STRIPED: A Threat Analysis Method for IoT Systems


연구 분야: Analysis



학회: ARES '22: Proceedings of the 17th International Conference on Availability, Reliability and Security


초록

Currently, IoT systems display a poor level of security, as 50% of IoT devices are vulnerable to severe attacks, according to research. In an attempt to ameliorate the situation, we propose STRIPED, a threat analysis technique that focuses particularly on threat scenarios involving IoT devices that can be physically accessed by attackers. We evaluate STRIPED in a two-pronged way. First, we assess its performance compared to STRIDE (from which STRIPED is derived) in the context of a case study from the manufacturing industry. Second, we gather the feedback of 8 security experts working in a large, multinational company that specializes in secure IoT products for the domains of automotive, industrial, mobile and smart-home applications. These initial evaluation attempts provide encouraging evidence and suggest our method is a step in the right direction of facilitating security-by-design in IoT systems, especially industrial ones.


Author Profile
Kamakshi Srikumar

Hamburg University of Technology Germany

Germany
Author Profile
Komal Kashish

Hamburg University of Technology Germany

Germany
Author Profile
Kolja Eggers

Hamburg University of Technology Germany

Germany

📄 논문 정보

발행 연도 2022년
인용수 2
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (86건)