Journal - "Internet of things (IoT) attracts and increases threats surface"
INTERNET OF THINGS: A STUDY ON SECURITY AND PRIVACY THREATS
Dept. of computer science
College of CS and IT, Al-Baha University
Al-Baha, Kingdom of Saudi Arabia
ABSTRACT
The current world is driven by new, developing technologies. This has resulted in a variety of smart devices in the society that has impacted positively on the lives of people in the community. However, the organization has been experiencing threats and cyberattacks that mostly targets the private information. Therefore, in this paper, my discussion is centered on the different applications of the internet of things as well as security threats that are involved.
Keywords: security, privacy.
INTRODUCTION
The Internet of things is the most significant of the future of the internet. IoT has a global network through which ant object can connect with the other devices that are also linked on the internet. These devices include computers, tabs, cell phones, among many others. Generally, the internet of things is a system made up of connected things. This machine contains a microchip that connects all the methods related to it. Microchips serve the function of tracking the surrounding of the network and to give the report in case of any findings pertaining to the internet. The meaning of PC wrongdoing and cloud wrongdoing will be come to out to the IoT wrongdoing, which talks to any malignant development that incorporates the IoT worldview as within the IoT contraptions, organizations, or correspondence channels can be a subject, thing, or gadget recognized with the infringement. To investigate these sorts of cases, it is required to execute computerized crime scene examination technique within the IoT to choose the substances around an event. The meaning of a capable and adjust IoT progressed lawful sciences method is still at its unimaginable intrigued (Husamuddin, 2015). The most significant part of IoT is that it makes it possible for different entities to be communicated and to be accessed via the internet. This is very economical as a result, attracts many devices to be connected to the internet (Balte &Patil,2015). Research shows that more than 40 billion devices in 2019 got connected, and a higher risk of this is expected in the current year.
SECURITY REQUIREMENTS
The rate at which technologies are emerging is so high, and this has lead to threats as well as a privacy issue. The smart devices arising from this technology will interact with other devices and transmit information in the network (Balte, &Patil,2015). If a computer gets infected, the effects ripples to other devices in the system; thus, the whole internet infrastructure would be at risk. As soon as an attack spot has been identified, it is feasible to enumerate the safety vulnerabilities and risk prone regions requiring defense-in-intensity protection. Such safety refers to a typically used approach to protect important data on company networks wherein security controls are set up at a couple of tiers of the IT information technology infrastructure. The critical security issues are the validity of data, the privacy of data, accountability of data, and accessibility of data. The highlighted points are the main security concerns that are related to the privacy of the information in the network. Without suitable security and assurance defending frameworks, IoT fog can't be grasped in any case of its esteem. The inconvenience does not fair begin from the interoperability issue, however in expansion the planning ask of security courses of action (Varga, P., Plosz, S., Soos, G., & Hegedus, 2017).
IOT TECHNOLOGIES AND SECURITY THREATS
Wireless Sensor Network (WSN)
The sensor wireless network is a technique that comprises of a variety of small cells that are called sensor nodes and other computing components called actuators. The primary purpose of sensor nodes is to facilitate data processing and communication. This technique can be applied in fields such as healthcare, military, logistics, and many others (Botta, 2020). this network is prone to attacks since it acts as a transimmitio channel for broadcasting. The major threats to this network include; physical attacks from hackers due to the fact that this network can’t stop unauthorized physical access. Node replication. In this, the id of the node is moved to a network together with a sensor resulting in disruption of the network performance. Sinkhole attack. This is where an intruder takes possession of the node from the internet and then attracts the traffic from the neighbor nodes. As a result, this can lead to the alteration of the information such as deleting or the changing of the data. Another threat to this network is service attack denial. The services to the legitimate user are made unavailable by the intruders. Another technology and its security threats are Radio Frequency Identification Technology that consists of a specific identity on the tags, and this is incorporated to the object (Botta, 2020). This tag serves as an identifier for the purpose. This technique is mostly applicable to the healthcare field.
