Tool Support for Risk-driven Planning of Trustworthy Smart IoT Systems within DevOps

被引:0
|
作者
Thompson, Andreas [1 ]
Erdogan, Gencer [2 ]
机构
[1] Univ Oslo, Oslo, Norway
[2] SINTEF Digital, Software & Serv Innovat, Oslo, Norway
基金
欧盟地平线“2020”;
关键词
Security; Privacy; Cyber-risk; DevOps; IoT; Method; Risk-driven; Planning; Tool Support; Smart Home;
D O I
10.5220/0009189307420753
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
There is a serious lack of support for trustworthy smart IoT systems within DevOps. Security and privacy are often overlooked in DevOps cultures and almost absent in the context of IoT. In this paper, we focus on the planning stage of DevOps and propose a tool-supported method for risk-driven planning considering security and privacy risks. Our method consists of five steps: establish context, analyse dataflow, model privacy and security risk, develop risk assessment algorithm based on risk model, and execute risk assessment algorithm. Our tool supports this method in the first and the last step and facilitates dynamic risk assessment based on input provided by the user or collected from the monitoring stage into predefined risk models. The output of the tool is a risk assessment which the end users, e.g. developers, can use as decision support to prioritize certain parts of the target under analysis in the next cycle of DevOps. The tool and the method are evaluated in a real-world smart home case. Our initial evaluation indicates that the approach is comprehensible for our intended users, supports the planning stage in terms of security and privacy risk assessment, and feasible for use in the DevOps practice.
引用
收藏
页码:742 / 753
页数:12
相关论文
共 50 条
  • [1] Risk-Driven Design of Perception Systems
    Corso, Anthony L.
    Katz, Sydney M.
    Innes, Craig
    Du, Xin
    Ramamoorthy, Subramanian
    Kochenderfer, Mykel J.
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [2] Continuous Deployment of Trustworthy Smart IoT Systems
    Ferry, Nicolas
    Nguyen, Phu H.
    Song, Hui
    Rios, Erkuden
    Iturbe, Eider
    Martinez, Satur
    Rego, Angel
    [J]. JOURNAL OF OBJECT TECHNOLOGY, 2020, 19 (02): : 1 - 23
  • [3] Risk-driven Framework for Decision Support in Cloud Service Selection
    Gupta, Smrati
    Muntes-Mulero, Victor
    Matthews, Peter
    Dominiak, Jacek
    Omerovic, Aida
    Aranda, Jordi
    Seycek, Stepan
    [J]. 2015 15TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING, 2015, : 545 - 554
  • [4] Risk-Driven Security Metrics Development for an e-Health IoT Application
    SavoIa, Reijo M.
    Savolainen, Pekka
    Evesti, Antti
    Abie, Habtamu
    Sihvonen, Markus
    [J]. 2015 INFORMATION SECURITY FOR SOUTH AFRICA - PROCEEDINGS OF THE ISSA 2015 CONFERENCE, 2015,
  • [5] A Risk-Driven Model to Minimize the Effects of Human Factors on Smart Devices
    Gupta, Sandeep
    Buriro, Attaullah
    Crispo, Bruno
    [J]. EMERGING TECHNOLOGIES FOR AUTHORIZATION AND AUTHENTICATION, ETAA 2019, 2020, 11967 : 156 - 170
  • [6] ENACT: Development, Operation, and Quality Assurance of Trustworthy Smart IoT Systems
    Ferry, Nicolas
    Solberg, Arnor
    Song, Hui
    Lavirotte, Stephane
    Tigli, Jean-Yves
    Winter, Thierry
    Muntes-Mulero, Victor
    Metzger, Andreas
    Rios Velasco, Erkuden
    Castelruiz Aguirre, Amaia
    [J]. SOFTWARE ENGINEERING ASPECTS OF CONTINUOUS DEVELOPMENT AND NEW PARADIGMS OF SOFTWARE PRODUCTION AND DEPLOYMENT, DEVOPS 2018, 2019, 11350 : 112 - 127
  • [7] Towards Risk-Driven Security Testing of Service Centric Systems
    Zech, Philipp
    Felderer, Michael
    Breu, Ruth
    [J]. 2012 12TH INTERNATIONAL CONFERENCE ON QUALITY SOFTWARE (QSIC), 2012, : 140 - 143
  • [8] A Risk-Driven Methodology in Developing Ambient Intelligence Healthcare Systems
    Cicotti, Giuseppe
    Coronato, Antonio
    [J]. INTELLIGENT ENVIRONMENTS 2016, 2016, 21 : 86 - 93
  • [9] Risk-Driven Compliance Assurance for Collaborative AI Systems: A Vision Paper
    Camilli, Matteo
    Felderer, Michael
    Giusti, Andrea
    Matt, Dominik Tobias
    Perini, Anna
    Russo, Barbara
    Susi, Angelo
    [J]. REQUIREMENTS ENGINEERING: FOUNDATION FOR SOFTWARE QUALITY (REFSQ 2021), 2021, 12685 : 123 - 130
  • [10] Risk-driven development of security-critical systems using UMLsec
    Jürjens, J
    [J]. INFORMATION TECHNOLOGY: SELECTED TUTORIALS, 2004, 157 : 21 - 53