Helping novice developers harness security issues in cloud-IoT systems

被引:6
|
作者
Corno F. [1 ]
De Russis L. [1 ]
Mannella L. [1 ]
机构
[1] Dipartimento di Automatica e Informatica, Politecnico di Torino, Corso Duca degli Abruzzi 24, Torino
关键词
AWS; Azure; Cloud; Cybersecurity; Guidelines; IoT; Novice programmers;
D O I
10.1007/s40860-022-00175-4
中图分类号
学科分类号
摘要
The development of cloud-connected Internet of Things (IoT) systems is becoming more and more affordable, even to novice programmers, thanks to dedicated cloud platforms that already integrate the core functionality needed by an IoT system. In this context, a growing number of IoT systems are being developed and deployed on open networks, often without integrating adequate security in the process. Novice IoT programmers, in particular, tend to overlook security issues, as confirmed by a small user study. Starting from this risk, the paper analyzes the security features available in two major cloud-IoT platforms (Amazon Web Services and Microsoft Azure) and highlights those settings, tools, and practices designed to ensure more secure implementations. We observed that these platforms would reasonably address many security problems detected in the study, if only the correct features were identified and used. The paper finally contributes a set of guidelines to support novice IoT developers in avoiding the main and recurrent security issues in their projects and better exploiting cloud-IoT platforms’ inherent security features. © 2022, The Author(s).
引用
收藏
页码:261 / 283
页数:22
相关论文
共 38 条
  • [1] Perception of Security Issues in the Development of Cloud-IoT Systems by a Novice Programmer
    Corno, Fulvio
    De Russis, Luigi
    Mannella, Luca
    INTELLIGENT ENVIRONMENTS 2021, 2021, 29 : 5 - 15
  • [2] The Security Issues in IoT - Cloud: A Review
    Almolhis, Nawaf
    Alashjaee, Abdullah Mujawib
    Duraibi, Salahaldeen
    Alqahtani, Fahad
    Moussa, Ahmed Nour
    2020 16TH IEEE INTERNATIONAL COLLOQUIUM ON SIGNAL PROCESSING & ITS APPLICATIONS (CSPA 2020), 2020, : 191 - 196
  • [3] Mobile fog based secure cloud-IoT framework for enterprise multimedia security
    Sandeep Kumar Sood
    Multimedia Tools and Applications, 2020, 79 : 10717 - 10732
  • [4] Susceptible data classification and security reassurance in cloud-IoT based computing environment
    Ray, Soumya
    Mishra, Kamta Nath
    Dutta, Sandip
    SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2021, 46 (04):
  • [5] Mobile fog based secure cloud-IoT framework for enterprise multimedia security
    Sood, Sandeep Kumar
    MULTIMEDIA TOOLS AND APPLICATIONS, 2020, 79 (15-16) : 10717 - 10732
  • [6] Susceptible data classification and security reassurance in cloud-IoT based computing environment
    Soumya Ray
    Kamta Nath Mishra
    Sandip Dutta
    Sādhanā, 2021, 46
  • [7] Known security issues of IoT systems
    Szadeczky, Tamas
    Kovacs, Gergely
    2018 IEEE INTERNATIONAL CONFERENCE AND WORKSHOP IN OBUDA ON ELECTRICAL AND POWER ENGINEERING (CANDO-EPE), 2018, : 133 - 136
  • [8] New Efficient and Secured Authentication Protocol for Remote Healthcare Systems in Cloud-IoT
    Azrour, Mourade
    Mabrouki, Jamal
    Chaganti, Rajasekhar
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [9] Security-Enhanced Certificate-Based Remote Data Integrity Batch Auditing for Cloud-IoT
    Wang, Wenhao
    Sun, Yinxia
    Li, Yumei
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [10] A survey on security issues in IoT operating systems
    Sun, Panjun
    Wan, Yi
    Wu, Zongda
    Fang, Zhaoxi
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 231