An Experimental Framework for Investigating Security and Privacy of IoT Devices

被引:10
|
作者
Tekeoglu, Ali [1 ]
Tosun, Ali Saman [2 ]
机构
[1] SUNY Polytech Inst, Network Comp Secur Dept, 100 Seymour Ave, Utica, NY 13502 USA
[2] Univ Texas San Antonio, Dept Comp Sci, One UTSA Circle, San Antonio, TX 78249 USA
关键词
IoT devices; Security; Privacy; Framework; IoT testbed;
D O I
10.1007/978-3-319-69155-8_5
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the rapid growth of Internet-of-Things (IoT) devices, security and privacy issues emerged as a potential roadblock for widespread adoption. Preliminary research indicates that many types of IoT devices have serious vulnerabilities. It is not easy to investigate security and privacy issues since each type of device is different and manual experiments need to be conducted on the device. In this paper, we propose a framework for investigation of security and privacy issues of IoT devices. The framework consists of four components, a testbed, set of topics to be investigated, a set of experiments for each topic investigated and a final report. Fundamental approach used in the framework is to capture layer 2 and layer 3 packets and to analyze the packets for various features. Proposed framework is low cost and is based on off-the-shelf hardware and open source software. Using the framework, we can investigate security and privacy issues of many IoT devices including HDMI sticks, IP cameras, activity trackers, smartwatches and drones. A large set of topics can be investigated on IoT devices using the framework including vulnerability issues, protocol security, firmware updates, authentication issues and privacy violations. Sample experimental results show the promise of the proposed framework. We believe this framework will serve as the foundation for a general automated framework to investigate security and privacy issues of most IoT devices.
引用
收藏
页码:63 / 83
页数:21
相关论文
共 50 条
  • [1] Security and Privacy Framework for Ubiquitous Healthcare IoT Devices
    Alkeem, Ebrahim A. L.
    Yeun, Chan Yeob
    Zemerly, M. Jamal
    [J]. 2015 10TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2015, : 70 - 75
  • [2] A Testbed for Security and Privacy Analysis of IoT Devices
    Tekeoglu, Ali
    Tosun, Ali Saman
    [J]. PROCEEDINGS 2016 IEEE 13TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS 2016), 2016, : 343 - 348
  • [3] Are ConsumersWilling to Pay for Security and Privacy of IoT Devices?
    Emami-Naeini, Pardis
    Dheenadhayalan, Janarth
    Agarwal, Yuvraj
    Cranor, Lorrie Faith
    [J]. PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 1505 - 1522
  • [4] A Smart-phone Based Privacy-Preserving Security Framework for IoT Devices
    Togan, Mihai
    Chifor, Bogdan-Cosmin
    Florea, Ionut
    Gugulea, George
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTERS AND ARTIFICIAL INTELLIGENCE - ECAI 2017, 2017,
  • [5] Systematically Evaluating Security and Privacy for Consumer IoT Devices
    Loi, Franco
    Sivanathan, Arunan
    Gharakheili, Hassan Habibi
    Radford, Adam
    Sivaraman, Vijay
    [J]. PROCEEDINGS OF THE 2017 WORKSHOP ON INTERNET OF THINGS SECURITY AND PRIVACY (IOT S&P'17), 2017, : 1 - 6
  • [6] Smart IoT Devices in the Home Security and Privacy Implications
    Sivaraman, Vijay
    Gharakheili, Hassan Habibi
    Fernandes, Clinton
    Clark, Narelle
    Karliychuk, Tanya
    [J]. IEEE TECHNOLOGY AND SOCIETY MAGAZINE, 2018, 37 (02) : 71 - 79
  • [7] Security/Privacy of Wearable Fitness Tracking IoT Devices
    Zhou, Wei
    Piramuthu, Selwyn
    [J]. PROCEEDINGS OF THE 2014 9TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI 2014), 2014,
  • [8] Privacy and Security Requirements Framework for the Internet of Things (IoT)
    Alqassem, Israa
    [J]. 36TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE COMPANION 2014), 2014, : 739 - 741
  • [9] The Security and Privacy Protection Framework for Wearable Devices
    Cui, Youxiang
    Gu, Zhongwei
    Sun, Lei
    Tang, Haibo
    Cui, Lumeng
    [J]. DESIGN, OPERATION AND EVALUATION OF MOBILE COMMUNICATIONS, MOBILE 2022, 2022, 13337 : 203 - 210
  • [10] Security Evaluation Framework for Military IoT Devices
    Cha, Sungyong
    Baek, Seungsoo
    Kang, Sooyoung
    Kim, Seungjoo
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2018,