arrow
返回

Towards System-Level Security Analysis of IoT Using Attack Graphs

delete2024-02-01
delete2
PRE
AI
Z
Zheng Fang
H
Hao Fu
胡
胡鹏飞 (Pengfei Hu) *
J
Jinyue Song
T
Trent Jaeger
P
Prasant Mohapatra
DOI:10.1109/TMC.2022.3231567delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Most IoT systems involve IoT devices, communication protocols, remote cloud, IoT applications, mobile apps, and the physical environment. However, existing IoT security analyses only focus on a subset of all the essential components, such as device firmware or communication protocols, and ignore IoT systems' interactive nature, resulting in limited attack detection capabilities. In this work, we propose Iota, a logic programming-based framework to perform system-level security analysis for IoT systems. Iota generates attack graphs for IoT systems, showing all of the system resources that can be compromised and enumerating potential attack traces. In building Iota, we design novel techniques to scan IoT systems for individual vulnerabilities and further create generic exploit models for IoT vulnerabilities. We also identify and model physical dependencies between different devices as they are unique to IoT systems and are employed by adversaries to launch complicated attacks. In addition, we utilize NLP techniques to extract IoT app semantics based on app descriptions. Iota automatically translates vulnerabilities, exploits, and device dependencies to Prolog clauses and invokes MulVAL to construct attack graphs. To evaluate vulnerabilities' system-wide impact, we propose three metrics based on the attack graph, which provide guidance on hardening IoT systems. Evaluation on 127 IoT CVEs (Common Vulnerabilities and Exposures) shows that Iota's exploit modeling module achieves over 80% accuracy in predicting vulnerabilities' preconditions and effects. We apply Iota to 37 synthetic smart home IoT systems based on real-world IoT apps and devices. Experimental results show that our framework is effective and highly efficient. Among 27 shortest attack traces revealed by the attack graphs, 62.8% are not anticipated by the system administrator. It only takes 1.2 seconds to generate and analyze the attack graph for an IoT system consisting of 50 devices.
Keyword:
Internet of Things (IoT)
security and privacy
attack graph

期刊

IEEE Transactions on Mobile Computing 封面图
IEEE Transactions on Mobile Computing
IF:
9.2
论文数:
5.8K
被引数:
1.8W

机构

U
university of california davis
学者数:
3.4W
论文数: 2.6W
被引数: 45
P
pennsylvania commonwealth system of higher education (pcshe)
学者数:
12.9W
论文数: 11.7W
被引数: 177
S
shandong university
学者数:
9.5W
论文数: 6.4W
被引数: 94
University of California System 封面图
University of California System
学者数:
37.7W
论文数: 33.8W
被引数: 6.6K
学者 查看更多机构
引用论文

引用论文

Characterization of microsatellite loci in Coffea arabica and related coffee species
err2001-12-25
err0
PREAI
errM. C. Combes; S. Andrzejewski; F. Anthony; B. Bertrand; P. Rovelli; G. Graziosi; P. Lashermes
err分享
err收藏
err分享
err收藏
North Atlantic Craton architecture revealed by kimberlite-hosted crustal zircons
err2020-03-01
err0
errOAAI
errNicholas J. Gardiner; Christopher L. Kirkland; Julie A. Hollis; Peter A. Cawood; Oliver Nebel; Kristoffer Szilas; Chris Yakymchuk
err分享
err收藏
E-transportation: the role of embedded systems in electric energy transfer from grid to vehicle
err2016-05-10
err0
errOAAI
errFederico Baronti; Mo-Yuen Chow; Chengbin Ma; Habiballah Rahimi-Eichi; Roberto Saletti
err分享
err收藏
Cardiovascular diseases risk prediction in patients with diabetes: Posthoc analysis from a matched case-control study in Bangladesh
err2021-02-15
err0
errOAAI
errSheikh Mohammed Shariful Islam; Shyfuddin Ahmed; Riaz Uddin; Muhammad U. Siddiqui; Mahsa Malekahmadi; Abdullah Al Mamun; Roohallah Alizadehsani; Abbas Khosravi; Saeid Nahavandi
err分享
err收藏
err分享
err收藏
Swarming and Behaviour in Antarctic Krill
err2016-08-04
err0
PREAI
errGeraint A. Tarling; Sophie Fielding
err分享
err收藏
学者 查看更多内容