CONCLUSION
IoT is among the significant emerging technologies in the world.the data transmitted through the sensors carry sensitivity information that needs protection from the attackers. To archive, this IoT technology must incorporate services such as encryption, access control for a real-time, end to end environment as well as critical infrastructure protection. This will make it possible for the consumers to control tasks automatically and effectively using IOT technology. In the future, more changes pertaining to the security of smart devices, as well as privacy measures of communication in IOT, will advance and this will win the trust of the operators. Threats involved in this technique include tag cloning, tag swapping that consists of the process of replacing two tags that are of different products with each other, physical data modification, and service denial to the legitimate user.
BIBLIOGRAPHY
Balte, A., Kashid, A., &Patil, B. (2015). Security Issues in the Internet of Things (IoT): A Survey. International Journal of Advanced Research in Computer Science and Software Engineering, 5(4), 450-455. ISSN: 2277, 128X.
SHIELDING IOT AGAINST CYBER-ATTACKS: AN EVENT-BASED APPROACH USING SIEM
Daniel Díaz López,1 María Blanco Uribe,1 Claudia Santiago Cely,1 Andrés Vega Torres,1 Nicolás Moreno Guataquira,1 Stefany Morón Castro,1 Pantaleone Nespoli,2 and Félix Gómez Mármol.
ABSTRACT
The massive growth in the internet of things has led to a variety of machines in diverse industries. However, there is presently inadequate security for these new smart objects in the market. This has risen the need for safety solutions to these issues, and the most desirable techniques have been developed to offer a solution to this problem. This paper proposes the best security solution derived from the management of security events that clearly determines any malicious activity on this model. Different vulnerabilities relating to this technique are pointed out so that solution measures can be undertaken. In this paper, three attack events are generated, exploited vulnerabilities, and the response that could be launched to solve and curb the attack on IoT devices. This paper generally proposes the best approach that can be used to protect the IoT ecosystem.
Keywords: Privacy, security, and trust on the internet of things
INTRODUCTION
IoT devices have rapidly grown and have attracted attention from several fields in the society. It is an emerging technology in the decade is with the capability to be developed to perform efficiently as intended. The main area of concern in this paper is the proposal security method that can be applied in IoT to deal with security issues affecting the performance of this technology. When mulling over the IoT contraptions, it is basic to get it that, comparative to a few other contraptions, security can't be guaranteed. IoT security is certifiably not a combined suggestion of secure or temperamental. Or maybe, it is profitable to conceptualize IoT security as a run of contraption weakness (Rodriguez-Mota, A., Escamilla-Ambrosio, P. J., Happa, J., & Nurse, 2016). Detailed security events of IoT and the proposed security to each scenario. Another sector focuses on the security issues for the IoT devices and the last part about the proposed security measures. The suggestions of a cyber assault by means of the web may result within the collapse of communications networks; the disappointment of electronic keeping money and major online shops including eBay and Amazon; the frustration of transport systems, counting discuss control computers and railroad frameworks; and also the disappointment of the facility grid, shutting down control supplies and causing broad power outages. Advanced framework is especially defenseless to assault. Cyber assaults are difficult to distinguish and indeed harder to shield against (Corones, S., & Lane, 2010). IoT incorporates interconnection a huge number of contraptions from various producers and businesses and execution framework for the most part shifts on different applications and client necessities, heterogeneity of contraptions and information is of imperative noteworthiness. In like way, designing has been the establishment of IoT system, and routine web plan ought to be changed to address IoT challenges (Yelamarthi, Abdelgawad 2017).
