中文

面向通过威胁建模、安全分析与渗透测试实现安全保证自动化的 IoT/IIoT 模型需求与建议

密码学与安全 2019-06-26 v1

摘要

未来工厂需要将其物理机器高效地互联至网络空间,以应对机器高可用时间、更高性能率、更高生产力水平以及供应链协同协作的新兴需求。随着物联网(IoT)的快速增长及其在工业领域的应用,所谓的工业物联网(IIoT)/工业 4.0 应运而生。然而,除 IoT/IIoT 系统的快速增长外,网络攻击正成为新兴威胁,而简单的人工安全测试往往无法应对大型 IoT/IIoT 网络的规模。本文建议从典型软件开发过程中常用的图表与模型提取元数据,以在无需详尽安全先验知识的情况下自动化威胁建模、安全分析与渗透测试过程。在此背景下,我们提出 IoT/IIoT 模型中作为安全保证工具必要输入参数所需的元数据需求与建议。

关键词

引用

@article{arxiv.1906.10416,
  title  = {Requirements and Recommendations for IoT/IIoT Models to automate Security Assurance through Threat Modelling, Security Analysis and Penetration Testing},
  author = {Ralph Ankele and Stefan Marksteiner and Kai Nahrgang and Heribert Vallant},
  journal= {arXiv preprint arXiv:1906.10416},
  year   = {2019}
}

备注

8 pages, Proceedings of the 14th International Conference on Availability, Reliability and Security (ARES 2019) (ARES '19), August 26-29, 2019, Canterbury, United Kingdom