needs. But all that glitters is not gold. Indeed, the other side of the coin is that, from a security perspective, this IoT revolution represents a potential disaster. This plethora of IoT devices that flooded the market were very badly protected, thus an easy prey for several families of malwares that can enslave and incorporate them in very large botnets. This, eventually, brought back to the top Distributed Denial of Service (DDoS) attacks, making them more powerful and easier to achieve than ever. This paper aims at provide an up-to-date picture of DDoS attacks in the specific subject of the IoT, studying how these attacks work and considering the most common families in the IoT context, in terms of their nature and evolution through the years. It also explores the additional offensive capabilities that this arsenal of IoT malwares has available, to mine the security of Internet users and systems. We think that this up-to-date picture will be a valuable reference to the scientific community in order to take a first crucial step to tackle this urgent security issue.

sted, utgiver, år, opplag, sider
Institute of Electrical and Electronics Engineers (IEEE), 2017
Serie
Annals of computer science and information systems, E-ISSN 2300-5963 ; 11
HSV kategori
Identifikatorer
urn:nbn:se:oru:diva-62795 (URN)10.15439/2017F288 (DOI)000417412800118 ()2-s2.0-85039904613 (Scopus ID)978-83-946253-7-5 (ISBN)
Konferanse
Federated Conference on Computer Science and Information Systems (FedCSIS 2017), Prague, Czech Republic, September 3-6, 2017
Tilgjengelig fra: 2017-11-23 Laget: 2017-11-23 Sist oppdatert: 2021-01-07bibliografisk kontrollert
5. DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation
Åpne denne publikasjonen i ny fane eller vindu >>DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation
2018 (engelsk)Inngår i: Security and Communication Networks, ISSN 1939-0114, E-ISSN 1939-0122, artikkel-id 7178164Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

The Internet of Things (IoT) revolution has not only carried the astonishing promise to interconnect a whole generation of traditionally “dumb” devices, but also brought to the Internet the menace of billions of badly protected and easily hackable objects. Not surprisingly, this sudden flooding of fresh and insecure devices fueled older threats, such as Distributed Denial of Service (DDoS) attacks. In this paper, we first propose an updated and comprehensive taxonomy of DDoS attacks, together with a number of examples on how this classification maps to real-world attacks. Then, we outline the current situation of DDoS-enabled malwares in IoT networks, highlighting how recent data support our concerns about the growing in popularity of these malwares. Finally, we give a detailed analysis of the general framework and the operating principles of Mirai, the most disruptive DDoS-capable IoT malware seen so far.

sted, utgiver, år, opplag, sider
Hindawi Publishing Corporation, 2018
HSV kategori
Forskningsprogram
Datavetenskap
Identifikatorer
urn:nbn:se:oru:diva-65665 (URN)10.1155/2018/7178164 (DOI)000426639800001 ()2-s2.0-85043390832 (Scopus ID)
Tilgjengelig fra: 2018-03-12 Laget: 2018-03-12 Sist oppdatert: 2021-01-07bibliografisk kontrollert
6. Protecting the Internet of Things with Security-by-Contract and Fog Computing
Åpne denne publikasjonen i ny fane eller vindu >>Protecting the Internet of Things with Security-by-Contract and Fog Computing
2019 (engelsk)Inngår i: 2019 IEEE 5th World Forum on Internet of Things (WF-IoT), IEEE , 2019Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Nowadays, the Internet of Things (IoT) is a consolidated reality. Smart homes are equipped with a growing number of IoT devices that capture more and more information about human beings lives. However, manufacturers paid little or no attention to security, so that various challenges are still in place. In this paper, we propose a novel approach to secure IoT systems that combines the concept of Security-by-Contract (SxC) with the Fog computing distributed paradigm. We define the pillars of our approach, namely the notions of IoT device contract, Fog node policy and contract-policy matching, the respective life-cycles, and the resulting SxC workflow. To better understand all the concepts of the SxC framework, and highlight its practical feasibility, we use a running case study based on a context-aware system deployed in a real smart home.

