Abstract
Internet of Things (IoT) is enabling innovative applications in various domains. Due to its heterogeneous and wide scale structure, it introduces many new security issues. To address the security problem, we propose a framework for security modeling and assessment of the IoT. The framework helps to construct graphical security models for the IoT. Generally, the framework involves five steps to find attack scenarios, analyze the security of the IoT through well-defined security metrics, and assess the effectiveness of defense strategies. The benefits of the framework are presented via a study of two example IoT networks. Through the analysis results, we show the capabilities of the proposed framework on mitigating impacts of potential attacks and evaluating the security of large-scale networks.
1. Introduction
In the Internet of Things (IoT), every physical object becomes locatable, addressable and reachable in the virtual world [1], [2], [3]. The IoT is supposed to contain millions or billions of objects which will communicate with each other and with other entities (e.g., human beings). With the inherent complexity and heterogeneous feature, the IoT has faced numerous threats and attacks that will negatively affect its normal functionality. Thus protecting the security of the IoT becomes a complex and difficult task.
5. Conclusion
Modeling security of the IoT is a complex task as the IoT is characterized by a large number of heterogeneous and mobile nodes. In the paper, we have presented a framework of modeling and assessing security for the IoT which encompasses five steps: i) preprocessing, ii) security model generation, iii) visualization and storage, iv) security analysis, and v) changes and updates. In the framework, we have developed an IoT Generator, a Security Model Generator and a Security Evaluator. Two example IoT networks were provided to demonstrate the capabilities of the framework on mitigating impacts of potential attacks and addressing the scalability problem.