Refine
Year of publication
Document Type
Is part of the Bibliography
- no (25)
Keywords
- Internet of Things (6)
- IoTAG (3)
- device identification (2)
- safety-critical infrastructure (2)
- security rating (2)
- Anomaly Detection (1)
- Artificial Intelligence (1)
- CMUT (1)
- Detection System (1)
- ECU (1)
Institute
- Fakultät Informatik und Mathematik (22)
- Labor Informationssicherheit und Complience (ISC) (8)
- Research Center for Artificial Intelligence - RCAI (3)
- Fakultät Angewandte Natur- und Kulturwissenschaften (2)
- Hochschulleitung/Hochschulverwaltung (1)
- Research Center of Biomedical Engineering - RCBE (1)
- Research Center of Energy and Resources - RCER (1)
- Sensorik-Applikationszentrum (SappZ) (1)
- Zentrum für Forschung und Transfer (ZFT ab 2024; vorher: IAFW) (1)
Begutachtungsstatus
- peer-reviewed (13)
- begutachtet (1)
Forschungsbericht 2016
(2016)
Internet of Thing (IoT) and Smart Grid (SG) are separate technologies. The digital transformation of the energy industry and the increasing digitalization in the private sector connect these technologies. Currently in Germany, the SG is under construction. In order to use future innovative services, SG and IoT must be combined. For this, we connect the SG Infrastructure with the IoT. A potential insecure device and network (IoT) should be able to transfer data to and from a critical infrastructure (SG). Open research question in this context are the security requirements architecture SG and IoT and the mechanism for authentication and authorisation in future application (SG and IoT). Due to the increasing networking of the systems (SG and IoT) new threats and attack vectors arise. The attacks to the architecture influence the target of authenticity, security and privacy. For the security analysis we focus on two communication points: the communication between the smart meter gateway, and the IoT device. In our example, a connected charging station with cloud services is connected with a SG infrastructure. To create a really smart service, the charging station needs a connection to the SG to get the current amount of renewable energy in the grid. With this two connections, new threats emerge. A security analysis over all the connections, including the vulnerability and the ability of an attacker, is developed in this paper. The analysis shows us challenges of the communication between IoT and SG. For this, we defined technical and organizational requirements for authentication and authorization. Current authentication and authorization mechanisms are no longer sufficient for the defined requirements. We present the Role-based trust model for Safety-critical Systems for these defined requirements. The new trust model is integrated into a role-based access control model. It defines data classes, which separate the sensitive and non-sensitive information.
The Internet of Things (IoT) is widely used as a
synonym for nearly every connected device. This makes it really
difficult to find the right kind of scientific publication for the
intended category of IoT. Conferences and other events for
IoT are confusing about the target group (consumer, enterprise,
industrial, etc.) and standardisation organisations suffer from
the same problem. To demonstrate these problems, this paper
shows the results of an analyses over IoT publications in different
research libraries. The number of results for IoT, consumer,
enterprise and industrial search queries were evaluated and a
manual study about 100 publications was done. According to
the research library or search engine, different results about
the distribution of consumer-, enterprise- and industrial- IoT
are visible. The comparison with the results of the manual
evaluation shows that some search queries do not show all desired
publications or that considerably more, unwanted results are
returned. Most researchers do not use the keywords right and
the exact category of IoT can only be accessed via the abstract.
This shows major problems with the use of the term IoT and its
minor limitations.
Internet of Things (IoT) devices are critical to operate and maintain, because of their number and high connectivity.
A lot of security issues concern IoT devices and the networks they
are integrated. To help getting an overview of an IoT network,
the devices and the security, we propose a scoring system to get
a good impression of IT security. This system generates single
scores for each device, using features like encryption, update
behavior, etc. Furthermore, a summarized score for the whole
network is calculated, to show the status of the network security
in an easy way for the administrator. To enable the scoring
system, a precise list of the existing devices and their operating
status is necessary. To achieve this, we present an open standard
for the IoT Device IdentificAtion and RecoGnition (short IoTAG),
which requires that devices report, e.g., their name, an unique ID,
the firmware version and the supported encryption. The proposed
standard is described in detail and an implementation guideline
is given in this paper. Additionally, information about how to
realize the serialization, the integrity and the communication
with IoTAG.