IOT ATTACK SURFACES
This comprises the enablers that are the communication protocols and channels and targets that are the data and the processes needed to operate an incident on the IoT devices. The incident threat on the surface primarily depends on the connection among variables of the devices. In this issue, once the attack surface has been determined, the vulnerabilities and the areas of risks that need protection are identified and protective measures adopted. The most common surface attacks include the device web interface, administrative interface, device network services, cloud web interface, mobile application, and many others (Yelamarthi, Abdelgawad 2017). From these vulnerabilities, it is frank that the IoT infrastructure is vulnerable to security threats from a variety of contexts. Right now, may be a major investigate opportunity in different locales, among them Security. Along these lines, right presently has been presented a novel way to bargain with security examination for the IoT systems, counting the progression of a visual dialect structure for the depiction of IoT components and their blend, a framework to recognize veritable circumstances where models can be attempted, and a strategy to grant security courses of action. The heterogeneous thought of the IoT talks to a major test for the different accomplices locked in with the advancement of the supporting development and rules (Rodriguez-Mota, A., Escamilla-Ambrosio, P. J., Happa, J., & Nurse, 2016).
IOT VULNERABILITIES
Data security in the objects of IoT can be clear comprehended through the concepts of integrity, confidentiality, and availability of the information. These are the principles that underline this technique, and they tend to represent the measure of the safety levels that this model has implemented. Unfortunately, these attributes are violated due to the vulnerabilities associated with this technique. These vulnerabilities are the ones that increase the surface attack(“Gartner’s 2016). These vulnerabilities include cryptography, physical access, device control, and authentication problems, as discussed in the previous article. Within the IoT setting, not as it were the client may get to the information but the authorized question. This requires tending to two critical viewpoints: to begin with, get to control and authorization component and moment confirmation and character administration (IdM) mechanism. The IoT gadget should be able to confirm that the substance (individual or other gadgets) is authorized to get to the benefit. The authorization makes a difference decide if, upon recognizable proof, the individual or gadget is allowed to get a benefit (Abomhara, M., 2015).
STATE OF THE ART
Security Information and Event Management (SIEM)
The show cutting edge of the middleware for IoT examines different ways to bargain with offer assistance a parcel of the functionalities to work in IoT space. Be that because it may, no one covers the total course of action of functionalities to meet the prerequisite of IoT-middleware as broke down here for any sharp or unavoidable condition (Soma Bandyopadhyay, Munmun Sengupta, Souvik Maiti, Subhajit Dutta, 2011). This is a model that reveals the happening of a system, network, or service showing the breach of information that occurred as well as offering the security solution to the problem that occurred. The security event comes from the firewalls, virtual private networks, intrusion prevention systems, servers, routers, among others (“Gartner’s 2016). security event management is adopted to ensure monitoring, normalization, reporting, and integration of the security incidents. Security event management (SEM) merge with Security information system (SIM) to facilitate management of log and to give report so as to update security information and event management (SIEM). Hence, the SIEM helps in the discovery of threats and to respond to security incidents through a deep study of the security issues from a range of activities as well as sources of data throughout an IT structure or system. SIEM provides a long period of security occasions and proper reporting of any security incidents in the IoT technique.
CONCLUSION
The IoT technology is accompanied by great beneficial opportunities in the market places. There are a variety of advanced applications to promote productivity and the quality of this technology. In this paper, security measures in the IoT devices have been conducted, and responsive tests also revealed. The most common security events, attack surfaces, and vulnerabilities have also been discussed. SIEM system is the model that has been adopted to generate correlation guidelines to detect security incidents as well as the responsive measures.
BIBLIOGRAPHY
K. Yelamarthi, M. S. Aman, and A. Abdelgawad, “An application-driven modular IoT architecture,” Wireless Communications and Mobile Computing, vol. 2017, Article ID 1350929, 16 pages, 2017.View at: Publisher Site | Google Scholar
Gartner, “Gartner’s 2016 Hype Cycle for Emerging Technologies,” 2016. [Online]. Available: https://www.gartner.com/newsroom/id/3412017.
THE FUTURE INTERNET OF THINGS AND SECURITY OF ITS CONTROL SYSTEMS
Misty Blowers, USAF Research Laboratory
Jose Iribarne, westrock
Edward Colbert, ICF International, Inc.
