IoT Security Risk Management: A Framework and Teaching Approach

被引:2
|
作者
Affia, Abasi-amefon O. [1 ]
Nolte, Alexander [1 ,2 ]
Matulevicius, Raimundas [1 ]
机构
[1] Univ Tartu, Tartu, Estonia
[2] Carnegie Mellon Univ, Pittsburgh, PA USA
来源
INFORMATICS IN EDUCATION | 2023年 / 22卷 / 04期
关键词
Internet of Things (IoT); security risk management; hackathons; security learning; INTERNET;
D O I
10.15388/infedu.2023.30
中图分类号
G40 [教育学];
学科分类号
040101 ; 120403 ;
摘要
While Internet of Things (IoT) devices have increased in popularity and usage, their users have become more susceptible to cyber-attacks, thus emphasizing the need to manage the resulting security risks. However, existing works reveal research gaps in IoT security risk manage-ment frameworks where the IoT architecture - building blocks of the system - are not adequately considered for analysis. Also, security risk management includes complex tasks requiring appro-priate training and teaching methods to be applied effectively. To address these points, we first proposed a security risk management framework that captures the IoT architecture perspective as an input to further security risk management activities. We then proposed a hackathon learning model as a practical approach to teach hackathon participants to apply the IoT security risk man-agement framework. To evaluate the benefits of the framework and the hackathon learning model, we conducted an action research study that integrated the hackathon learning model into a cy-bersecurity course, where students learn how to apply the framework. Our findings show that the IoTA-SRM framework was beneficial in guiding students towards IoT security risk management and producing repeatable outcomes. Additionally, the study demonstrated the applicability of the hackathon model and its interventions in supporting the learning of IoT security risk management and applying the proposed framework to real-world scenarios.
引用
收藏
页码:555 / 588
页数:34
相关论文
共 50 条
  • [41] Security Evaluation Framework for Military IoT Devices
    Cha, Sungyong
    Baek, Seungsoo
    Kang, Sooyoung
    Kim, Seungjoo
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [42] LEARNING ANALYTICS FRAMEWORK FOR IOT SECURITY EDUCATION
    Ma Chenguang
    Kulshrestha, Srishti
    Wei, Shi
    Okada, Yoshihiro
    Bose, Ranjan
    [J]. 12TH INTERNATIONAL TECHNOLOGY, EDUCATION AND DEVELOPMENT CONFERENCE (INTED), 2018, : 9181 - 9191
  • [43] IoT Security Framework for Smart Cyber Infrastructures
    Pacheco, Jesus
    Hariri, Salim
    [J]. 2016 IEEE 1ST INTERNATIONAL WORKSHOPS ON FOUNDATIONS AND APPLICATIONS OF SELF* SYSTEMS (FAS*W), 2016, : 242 - 247
  • [44] FuzzDocs: An Automated Security Evaluation Framework for IoT
    You, Myoungsung
    Kim, Yeonkeun
    Kim, Jaehan
    Seo, Minjae
    Son, Sooel
    Shin, Seungwon
    Lee, Seungsoo
    [J]. IEEE ACCESS, 2022, 10 : 102406 - 102420
  • [45] IoT Security Risk Management Strategy Reference Model (IoTSRM2)
    Popescu, Traian Mihai
    Popescu, Alina Madalina
    Prostean, Gabriela
    [J]. FUTURE INTERNET, 2021, 13 (06):
  • [46] A multidisciplinary approach to Internet of Things (IoT) cybersecurity and risk management
    Choo, Kim-Kwang Raymond
    Gai, Keke
    Chiaraviglio, Luca
    Yang, Qing
    [J]. COMPUTERS & SECURITY, 2021, 102
  • [47] Security Weaknesses in IoT Management Platforms
    Tejaswi, Bhaskar
    Mannan, Mohammad
    Youssef, Amr
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (01) : 1572 - 1588
  • [48] An economic modelling approach to information security risk management
    Bojanc, Rok
    Jerman-Blazic, Borka
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2008, 28 (05) : 413 - 422
  • [49] A game theoretic approach to cyber security risk management
    Musman, Scott
    Turner, Andrew
    [J]. JOURNAL OF DEFENSE MODELING AND SIMULATION-APPLICATIONS METHODOLOGY TECHNOLOGY-JDMS, 2018, 15 (02): : 127 - 145
  • [50] Agile Approach with Kanban in Information Security Risk Management
    Dorca, Vasile
    Popescu, Sorin
    Munteanu, Radu, Jr.
    Chioreanu, Adrian
    Peleskei, Claudius
    [J]. PROCEEDING OF 2016 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS (AQTR), 2016, : 19 - 24