Assessing Risks and Modeling Threats in the Internet of Things

10/14/2021
by   Paul Griffioen, et al.
0

Threat modeling and risk assessments are common ways to identify, estimate, and prioritize risk to national, organizational, and individual operations and assets. Several threat modeling and risk assessment approaches have been proposed prior to the advent of the Internet of Things (IoT) that focus on threats and risks in information technology (IT). Due to shortcomings in these approaches and the fact that there are significant differences between the IoT and IT, we synthesize and adapt these approaches to provide a threat modeling framework that focuses on threats and risks in the IoT. In doing so, we develop an IoT attack taxonomy that describes the adversarial assets, adversarial actions, exploitable vulnerabilities, and compromised properties that are components of any IoT attack. We use this IoT attack taxonomy as the foundation for designing a joint risk assessment and maturity assessment framework that is implemented as an interactive online tool. The assessment framework this tool encodes provides organizations with specific recommendations about where resources should be devoted to mitigate risk. The usefulness of this IoT framework is highlighted by case study implementations in the context of multiple industrial manufacturing companies, and the interactive implementation of this framework is available at http://iotrisk.andrew.cmu.edu.

READ FULL TEXT

page 3

page 4

page 5

page 6

research
11/08/2018

Security Risk Assessment in Internet of Things Systems

Information security risk assessment methods have served us well over th...
research
12/11/2018

Information Security Risks Assessment: A Case Study

Owing to recorded incidents of Information technology inclined organisat...
research
05/09/2023

PSP Framework: A novel risk assessment method in compliance with ISO/SAE-21434

As more cars connect to the internet and other devices, the automotive m...
research
01/18/2023

Graph-Theoretic Approach for Manufacturing Cybersecurity Risk Modeling and Assessment

Identifying, analyzing, and evaluating cybersecurity risks are essential...
research
02/18/2023

Security of IT/OT Convergence: Design and Implementation Challenges

IoT is undoubtedly considered the future of the Internet. Many sectors a...
research
06/17/2023

An Architectural Design Decision Model for Resilient IoT Application

The Internet of Things is a paradigm that refers to the ubiquitous prese...
research
06/15/2022

A Continuous Risk Assessment Methodology for Cloud Infrastructures

Cloud systems are dynamic environments which make it difficult to keep t...

Please sign up or login with your details

Forgot password? Click here to reset