Alexander Kott, US Army Research Laboratory
ABSTRACT
The industrial evolution commenced in the 18th century in Britain. Textile industry marked the beginning of the industrial revolution. All the work that was performed manually were brought down to a milling machine in the textile industry, giving rise to the factory. In the 20th century, the second industrial revolution took place leading to the mass development of products. In this particular paper am going to discuss the change that has occurred in the IoT and its future. The future of IoT will come at a cost as it involves technological innovations.
Key terms: Manufacturing and industry
INTRODUCTION
The future of cybersecurity highly depends on the context of the Internet of Things. All the infrastructure and industrial contexts, and all the cyber systems are actually all referred to the IoT. The IoT in the future will most likely subsume the industrial plants, housing facilities, infrastructure, and all the methods that are under the control of ICS systems today. For the development of IoT to take place, a few other things must accompany its construction such as the increase in the mobility of devices, growing of automation, ubiquitous robotics as well as miniaturization of sensors and devices (Allen, 2005). The future of IoT depends on the enhancement of automation of machines. It will also involve the emergence of networking and computing paradigms. Cybersecurity will highly benefit from system agility in the IoT environment.
FACTORS THAT WILL AFFECT THE FUTURE OF IOT
Various factors are bound to change the future of IoT. These factors include the building of the future of the IoT. Here academic along with economic support will be required for the success of innovations in the IoT and ICS field that will also be used by others to build the IoT future. The users of the system is another factor that will affect the future of IoT. These are the people who will use or consume the innovative systems in IoT(Allen, 2005). Support is also needed from collaborative parties so as to enhance the ability of consumers to make use of innovative products and services. There are various fields in which I should focus on. These categories include in the first category; materials, devices, automation, and software. In the second category, the focus should be on industrial plant users as well as consumers, and in the third category, the focus should be on infrastructure and computing as well as in government collaboration. Various challenges within the IoT are still beneath investigated. The IoT challenges and open issues are raised due to two fundamental reasons. These reasons for mass gathering information for each thing within the IoT framework and the communication among framework equipment. Gadgets and controllers are utilized by buyers around the world for controlling domestic lighting, reconnaissance cameras, vehicles, and a parcel dynamically locally built up sensors. One difference is that locally built up contraptions and controllers are less costly, are mass-produced with commonly destitute programming and firmware security, and are by and large related to the Net. Web Control Systems were arranged with the common understanding that they would have no framework accessibility to the outside world. In any case, this is often changing as the trade wishes to manhandle the central focus inconvenience gave by amplifying framework accessibility.
SUMMARY
The control systems and IT are making good use of every opportunity that facilitates the development of new hardware devices as the IoT field continues to grow. New automation is required due to the increase in the number of devices both in the consumer and industrial fields. Cloud storage systems, for example, Microsoft Purplish blue, Amazon Web Organizations (AWS), Google Docs, and so on., are foreseen to supply standard entryways for interconnection articles with calculation and correspondence abilities over a wide reach out of utilizations, organizations, and advancements. As IoT drives, distributed computing is foreseen to supply the spine for the around the globe information dispersal, data investigation (or calculation) and limit (Tweneboah-Koduah, S., Skouby, K. E., & Tadayoni, 2017). Consequently, as automation of machines continues to increase in the control centre of IoT, vulnerabilities will also be on the rise both in the software and hardware devices. In the near future, information originating from the IoT will soon be facilitated by proxy network servers such as mobile phones. This will be so because the current wearables and devices have no inbuilt security and those that have inbuilt security they have very little. An extensive software will be required so as to support the future of IoT. Devices should be equipped with protection enough to safeguard personal data, and thus IOT devices need to be designed.