Increasing cyber-attacks on Internet of Things (IoT) environments are a growing problem of digitized households worldwide. The purpose of this study is to investigate how an intelligent Intrusion Detection System (iIDS) can provide more security in IoT networks with a novel architecture, combining
multiple classical and machine learning approaches. By combining classical security analysis methods and modern concepts of artificial intelligence, we increase the quality of attack detection and can therefore conduct dedicated attack suppression. The architectural image of the iIDS consists of different layers, which in parts achieve self-sufficient results. The results of
the different modules are calculated by means of statement variables and evaluation techniques adapted for the individual module elements and subsequently combined by limit value considerations. The architecture image combines approaches for the analysis and processing of IoT network traffic and
evaluates it to an aggregated score. From this result it can be determined whether the analyzed data indicates device misuse or attempted break-ins into the network. This study answers the questions whether a connection between classical and modern concepts for monitoring and analyzing IoT network traffic can be implemented meaningfully within a reliable architecture of an
iIDS.
Since IoT devices are potentially insecure and offer great attack potential, in our past research we presented IoTAG, a solution where devices communicate security-related information about themselves. However, since this information can also be exploited by attackers, we present in this paper a solution against the misuse of IoTAG. In doing so, we address the two biggest problems: authentication and pairing with a trusted device. This is solved by introducing a pairing process, which uses the simultaneous authentication of equals algorithm to securely exchange and verify each others signature, and by using the server and client authentication provided by HTTP over TLS. We provide the minimum requirements and evaluate the methods used. The emphasis is on known and already proven methods. Additionally, we analyze the potential consequences of an attacker tapping the IoTAG information. Finally, we conclude that the solution successfully prevents access to IoTAG by unauthorized clients on the same network.
Cloud Computing (CC), Internet of Thing (IoT) and Smart Grid (SG) are separate technologies. The digital transformation of the energy industry and the increasing digitalization in the private sector connect these technologies. At the moment, CC is used as a service provider for IoT. Currently in Germany, the SG is under construction and a cloud connection to the infrastructure has not been implemented yet. To build the SG cloud, the new laws for privacy must be implemented and therefore it’s important to know which data can be stored and distributed over a cloud. In order to be able to use future
innovative services, SG and IoT must be combined. For this, in
the next step we connect the SG infrastructure with the IoT.
A potential insecure device and network (IoT) should be able
to transfer data to and from a critical infrastructure (SG). In
detail, we focus on two different connections: the communication
between the smart meter switching box and the IoT device and the data transferred between the IoT and SG cloud. In our example, a connected charging station with cloud services is connected with a SG infrastructure. To create a really smart service, the charging station needs a connection to the SG to get the current amount of renewable energy in the grid. Private data, such as name, address and payment details, should not be transferred to the IoT cloud. With these two connections, new threads emerge. In this case, availability, confidentiality and integrity must be ensured. A risk analysis over all the cloud connections, including the vulnerability and the ability of an attacker and the resulting risk are developed in this paper.
Distributed Denial of Service attacks are among the most common and widespread network attacks. Due to their nature, they are difficult to defend. Intrusion detection systems, based on machine learning, are a promising approach to counter this threat. But to train these systems, data sets with Distributed Denial of Service attacks are needed. An implemented Python program, which creates Denial of Services packets and simulates distributed sending by multithreading, is presented. Unlike synthetically generated data with the use of simulators, real network traffic is generated. This eliminates errors and offers a better basis of data, as machine learning algorithms need data that is as error-free as possible in order to learn efficiently.
This paper explores the mitigation of the compliance burdens faced by manufacturers of digital products under the Cyber Resilience Act. After providing a concise overview of the Cyber Resilience Act and pinpointing pivotal areas where tool-based interventions could reduce the regulatory strain on manufacturers, we introduce two prototypes: a digital checklist for product classification and a prototype to streamline the analysis and monitoring of the security state of software along the software development life cycle. As the second prototype is based on Static Application Software Testing and Software Component Analysis, we validate the approach through benchmark tests. While Static Application Software Testing tools show promise in identifying vulnerabilities, additional tests are needed for full compliance with the Cyber Resilience Act. In general, the prototypes serve as an entry point for identifying possible automation potential to alleviate the compliance burdens of manufacturers.