A Comprehensive Study of Security of Internet-of-Things

A Comprehensive Study of Security of Internet-of-Things
复制标题

DOI:
10.1109/tetc.2016.2606384
复制
发表时间:
2017-10-01
影响因子:
5.9
通讯作者:
Jha, Niraj K.
Jha, Niraj K.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Mosenia, Arsalan;Jha, Niraj K.

文献摘要

被引文献

相似文献

物联网(IoT),也被称为物联网,是一种提供多种服务的变革性方法。紧凑型智能设备是物联网的重要组成部分。它们在用途、大小、能量容量和计算能力方面都有广泛的应用。然而,将这些智能物集成到标准互联网中会带来几个安全挑战,因为大多数互联网技术和通信协议都不是为支持物联网而设计的。此外,物联网商业化引发了公共安全担忧,包括个人隐私问题、网络攻击威胁和有组织犯罪。为了给那些想要研究物联网安全并促进其改进的人提供指导,本调查试图提供物联网边缘侧层的漏洞和对策的综合清单,物联网边缘层由三个层次组成:(I)边缘节点,(Ii)通信,和(Iii)边缘计算。为了实现这一目标,我们首先简要描述三种广为人知的物联网参考模型,并在物联网的背景下定义安全。其次,我们讨论了物联网的可能应用以及针对这一新范式的攻击者的潜在动机。第三,我们讨论不同的攻击和威胁。第四,我们描述了针对这些攻击的可能对策。最后,我们介绍了两个新出现的安全挑战,这些挑战在以前的文献中尚未详细说明。
Internet of Things (IoT), also referred to as the Internet of Objects, is envisioned as a transformative approach for providing numerous services. Compact smart devices constitute an essential part of IoT. They range widely in use, size, energy capacity, and computation power. However, the integration of these smart things into the standard Internet introduces several security challenges because the majority of Internet technologies and communication protocols were not designed to support IoT. Moreover, commercialization of IoT has led to public security concerns, including personal privacy issues, threat of cyber attacks, and organized crime. In order to provide a guideline for those who want to investigate IoT security and contribute to its improvement, this survey attempts to provide a comprehensive list of vulnerabilities and countermeasures against them on the edge-side layer of IoT, which consists of three levels: (i) edge nodes, (ii) communication, and (iii) edge computing. To achieve this goal, we first briefly describe three widely-known IoT reference models and define security in the context of IoT. Second, we discuss the possible applications of IoT and potential motivations of the attackers who target this new paradigm. Third, we discuss different attacks and threats. Fourth, we describe possible countermeasures against these attacks. Finally, we introduce two emerging security challenges not yet explained in detail in previous literature.