Penetration Testing Framework for IoT

Geeta Yadav, Alaa Allakany, Vijay Kumar, Kolin Paul, Koji Okamura

    研究成果: 書籍/レポート タイプへの寄稿会議への寄与

    2 被引用数 (Scopus)

    抄録

    In the Internet of Things (IoT) environment, objects are connected on a network to share data. However, most of the IoT devices are developed and deployed with poor security consideration. As a result, these devices become a target of attacks. A solution for ensuring the safety and security of a network system is Penetration testing. In this study, we propose a framework for automated and flexible penetration testing for IoT network. Most of the available penetration testing methods are experts based, that select tool and process manually. This kind of Pen-test is a costly, time-consuming and inefficient. Also, the existing automated penetration testing doesn't consider the interaction between system components; it works by testing each component of a system separately. Individual component testing can lead to a security gap that makes the Pen-test inefficient since many low severity vulnerabilities on different inter-connected components can lead the system to an insecure state. Moreover, in some cases testing the individual components can claim that the particular component is secure, but if these individual components are connected in one system, it makes this system insecure. Due to such shortages, our framework will test the End-to-End target system (i.e., end devices, wireless communication, the control unit, then communication to the cloud server, and finally communication from the cloud to end user through mobile app or webpage). The proposed framework will automatically gather the information of the target IoT network and then perform various kinds of penetration testing through the network. Then it will summarize the results of Pentest and gives the recommendations to secure the system.

    本文言語英語
    ホスト出版物のタイトルProceedings - 2019 8th International Congress on Advanced Applied Informatics, IIAI-AAI 2019
    出版社Institute of Electrical and Electronics Engineers Inc.
    ページ477-482
    ページ数6
    ISBN(電子版)9781728126272
    DOI
    出版ステータス出版済み - 7月 2019
    イベント8th IIAI International Congress on Advanced Applied Informatics, IIAI-AAI 2019 - Toyama, 日本
    継続期間: 7月 7 20197月 11 2019

    出版物シリーズ

    名前Proceedings - 2019 8th International Congress on Advanced Applied Informatics, IIAI-AAI 2019

    会議

    会議8th IIAI International Congress on Advanced Applied Informatics, IIAI-AAI 2019
    国/地域日本
    CityToyama
    Period7/7/197/11/19

    !!!All Science Journal Classification (ASJC) codes

    • コンピュータ ネットワークおよび通信
    • コンピュータ サイエンスの応用
    • 情報システム
    • 情報システムおよび情報管理
    • 社会科学(その他)

    フィンガープリント

    「Penetration Testing Framework for IoT」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

    引用スタイル