IoT Security Risk Management: A Framework and Teaching Approach

被引:2
|
作者
Affia, Abasi-amefon O. [1 ]
Nolte, Alexander [1 ,2 ]
Matulevicius, Raimundas [1 ]
机构
[1] Univ Tartu, Tartu, Estonia
[2] Carnegie Mellon Univ, Pittsburgh, PA USA
来源
INFORMATICS IN EDUCATION | 2023年 / 22卷 / 04期
关键词
Internet of Things (IoT); security risk management; hackathons; security learning; INTERNET;
D O I
10.15388/infedu.2023.30
中图分类号
G40 [教育学];
学科分类号
040101 ; 120403 ;
摘要
While Internet of Things (IoT) devices have increased in popularity and usage, their users have become more susceptible to cyber-attacks, thus emphasizing the need to manage the resulting security risks. However, existing works reveal research gaps in IoT security risk manage-ment frameworks where the IoT architecture - building blocks of the system - are not adequately considered for analysis. Also, security risk management includes complex tasks requiring appro-priate training and teaching methods to be applied effectively. To address these points, we first proposed a security risk management framework that captures the IoT architecture perspective as an input to further security risk management activities. We then proposed a hackathon learning model as a practical approach to teach hackathon participants to apply the IoT security risk man-agement framework. To evaluate the benefits of the framework and the hackathon learning model, we conducted an action research study that integrated the hackathon learning model into a cy-bersecurity course, where students learn how to apply the framework. Our findings show that the IoTA-SRM framework was beneficial in guiding students towards IoT security risk management and producing repeatable outcomes. Additionally, the study demonstrated the applicability of the hackathon model and its interventions in supporting the learning of IoT security risk management and applying the proposed framework to real-world scenarios.
引用
收藏
页码:555 / 588
页数:34
相关论文
共 50 条
  • [1] Security risk management in IoT environment
    Malik, Vinita
    Singh, Sukhdip
    [J]. JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2019, 22 (04): : 697 - 709
  • [2] A Framework for Uniformization of Security, Network and Management in IoT Applications
    Cavalcanti, Ricardo J. B. de V. M.
    Costa, Danielly C. M.
    Ali, Mohamad S. A.
    Oliveira, Josiel P. P.
    Silva, Diego R. C.
    Nogueira, Marcelo B.
    Rodrigues, Marconi C.
    [J]. 2019 IEEE INTERNATIONAL WORKSHOP ON METROLOGY FOR INDUSTRY 4.0 AND INTERNET OF THINGS (METROIND4.0&IOT), 2019, : 196 - 201
  • [3] Framework for Teaching Safety Case Studies Using a Risk Management Approach
    Bocwinski, Rachel
    Finster, David C.
    Weizman, Haim
    [J]. JOURNAL OF CHEMICAL EDUCATION, 2021, 98 (12) : 3824 - 3830
  • [4] IOT SECURITY RISK MANAGEMENT MODEL FOR HEALTHCARE INDUSTRY
    Salih, Fathi Ibrahim
    Abu Bakar, Nur Azaliah
    Hassan, Noor Hafizah
    Yahya, Farashazillah
    Kama, Nazri
    Shah, Jalal
    [J]. MALAYSIAN JOURNAL OF COMPUTER SCIENCE, 2019, : 131 - 144
  • [5] Layered management approach to cyber security of IoT solutions
    Ozdogan, Erdal
    Das, Resul
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2023, 14 (05) : 493 - 504
  • [6] IT Security Risk Management: An Early Assessment Framework
    Sinclaire, Jollean K.
    Simon, Judith C.
    Campbell, Charles J.
    Wilkes, Ronald B.
    [J]. JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2011, 6 (04): : 248 - 261
  • [8] Technology and policy post-security management framework for IoT electrical safety management
    [J]. Park, Namje (namjepark@jejunu.ac.kr), 1879, Korean Institute of Electrical Engineers (66):
  • [9] Agentless Approach for Security Information and Event Management in Industrial IoT
    Zahid, Huma
    Hina, Sadaf
    Hayat, Muhammad Faisal
    Shah, Ghalib A.
    [J]. ELECTRONICS, 2023, 12 (08)
  • [10] Artorias: IoT Security Testing Framework
    Jeannotte, Bryer
    Tekeoglu, Ali
    [J]. 2019 26TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2019, : 233 - 237