Towards Actionable Security Guidelines for IoT Compliance Auditing and Integration with Trustworthiness
Towards Actionable Security Guidelines for IoT Compliance Auditing and Integration with Trustworthiness
批准号:
577183-2022
负责人:
Majumdar, SuryadiptaS
金额:
$3.28万
依托单位:
依托单位国家:
加拿大
项目类别:
Alliance Grants
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
There has been a significant increase in the deployments of the Internet of Things (IoT) devices over the last few years. Security, however, has lagged behind, as evidenced by the increasing number of attacks that target IoT devices (e.g., an arson that uses a smart oven, burglary via a smart lock), which may lead to as severe consequences as, not to mention sometimes more than, those targeting conventional devices. Nowadays, IoT devices tend to be trusted with more personal and security-critical data, although with relatively less computing power. Common causes of those attacks include but are not limited to software vulnerabilities and misconfigurations. Another important contributor is the multiparty model of the IoT device lifecycle, e.g., what the vendor/developer left as "defaults" might not match a security-unaware user's situation. Despite existing efforts, mitigating such security threats still remains challenging mainly for the following reasons: 1) current IoT security recommendations (e.g., NIST, ENISA) are too high-level to produce actionable items for enforcement/auditing; 2) those recommendations are not also expressed using system-level data so that the developers and manufacturers of IoT devices can easily integrate them into the device implementation; 3) most IoT devices lack sufficient storage and computational capabilities to conduct compliance auditing (e.g., using formal methods); and 4) collecting data from those devices, which frequently generate/collect sensitive information, introduces new privacy concerns.This proposed program seeks to overcome those challenges and develop an AI-enhanced security framework for IoT devices to benefit from the security recommendations/standards in an automated manner. The objectives of this program are to: (i) derive actionable security guidelines by bridging the gap between the high-level recommendations and low-level system technicality; (ii) overcome the resource constraint and privacy concerns about data sharing; (iii) provide trustworthiness assurance for either the integration of those guidelines during the development/manufacturing phase, or the compliance auditing thereof, of the user's choice. In pursuit of these objectives, the proposed research will be conducted through several major research thrusts. First, we will build an automated solution to translate high-level recommendations into more concrete, actionable security guidelines that adapts to heterogeneous IoT platforms, by applying natural language processing (NLP) techniques. Second, we will devise a compliance auditing approach that learns the clusters of similar devices using nonsensitive data (e.g., design specifications) and then locally utilizes the sensitive data (e.g., sensor data) to perform the actual auditing in a federated manner to preserve privacy. Third and orthogonally, we will develop an automated technique to generate concrete integration inputs, e.g., scripts, templates and policies, so that the developers/manufacturers can easily apply these actionable guidelines and proactively ensure compliance if they choose to. Both the second and third thrusts will try to make use of current hardware-based techniques (e.g., trusted computing). The outcome of the proposed research will help secure IoT environments and can be used to design a viable adoption plan (e.g., IoT security education, defining security policies) for the upcoming IoT era.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金