Strategic Remote Attestation: Testbed for Internet-of-Things Devices and Stackelberg Security Game for Optimal Strategies

09/16/2021
by   Shanto Roy, et al.
0

Internet of Things (IoT) devices and applications can have significant vulnerabilities, which may be exploited by adversaries to cause considerable harm. An important approach for mitigating this threat is remote attestation, which enables the defender to remotely verify the integrity of devices and their software. There are a number of approaches for remote attestation, and each has its unique advantages and disadvantages in terms of detection accuracy and computational cost. Further, an attestation method may be applied in multiple ways, such as various levels of software coverage. Therefore, to minimize both security risks and computational overhead, defenders need to decide strategically which attestation methods to apply and how to apply them, depending on the characteristic of the devices and the potential losses. To answer these questions, we first develop a testbed for remote attestation of IoT devices, which enables us to measure the detection accuracy and performance overhead of various attestation methods. Our testbed integrates two example IoT applications, memory-checksum based attestation, and a variety of software vulnerabilities that allow adversaries to inject arbitrary code into running applications. Second, we model the problem of finding an optimal strategy for applying remote attestation as a Stackelberg security game between a defender and an adversary. We characterize the defender's optimal attestation strategy in a variety of special cases. Finally, building on experimental results from our testbed, we evaluate our model and show that optimal strategic attestation can lead to significantly lower losses than naive baseline strategies.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/17/2019

A Secure Contained Testbed for Analyzing IoT Botnets

Many security issues have come to the fore with the increasingly widespr...
research
05/25/2019

MoMIT: Porting a JavaScript Interpreter on a Quarter Coin

The Internet of Things (IoT) is a network of physical, heterogeneous, co...
research
05/24/2023

IoT Threat Detection Testbed Using Generative Adversarial Networks

The Internet of Things(IoT) paradigm provides persistent sensing and dat...
research
08/01/2019

Optimal Deployments of Defense Mechanisms for the Internet of Things

Internet of Things (IoT) devices can be exploited by the attackers as en...
research
03/30/2022

Internet of Things Protection and Encryption: A Survey

The Internet of Things (IoT) has enabled a wide range of sectors to inte...
research
07/28/2022

Gotham Testbed: a Reproducible IoT Testbed for Security Experiments and Dataset Generation

The scarcity of available Internet of Things (IoT) datasets remains a li...
research
07/13/2023

Ageing Analysis of Embedded SRAM on a Large-Scale Testbed Using Machine Learning

Ageing detection and failure prediction are essential in many Internet o...

Please sign up or login with your details

Forgot password? Click here to reset