sted, utgiver, år, opplag, sider
IEEE, 2019
Emneord
security-by-contract, Fog computing, IoT
HSV kategori
Identifikatorer
urn:nbn:se:oru:diva-78009 (URN)10.1109/WF-IoT.2019.8767243 (DOI)000492865800001 ()2-s2.0-85073699472 (Scopus ID)978-1-5386-4980-0 (ISBN)
Konferanse
5th IEEE World Forum on Internet of Things (WF-IoT 2019), Limerick, Ireland, April 15-18, 2019
Tilgjengelig fra: 2019-11-22 Laget: 2019-11-22 Sist oppdatert: 2021-01-07bibliografisk kontrollert
7. IoT Security Configurability with Security-by-Contract
Åpne denne publikasjonen i ny fane eller vindu >>IoT Security Configurability with Security-by-Contract
2019 (engelsk)Inngår i: Sensors, E-ISSN 1424-8220, Vol. 19, nr 19, artikkel-id E4121Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

Cybersecurity is one of the biggest challenges in the Internet of Things (IoT) domain, as well as one of its most embarrassing failures. As a matter of fact, nowadays IoT devices still exhibit various shortcomings. For example, they lack secure default configurations and sufficient security configurability. They also lack rich behavioural descriptions, failing to list provided and required services. To answer this problem, we envision a future where IoT devices carry behavioural contracts and Fog nodes store network policies. One requirement is that contract consistency must be easy to prove. Moreover, contracts must be easy to verify against network policies. In this paper, we propose to combine the security-by-contract (S × C) paradigm with Fog computing to secure IoT devices. Following our previous work, first we formally define the pillars of our proposal. Then, by means of a running case study, we show that we can model communication flows and prevent information leaks. Last, we show that our contribution enables a holistic approach to IoT security, and that it can also prevent unexpected chains of events.

sted, utgiver, år, opplag, sider
MDPI, 2019
Emneord
Fog computing, IoT, configurability, security, security-by-contract
HSV kategori
Identifikatorer
urn:nbn:se:oru:diva-76829 (URN)10.3390/s19194121 (DOI)000494823200065 ()31548501 (PubMedID)2-s2.0-85072578077 (Scopus ID)
Tilgjengelig fra: 2019-09-30 Laget: 2019-09-30 Sist oppdatert: 2022-02-10bibliografisk kontrollert
8. S×C4IoT: A Security-by-Contract Framework for Dynamic Evolving IoT Devices
Åpne denne publikasjonen i ny fane eller vindu >>S×C4IoT: A Security-by-Contract Framework for Dynamic Evolving IoT Devices
(engelsk)Manuskript (preprint) (Annet vitenskapelig)
HSV kategori
Identifikatorer
urn:nbn:se:oru:diva-88397 (URN)
Tilgjengelig fra: 2021-01-07 Laget: 2021-01-07 Sist oppdatert: 2021-01-07bibliografisk kontrollert

Open Access i DiVA

Cover(286 kB)187 nedlastinger
Filinformasjon
Fil COVER01.pdfFilstørrelse 286 kBChecksum SHA-512
07a4dcb765882212afa263e8f0a81234730c17c5f20deaf02d0fb3cd83b1e64d83b57d817d303817e38126d4a12b3ab4a7f77a22de10d49e2b86b8dc3866510b
Type coverMimetype application/pdf
Spikblad(93 kB)156 nedlastinger
Filinformasjon
Fil SPIKBLAD01.pdfFilstørrelse 93 kBChecksum SHA-512
ef9f6ab17f03fff8f0eedaecf39f9ea7d39c58a92185c74993a03c8dbab8eb3447061ee8dec10b42b0fca7b06bcf58900b0185344a5891dc97348de9dbb191c3
Type spikbladMimetype application/pdf

Person

Giaretta, Alberto

Søk i DiVA

Av forfatter/redaktør
Giaretta, Alberto
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar
Antall nedlastinger er summen av alle nedlastinger av alle fulltekster. Det kan for eksempel være tidligere versjoner som er ikke lenger tilgjengelige

isbn
urn-nbn

Altmetric

isbn
urn-nbn
Totalt: 882 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf