Addressing the Security Gap in IoT: Towards an IoT Cyber Range

被引:12
|
作者
Nock, Oliver [1 ]
Starkey, Jonathan [1 ]
Angelopoulos, Constantinos Marios [1 ]
机构
[1] Bournemouth Univ, Fac Sci & Technol, Dept Comp & Informat, Poole BH12 5BB, Dorset, England
基金
欧盟地平线“2020”;
关键词
cyber-range; IoT; testbed; cyber-security;
D O I
10.3390/s20185439
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The paradigm of Internet of Things has now reached a maturity level where the pertinent research goal is the successful application of IoT technologies in systems of high technological readiness level. However, while basic aspects of IoT connectivity and networking have been well studied and adequately addressed, this has not been the case for cyber security aspects of IoT. This is nicely demonstrated by the number of IoT testbeds focusing on networking aspects and the lack of IoT testbeds focusing on security aspects. Towards addressing the existing and growing skills-shortage in IoT cyber security, we present an IoT Cyber Range (IoT-CR); an IoT testbed designed for research and training in IoT security. The IoT-CR allows the user to specify and work on customisable IoT networks, both virtual and physical, and supports the concurrent execution of multiple scenarios in a scalable way following a modular architecture. We first provide an overview of existing, state of the art IoT testbeds and cyber security related initiatives. We then present the design and architecture of the IoT Cyber Range, also detailing the corresponding RESTful APIs that help de-associate the IoT-CR tiers and obfuscate underlying complexities. The design is focused around the end-user and is based on the four design principles for Cyber Range development discussed in the introduction. Finally, we demonstrate the use of the facility via a red/blue team scenario involving a variant of man-in-the-middle attack using IoT devices. Future work includes the use of the IoT-CR by cohorts of trainees in order to evaluate the effectiveness of specific scenarios in acquiring IoT-related cyber-security knowledge and skills, as well as the IoT-CR integration with a pan-European cyber-security competence network.
引用
收藏
页码:1 / 19
页数:19
相关论文
共 50 条
  • [1] Cyber Security - IoT
    Naik, Swapnil
    Maral, Vikas
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ELECTRONICS, INFORMATION & COMMUNICATION TECHNOLOGY (RTEICT), 2017, : 764 - 767
  • [2] Hybrid IoT Cyber Range
    Balto, Karl Edvard
    Yamin, Muhammad Mudassar
    Shalaginov, Andrii
    Katt, Basel
    SENSORS, 2023, 23 (06)
  • [3] Cyber security threats in IoT: A review
    Rana, Pragati
    Patil, B. P.
    JOURNAL OF HIGH SPEED NETWORKS, 2023, 29 (02) : 105 - 120
  • [4] AI security and cyber risk in IoT systems
    Radanliev, Petar
    De Roure, David
    Maple, Carsten
    Nurse, Jason R. C.
    Nicolescu, Razvan
    Ani, Uchenna
    FRONTIERS IN BIG DATA, 2024, 7
  • [5] IoT Security Framework for Smart Cyber Infrastructures
    Pacheco, Jesus
    Hariri, Salim
    2016 IEEE 1ST INTERNATIONAL WORKSHOPS ON FOUNDATIONS AND APPLICATIONS OF SELF* SYSTEMS (FAS*W), 2016, : 242 - 247
  • [6] Towards Solving the IoT Standards Gap
    Vivek, S.
    Verma, Divyanshu
    Krishnan, Prabhakar
    2018 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2018, : 1441 - 1447
  • [7] Towards IoT Security Automation and Orchestration
    Zheng, Yifeng
    Pal, Arindam
    Abuadbba, Sharif
    Pokhrel, Shiva Raj
    Nepal, Surya
    Janicke, Helge
    2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 55 - 63
  • [8] Towards a Formal IoT Security Model
    Martin, Tania
    Geneiatakis, Dimitrios
    Kounelis, Ioannis
    Kerckhof, Stephanie
    Fovino, Igor Nai
    SYMMETRY-BASEL, 2020, 12 (08): : 1 - 16
  • [9] Towards an Extensible IoT Security Taxonomy
    Wuestrich, Lars
    Pahl, Marc-Oliver
    Liebald, Stefan
    2020 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2020, : 697 - 702
  • [10] A Step Towards Checking Security in IoT
    Bodei, Chiara
    Degano, Pierpaolo
    Ferrari, Gian-Luigi
    Galletta, Letterio
    ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2016, (223): : 128 - 142