SOLUTIONS
Manufacturing will evolve in one way or the other so as to meet the need of the many changes in the globe. It is predictable that with the growing population, there will be a shortage of resources and products to meet consumer needs. Some of the solutions to curb the above risk are resilience self-adaption in which means that instead of more resources been designed, there should an increase in resilience. A resilient product may be prone to malware attacks but can recover fast from the incident. Thus, normal functioning of such a device is achieved faster (Atzori, & Morabito,2010). Mixed trust systems should also be developed. A mixed trust system is the kind of a system that is flexible and modifiable and those who can tolerate untrusted hardware and software. The use of Big Data Analytics is another solution to the future of IoT. This system is independent and predictive for it is able to anticipate a malware attack within a given time and doesn't require human intervention so as to operate (Atzori, & Morabito,2010). Proactive threat responsiveness is another solution to the future of IoT.
BIBLIOGRAPHY
Allen, J. (2005) Governing for Enterprise Security (CMU/SEI-2005-TN-023). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University
Atzori, L., Iera, A., & Morabito, G. (2010). The internet of things: A survey. Computer networks, 54(15), 2787-2805
SAFEGUARDING THE IOT
BEING SECURE, VIGILANT, AND RESILIENT IN THE CONNECTED AGE
by Irfan, Sean Peasley, and Perinkolam
ABSTRACT
IoT objects are not only smart objects but also connected. That is, they are able to transmit the data they produce. The IoT has done away with human control and can comfortably operate with the power of people. As it is transferred from one smart object to the other in the IoT, there is a possibility of the information being compromised. Data breaches can occur and expose highly private and personal data. IoT producers ignored to execute a generous security system within the contraptions, security pros have cautioned the potential peril of tremendous amounts of unbound gadgets meddle with the Internet. In this discussion, various paradigms that can be used to manage cyber risks are discussed. The ascent of the IoT holds magnificent assurance to change over individual's lives by making society progressively profitable in various districts, tallying essentialness, transportation, medical services, trade, manufacturing (Chen, D., Bovornkeeratiroj, P., Irwin, D., & Shenoy, 2018).
Keywords: Secure, vigilant, and resilient
INTRODUCTION
As advancements in technology continue to happen, and as connectivity increases, the risk of cybersecurity is also increasing and is proven to be a threat to all the users of IoT. Cars’ locations can be hacked, and even the control systems of the vehicle can be hacked. If the control systems of a vehicle are hacked, and the car moves against the will of the user, then the life of people are at serious risk (Pangburn, 2013). The emphasis is on taking care of the specialized issues recognized with building up the IoT with small thought to the issues of spurring powers to grasp, sharing of critical worth over organize clients, and estimation of extraordinary impact. The IoT has gone ahead to create information value loop so as to deal with the issue of insecurity. All objects are being turned as a source of information on that particular object by IoT. The creation of value in the form of an object or a service has led to the development of a value chain in which information about all the activities of a product is seen, thus the emergence of a value loop. This information value loop needs to be protected adequately through a framework, as discussed below.
THE PARADIGM FOR RISK MANAGEMENT
Secure; the first thing in the protection process is to ensure that data and systems are protected and secured against breaches and compromises. The most effective form of protection is that which controls approaches, layers, and types. This is because cyber attackers use the slightest weaknesses in a system to hack it. A weakness that the organization could not imagine existed. Sensors are hardened more and more so as to secure them against deliberate or accidental manipulation. Software firewalls should also be installed so as to protect the systems against hackers. Vigilant; in this paradigm, an organization should ensure frequent verification of security system so as to ensure that they are still functioning and that they have not yet been attacked (Pangburn, 2013). Software are prone to degradation due to age if they stay for a long time. This verification is also essential because attacks keep on mutating so as to fit in new systems, and thus the security systems should be checked regularly. Resilient; a resilient system should also be adopted by organizations. A resilient system recovers data quickly, and therefore even-after a cyber attack, an organization can resume its normal operations faster as the breech is being dealt with.
CONCLUSION
In summary, we can conclude that the IoT products are at high risk of malware attacks, and individuals and organizations should do everything in their power to ensure that they secure their devices against being attacked by hackers, which can use the breeched dat to harm them. We at that point layout the protection suggestions of untrusted IoT gadgets interfacing to certainly trusted systems, and conceivable future inquiries about bearings to relieve these protection suggestions (Chen, D., Bovornkeeratiroj, P., Irwin, D., & Shenoy, 2018). Various strategies can help in securing devices and systems against cyber-attacks, as discussed above.
BIBLIOGRAPHY
D. J. Pangburn, “How easily can a moving car be hacked?” Motherboard, June 28, 2013, http://motherboard.vice. com/blog/how-easily-can-a-moving-car-be-hacked, accessed Feb 29, 2020.
Hewlett-Packard, Internet of Things research study, 2014, www8.hp.com/h20195/v2/GetDocument. aspx?docname=4AA5-4759ENW, accessed April 2015; Arik Hesseldahl, "A hacker's eye view of the Internet of Things," Re/code, April 7, 2015, http://recode.net/2015/04/07/a-hackers-eye-view-of-the-internet-of-things/, accessed Feb 29, 2020.
REFERENCES
Bin Sulaiman, R. (2019). Future Threats to Internet of Things (IoT) Security & Privacy: A Survey. SSRN Electronic Journal. doi: 10.2139/ssrn.3509352
Masoodi, F., Alam, S., & Siddiqui, S. (2019). Security & Privacy Threats, Attacks and Countermeasures in Internet of Things. International Journal Of Network Security & Its Applications, 11(02), 67-77. doi: 10.5121/ijnsa.2019.11205
Ficco, M. (2019). Internet-of-Things and fog-computing as enablers of new security and privacy threats. Internet Of Things, 8, 100113. doi: 10.1016/j.iot.2019.100113
Yang, Y., Wu, L., Yin, G., Li, L., & Zhao, H. (2017). A survey on security and privacy issues in Internet-of-Things. IEEE Internet of Things Journal, 4(5), 1250-1258
Riggins, F. J., & Wamba, S. F. (2015, January). Research directions on the adoption, usage, and impact of the internet of things through the use of big data analytics. In 2015 48th Hawaii International Conference on System Sciences (pp. 1531-1540). IEEE.
Bandyopadhyay, S., Sengupta, M., Maiti, S., & Dutta, S. (2011). Role of middleware for internet of things: A study. International Journal of Computer Science and Engineering Survey, 2(3), 94-105.
Bandyopadhyay, S., Sengupta, M., Maiti, S., & Dutta, S. (2011). A survey of middleware for internet of things. In Recent trends in wireless and mobile networks (pp. 288-296). Springer, Berlin, Heidelberg.
Rodriguez-Mota, A., Escamilla-Ambrosio, P. J., Happa, J., & Nurse, J. R. (2016, November). Towards IoT cybersecurity modeling: From malware analysis data to IoT system representation. In 2016 8th IEEE Latin-American Conference on Communications (LATINCOM) (pp. 1-6). IEEE.
Chen, D., Bovornkeeratiroj, P., Irwin, D., & Shenoy, P. (2018, July). Private memoirs of iot devices: Safeguarding user privacy in the IoT era. In 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS) (pp. 1327-1336). IEEE.
Abomhara, M. (2015). Cyber security and the internet of things: vulnerabilities, threats, intruders and attacks. Journal of Cyber Security and Mobility, 4(1), 65-88.
Corones, S., & Lane, B. (2010). Shielding critical infrastructure information-sharing schemes from competition law. Deakin L. Rev., 15, 1.
Lee, K., Kim, D., Ha, D., Rajput, U., & Oh, H. (2015, September). On security and privacy issues of fog computing supported Internet of Things environment. In 2015 6th International Conference on the Network of the Future (NOF) (pp. 1-3). IEEE.
Tweneboah-Koduah, S., Skouby, K. E., & Tadayoni, R. (2017). Cyber security threats to IoT applications and service domains. Wireless Personal Communications, 95(1), 169-185.